CWE-345
Insufficient Verification of Data Authenticity
The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.
657 vulnerabilities with CWE-345
CVE-2026-2385
MEDIUM
The Plus Addons for Elementor <6.4.7 - Auth Bypass
CVSS 5.3
CVE-2026-26327
MEDIUM
OpenClaw < 2026.2.14 - Unauthenticated TLS Certificate Pinning Bypass via Discovery Beacon TXT Records
CVSS 6.5
CVE-2026-25474
HIGH
OpenClaw < 2026.2.1 - Insufficient Verification of Telegram Webhook Secret Token
CVSS 7.5
CVE-2026-26007
MEDIUM
cryptography < 46.0.5 - Insufficient Verification of Data Authenticity in Public Key Functions
CVSS 6.5
CVE-2026-21527
MEDIUM
Microsoft Exchange Server - Info Disclosure
CVSS 6.5
CVE-2026-1642
MEDIUM
NGINX OSS 1.3.0-1.28.1 & NGINX Plus r33-r34 TLS Data Authenticity Verification Bypass
CVSS 5.9
CVE-2026-24775
MEDIUM
OpenProject 17.0.0-17.0.2 - Server-Side Request Forgery via BlockNote Work Package Mention
CVSS 6.3
CVE-2026-24772
HIGH
OpenProject 17.0.0-17.0.2 - Authentication Token Spoofing via Synchronization Server URL Manipulation
CVSS 8.9
CVE-2026-23966
CRITICAL
sm-crypto <0.3.14 - Private Key Recovery
CVSS 9.1
CVE-2026-1195
MEDIUM
MineAdmin 1.x/2.x - Insufficient Verification of Data Authenticity in JWT Token Handler
CVSS 5.0
CVE-2026-0939
MEDIUM
Rede Itaú for WooCommerce <=5.1.2 - Auth Bypass
CVSS 5.3
CVE-2026-22703
MEDIUM
sigstore cosign < 2.6.2 and 3.0.4 - Insufficient Verification of Data Authenticity
CVSS 5.5
CVE-2025-52645
LOW
HCL AION is affected by a vulnerability where model packaging and distribution mechanisms may not include sufficient authenticity verification.
CVSS 1.9
CVE-2025-52638
MEDIUM
Multiple security vulnerabilities affect HCL AION
CVSS 5.6
CVE-2025-67298
HIGH
ClasroomIO <0.2.6 - Privilege Escalation
CVSS 8.1
CVE-2025-63910
HIGH
Cohesity TranZman 4.0 Build 14614 - File Upload RCE
CVSS 7.2
CVE-2025-15598
LOW
Dataease SQLBot <1.5.1 - Auth Bypass
CVSS 3.7
CVE-2025-71057
HIGH
D-Link DSL-124 ME_1.00 - Session Hijacking
CVSS 8.2
CVE-2025-14444
MEDIUM
RegistrationMagic <6.0.6.9 - Payment Bypass
CVSS 5.3
CVE-2025-59024
MEDIUM
PowerDNS Recursor 5.1.0-5.1.7, 5.2.0-5.2.5, 5.3.0 - Cache Poisoning via Crafted Delegations or IP Fragments
CVSS 6.5
CVE-2025-15385
CRITICAL
TECNO Mobile Boomplayer < 7.4.63 - Authentication Bypass via Insufficient Data Verification
CVSS 9.8
CVE-2025-15154
MEDIUM
pbootcms < 3.2.12 - Use of Less Trusted Source via X-Forwarded-For Header
CVSS 5.3
CVE-2025-66570
CRITICAL
cpp-httplib <0.27.0 - Info Disclosure
CVSS 10.0
CVE-2025-59700
LOW
Entrust nShield HSM <13.6.12 Recovery Partition Modification via Integrity Protection Lack
CVSS 3.9
CVE-2025-66225
HIGH
OrangeHRM 5.0-5.7 - Unauthenticated Account Takeover via Password Reset Username Manipulation
CVSS 8.8
Details
Vulnerabilities
657