VYPR

CWE-345

Insufficient Verification of Data Authenticity

ClassDraft

Description

The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-141 · CAPEC-142 · CAPEC-148 · CAPEC-218 · CAPEC-384 · CAPEC-385 · CAPEC-386 · CAPEC-387 · CAPEC-388 · CAPEC-665 · CAPEC-701

CVEs mapped to this weakness (720)

page 14 of 36
  • CVE-2024-30162HigJun 7, 2024
    risk 0.47cvss 7.2epss 0.01

    Invision Community through 4.7.16 allows remote code execution via the applications/core/modules/admin/editor/toolbar.php IPS\core\modules\admin\editor\_toolbar::addPlugin() method. This method handles uploaded ZIP files that are extracted into the…

  • CVE-2023-5747HigNov 13, 2023
    risk 0.47cvss 7.2epss 0.01

    Bashis, a Security Researcher at IPVM has found a flaw that allows for a remote code execution during the installation of Wave on the camera device. The Wave server application in camera device was vulnerable to command injection allowing an attacker to run arbitrary code.…

  • CVE-2023-5450HigOct 10, 2023
    risk 0.47cvss 7.3epss 0.00

    An insufficient verification of data vulnerability exists in BIG-IP Edge Client Installer on macOS that may allow an attacker elevation of privileges during the installation process.  Note: Software versions which have reached End of Technical Support (EoTS) are not…

  • CVE-2023-2866HigJun 7, 2023
    risk 0.47cvss 7.3epss 0.00

    If an attacker can trick an authenticated user into loading a maliciously crafted .zip file onto Advantech WebAccess version 8.4.5, a web shell could be used to give the attacker full control of the SCADA server.

  • CVE-2023-31502HigMay 11, 2023
    risk 0.47cvss 7.2epss 0.01

    Altenergy Power Control Software C1.2.5 was discovered to contain a remote code execution (RCE) vulnerability via the component /models/management_model.php.

  • CVE-2022-46370HigJan 12, 2023
    risk 0.47cvss 7.3epss 0.00

    Rumpus - FTP server version 9.0.7.1 Improper Token Verification– vulnerability may allow bypassing identity verification.

  • CVE-2022-30272HigJul 26, 2022
    risk 0.47cvss 7.2epss 0.00

    The Motorola ACE1000 RTU through 2022-05-02 mishandles firmware integrity. It utilizes either the STS software suite or ACE1000 Easy Configurator for performing firmware updates. In case of the Easy Configurator, firmware updates are performed through access to the Web UI where…

  • CVE-2021-26610HigOct 27, 2021
    risk 0.47cvss 7.2epss 0.00

    The move_uploaded_file function in godomall5 does not perform an integrity check of extension or authority when user upload file. This vulnerability allows an attacker to execute an remote arbitrary code.

  • CVE-2020-1677HigOct 16, 2020
    risk 0.47cvss 7.2epss 0.00

    When SAML authentication is enabled, Juniper Networks Mist Cloud UI might incorrectly handle child elements in SAML responses, allowing a remote attacker to modify a valid SAML response without invalidating its cryptographic signature to bypass SAML authentication security…

  • CVE-2020-24045HigSep 17, 2020
    risk 0.47cvss 7.2epss 0.02

    A sandbox escape issue was discovered in TitanHQ SpamTitan Gateway 7.07. It limits the admin user to a restricted shell, allowing execution of a small number of tools of the operating system. The restricted shell can be bypassed by presenting a fake vmware-tools ISO image to the…

  • CVE-2020-6090HigJun 11, 2020
    risk 0.47cvss 7.2epss 0.02

    An exploitable code execution vulnerability exists in the Web-Based Management (WBM) functionality of WAGO PFC 200 03.03.10(15). A specially crafted series of HTTP requests can cause code execution resulting in remote code execution. An attacker can make an authenticated HTTP…

  • CVE-2019-13483HigJul 25, 2019
    risk 0.47cvss 7.3epss 0.01

    Auth0 Passport-SharePoint before 0.4.0 does not validate the JWT signature of an Access Token before processing. This allows attackers to forge tokens and bypass authentication and authorization mechanisms.

  • CVE-2017-9606HigJun 15, 2017
    risk 0.47cvss 7.3epss 0.00

    Infotecs ViPNet Client and Coordinator before 4.3.2-42442 allow local users to gain privileges by placing a Trojan horse ViPNet update file in the update folder. The attack succeeds because of incorrect folder permissions in conjunction with a lack of integrity and authenticity…

  • CVE-2016-2309HigMay 30, 2016
    risk 0.47cvss 7.2epss 0.01

    iRZ RUH2 before 2b does not validate firmware patches, which allows remote authenticated users to modify data or cause a denial of service via unspecified vectors.

  • CVE-2026-50526HigJul 14, 2026
    risk 0.46cvss 7.0epss 0.00

    Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tampering locally.

  • CVE-2026-45055HigMay 13, 2026
    risk 0.46cvss 8.1epss 0.00

    CubeCart is an ecommerce software solution. Prior to 6.7.2, CubeCart 6.6.x – 6.7.1 builds CC_STORE_URL directly from the Host request header at bootstrap, with no allowlist. The constant is embedded verbatim into transactional email links, most critically the password-reset…

  • CVE-2026-33243HigMar 20, 2026
    risk 0.46cvss 8.2epss 0.00

    barebox is a bootloader. In barebox from version 2016.03.0 to before version 2026.03.1 (and the corresponding backport to 2025.09.3), an attacker could exploit a FIT signature verification vulnerability to trick the bootloader into booting different images than those that were…

  • CVE-2026-32231HigMar 12, 2026
    risk 0.46cvss 8.2epss 0.00

    ZeptoClaw is a personal AI assistant. Prior to 0.7.6, the generic webhook channel trusts caller-supplied identity fields (sender, chat_id) from the request body and applies authorization checks to those untrusted values. Because authentication is optional and defaults to…

  • CVE-2026-30851HigMar 7, 2026
    risk 0.46cvss 8.1epss 0.00

    Caddy is an extensible server platform that uses TLS by default. From version 2.10.0 to before version 2.11.2, forward_auth copy_headers does not strip client-supplied headers, allowing identity injection and privilege escalation. This issue has been patched in version 2.11.2.

  • CVE-2026-2836HigMar 5, 2026
    risk 0.46cvss 8.1epss 0.00

    A cache poisoning vulnerability has been found in the Pingora HTTP proxy framework’s default cache key construction. The issue occurs because the default HTTP cache key implementation generates cache keys using only the URI path, excluding critical factors such as the host…