CWE-345
Insufficient Verification of Data Authenticity
The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.
658 vulnerabilities with CWE-345
CVE-2025-53548
HIGH
Clerk Backend < 2.4.0 - Insufficient Verification of Data Authenticity in Webhook Verification
CVSS 7.5
CVE-2025-7096
HIGH
Comodo Internet Security Premium 12.3.4.8162 - Info Disclosure
CVSS 8.1
CVE-2025-5833
MEDIUM
Pioneer DMH-WT7600NEX - Privilege Escalation
CVSS 6.8
CVE-2025-5832
MEDIUM
Pioneer DMH-WT7600NEX Firmware - Unauthenticated Arbitrary Code Execution via Software Update Verification Bypass
CVSS 6.8
CVE-2025-6426
HIGH
Firefox < 128.12.0 and 128.12-128.* for macOS - Insufficient Executable File Warning for Terminal Extension
CVSS 8.8
CVE-2025-52484
LOW
risc0-zkvm 2.0.0-2.0.2 - Insufficient Verification of Data Authenticity via rv32im Circuit Constraint Bypass
CVE-2025-49199
HIGH
SICK Field Analytics - Insufficient Verification of Backup ZIP Authenticity
CVSS 8.8
CVE-2025-48865
CRITICAL
fabio < 1.6.6 - Insufficient Verification of Data Authenticity via Hop-by-Hop Header Manipulation
CVSS 9.1
CVE-2025-5320
LOW
gradio-app gradio <= 5.29.1 - Insufficient Verification of Data Authenticity in CORS Handler
CVSS 3.7
CVE-2025-27558
CRITICAL
IEEE P802.11-REVme D1.1-D7.0 - Frame Injection via Non-SSP A-MSDU Handling
CVSS 9.1
CVE-2025-29842
HIGH
Windows 10 1507-22H2 and Windows 11 22H2 - Security Feature Bypass via UrlMon Data Handling
CVSS 7.5
CVE-2025-43865
HIGH
React Router 7.0.0-pre.0-7.5.1 - Insufficient Verification of Data Authenticity via Request Header
CVSS 8.2
CVE-2025-27735
MEDIUM
Windows 10/11, Server 2016-2019 - Insufficient Data Authenticity Verification in VBS Enclave
CVSS 6.0
CVE-2025-30144
MEDIUM
fast-jwt < 5.0.6 - Authentication Bypass via Issuer Claim Spoofing
CVSS 6.5
CVE-2025-2346
MEDIUM
IROAD Dash Cam X5-X6 <20250308 - Origin Validation Error
CVSS 5.6
CVE-2025-0149
MEDIUM
Zoom Meeting SDK < 6.3.0 - Denial of Service via Network Access
CVSS 6.5
CVE-2025-27616
HIGH
go-vela/server < 0.25.3 and 0.26.0-0.26.3 - Repository Ownership Transfer via Spoofed Webhook Payload
CVSS 8.5
CVE-2025-1945
CRITICAL
picklescan < 0.0.23 - Insufficient Verification of Data Authenticity via ZIP File Header Bit Manipulation
CVSS 9.8
CVE-2025-1944
MEDIUM
PickleScan <0.0.23 - Code Injection
CVSS 6.5
CVE-2025-27257
MEDIUM
GE Vernova UR IED - Privilege Escalation
CVSS 6.1
CVE-2025-27680
CRITICAL
Vasion Print < 20.0.1442 and Virtual Appliance < 1.0.750 - Insufficient Verification of Data Authenticity
CVSS 9.1
CVE-2025-24903
HIGH
libsignal-service-rs - Sync Message Impersonation
CVSS 8.5
CVE-2025-24807
HIGH
eprosima Fast DDS < 2.6.10 - Insufficient Verification of Data Authenticity in PermissionsCA
CVSS 7.1
CVE-2025-25188
MEDIUM
Hickory DNS <0.24.3-0.25.0-alpha.5 - Info Disclosure
CVE-2025-1108
HIGH
Janto < r12 - Unauthenticated Email Content Modification via Xml Parameter Injection
CVSS 8.6
Details
Vulnerabilities
658