CWE-345
Insufficient Verification of Data Authenticity
The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.
657 vulnerabilities with CWE-345
CVE-2026-33243
HIGH
barebox: FIT Signature Verification Bypass Vulnerability
CVSS 8.2
CVE-2026-33221
MEDIUM
Nhost Storage Affected by MIME Type Spoofing via Trusted Client Content-Type Header in Storage Upload
CVSS 5.3
CVE-2026-33143
HIGH
OneUptime: WhatsApp Webhook Missing Signature Verification
CVSS 7.5
CVE-2026-4478
HIGH
Yi Technology YI Home Camera HTTP Firmware Update ipc signature verification
CVSS 8.1
CVE-2026-32029
MEDIUM
OpenClaw < 2026.2.21 - Client IP Spoofing via X-Forwarded-For Header Parsing
CVSS 5.3
CVE-2026-28500
HIGH
ONNX Untrusted Model Repository Warnings Suppressed by silent=True in onnx.hub.load() — Silent Supply-Chain Attack
CVSS 8.6
CVE-2026-32294
MEDIUM
JetKVM insufficient firmware verification
CVSS 4.7
CVE-2026-32290
MEDIUM
GL-iNet Comet (GL-RM1) KVM insufficient firmware verification
CVSS 4.7
CVE-2026-32597
HIGH
PyJWT < 2.12.0 - Insufficient Verification of Data Authenticity via crit Header Parameter
CVSS 7.5
CVE-2026-32231
HIGH
ZeptoClaw < 0.7.6 - Unauthenticated Message Spoofing and Session Routing Abuse via Webhook Identity Fields
CVSS 8.2
CVE-2026-23656
MEDIUM
Windows App Installer < 2.0.964.0 - Unauthenticated Spoofing via Insufficient Data Verification
CVSS 5.9
CVE-2026-30920
HIGH
OneUptime < 10.0.19 - Missing Authorization in GitHub App Callback
CVSS 8.6
CVE-2026-3706
LOW
Dropbear <=2025.89 - Improper Signature Verification
CVSS 3.7
CVE-2026-30851
HIGH
Caddy 2.10.0-2.11.1 - Privilege Escalation
CVSS 8.1
CVE-2026-30223
HIGH
olivetin < 3000.11.1 - Insufficient JWT Audience Verification
CVSS 8.8
CVE-2026-28454
HIGH
OpenClaw < 2026.2.2 - Unauthenticated Privileged Command Execution via Telegram Webhook Spoofing
CVSS 7.5
CVE-2026-25921
CRITICAL
Gogs < 0.14.2 - LFS Object Overwrite Supply-Chain Attack
CVSS 9.3
CVE-2026-30798
HIGH
RustDesk Client <=1.4.5 - Protocol Manipulation
CVSS 7.5
CVE-2026-30792
HIGH
RustDesk Client <=1.4.5 - MITM API Manipulation
CVSS 8.1
CVE-2026-2836
HIGH
Pingora Cache < 0.8.0 - Cache Poisoning via Insufficient Cache Key Verification
CVSS 8.1
CVE-2026-2428
HIGH
Fluent Forms Pro Add On Pack <=6.1.17 - Auth Bypass
CVSS 7.5
CVE-2026-27510
CRITICAL
Unitree Go2 firmware 1.1.7-1.1.11 - Remote Code Execution via Tampered Android App Programme
CVSS 9.6
CVE-2026-27804
CRITICAL
Parse Server <8.6.3/9.1.1-alpha.4 - Auth Bypass
CVSS 9.1
CVE-2026-27700
HIGH
Hono 4.12.0-4.12.1 - IP Spoofing via X-Forwarded-For Header Mishandling
CVSS 8.2
CVE-2026-2968
LOW
Cesanta Mongoose <=7.20 - Auth Bypass
CVSS 3.7
Details
Vulnerabilities
657