CWE-354

Medium likelihood

Improper Validation of Integrity Check Value

Parent: CWE-345 - Insufficient Verification of Data Authenticity

The product does not validate or incorrectly validates the integrity check values or "checksums" of a message. This may prevent it from detecting if the data has been modified or corrupted in transmission.

157 vulnerabilities with CWE-354
CVE-2026-32148 HIGH
Lockfile checksums not verified in Hex allows dependency integrity bypass
CVE-2026-40323 HIGH
SP1 V6 Recursion Circuit Row-Count Binding Gap
CVE-2026-32105 HIGH
xrdp: RDP MAC signature (dataSignature) never verified on receive — integrity bypass in non-TLS mode
CVSS 7.7
CVE-2026-5479 HIGH
wolfSSL EVP ChaCha20-Poly1305 AEAD authentication tag
CVSS 8.1
CVE-2026-5504 MEDIUM
PKCS7 CBC Padding Oracle — Plaintext Recovery
CVSS 5.3
CVE-2026-26928 HIGH
Lack of Dynamic Library Validation in SzafirHost
CVE-2026-33026 CRITICAL
nginx-ui Backup Restore Allows Tampering with Encrypted Backups
CVSS 9.1
CVE-2026-32318 HIGH
Cryptomator for IOS: Tampered vault configuration allows MITM attack on Hub API
CVSS 7.6
CVE-2026-32317 HIGH
Cryptomator for Android: Tampered vault configuration allows MITM attack on Hub API
CVSS 7.6
CVE-2026-32303 HIGH
Cryptomator: Tampered vault configuration allows MITM attack on Hub API
CVSS 7.6
CVE-2026-28498 HIGH
Authlib: Fail-Open Cryptographic Verification in OIDC Hash Binding
CVSS 7.5
CVE-2026-32600 HIGH
xml-security is Missing AES-GCM Authentication Tag Validation on Encrypted Nodes Allows for Unauthorized Decryption
CVSS 8.2
CVE-2026-32313 HIGH
xmlseclibs is Missing AES-GCM Authentication Tag Validation on Encrypted Nodes Allows for Unauthorized Decryption
CVSS 8.2
CVE-2026-31839 HIGH
Striae <3.0.0 - Integrity Bypass
CVSS 8.2
CVE-2026-28402 HIGH
nimiq/core-rs-albatross <1.2.2 - Auth Bypass
CVSS 7.1
CVE-2026-26275 HIGH
httpsig-hyper <0.0.23 - Auth Bypass
CVSS 7.5
CVE-2026-25934 MEDIUM
go-git <5.16.5 - Info Disclosure
CVSS 4.3
CVE-2025-11543 CRITICAL
Sharp Display Solutions - Code Injection
CVSS 9.8
CVE-2025-33193 MEDIUM
NVIDIA DGX Spark GB10 - Info Disclosure
CVSS 5.7
CVE-2025-4616 LOW
Palo Alto Networks Prisma Browser - Privilege Escalation
CVE-2025-55155 MEDIUM
MantisBT <2.27.1 - Info Disclosure
CVSS 5.4
CVE-2025-54887 CRITICAL
jwe <1.1.0 - Confidentiality Disclosure
CVSS 9.1
CVE-2025-7096 HIGH
Comodo Internet Security Premium 12.3.4.8162 - Info Disclosure
CVSS 8.1
CVE-2025-39203 MEDIUM
Hitachienergy Microscada X Sys600 < 10.7 - Denial of Service
CVSS 6.5
CVE-2025-4418 MEDIUM
AVEVA PI Connector for CygNet <1.6.14 - Privilege Escalation
CVSS 4.4
Details
Vulnerabilities 157
Exploit Likelihood Medium