VYPR

CWE-345

Insufficient Verification of Data Authenticity

ClassDraft

Description

The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-141 · CAPEC-142 · CAPEC-148 · CAPEC-218 · CAPEC-384 · CAPEC-385 · CAPEC-386 · CAPEC-387 · CAPEC-388 · CAPEC-665 · CAPEC-701

CVEs mapped to this weakness (720)

page 15 of 36
  • CVE-2026-27700HigFeb 25, 2026
    risk 0.46cvss 8.2epss 0.00

    Hono is a Web application framework that provides support for any JavaScript runtime. In versions 4.12.0 and 4.12.1, when using the AWS Lambda adapter (`hono/aws-lambda`) behind an Application Load Balancer (ALB), the `getConnInfo()` function incorrectly selected the first value…

  • CVE-2025-43865HigApr 25, 2025
    risk 0.46cvss 8.2epss 0.01

    React Router is a router for React. In versions on the 7.0 branch prior to version 7.5.2, it's possible to modify pre-rendered data by adding a header to the request. This allows to completely spoof its contents and modify all the values ​​of the data object passed to the…

  • CVE-2023-41896HigOct 19, 2023
    risk 0.46cvss 7.1epss 0.00

    Home assistant is an open source home automation. Whilst auditing the frontend code to identify hidden parameters, Cure53 detected `auth_callback=1`, which is leveraged by the WebSocket authentication logic in tandem with the `state` parameter. The state parameter contains the…

  • CVE-2023-5366HigOct 6, 2023
    risk 0.46cvss 7.1epss 0.00

    A flaw was found in Open vSwitch that allows ICMPv6 Neighbor Advertisement packets between virtual machines to bypass OpenFlow rules. This issue may allow a local attacker to create specially crafted packets with a modified or spoofed target IP address field that can redirect…

  • CVE-2023-35719MedSep 6, 2023
    risk 0.46cvss 6.8epss 0.26

    ManageEngine ADSelfService Plus GINA Client Insufficient Verification of Data Authenticity Authentication Bypass Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of ManageEngine ADSelfService Plus.…

  • CVE-2023-3749HigAug 3, 2023
    risk 0.46cvss 7.1epss 0.00

    A local user could edit the VideoEdge configuration file and interfere with VideoEdge operation.

  • CVE-2023-36858HigAug 2, 2023
    risk 0.46cvss 7.1epss 0.00

    An insufficient verification of data vulnerability exists in BIG-IP Edge Client for Windows and macOS that may allow an attacker to modify its configured server list.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

  • CVE-2023-3325HigJun 20, 2023
    risk 0.46cvss 8.1epss 0.01

    The CMS Commander plugin for WordPress is vulnerable to authorization bypass due to the use of an insufficiently unique cryptographic signature on the 'cmsc_add_site' function in versions up to, and including, 2.287. This makes it possible for unauthenticated attackers to the…

  • CVE-2022-42267HigDec 30, 2022
    risk 0.46cvss 7.0epss 0.00

    NVIDIA GPU Display Driver for Windows contains a vulnerability where a regular user can cause an out-of-bounds read, which may lead to code execution, denial of service, escalation of privileges, information disclosure, or data tampering.

  • CVE-2022-39909HigDec 8, 2022
    risk 0.46cvss 7.1epss 0.00

    Insufficient verification of data authenticity vulnerability in Samsung Gear IconX PC Manager prior to version 2.1.221019.51 allows local attackers to create arbitrary file using symbolic link.

  • CVE-2021-20267HigMay 28, 2021
    risk 0.46cvss 7.1epss 0.01

    A flaw was found in openstack-neutron's default Open vSwitch firewall rules. By sending carefully crafted packets, anyone in control of a server instance connected to the virtual switch can impersonate the IPv6 addresses of other systems on the network, resulting in denial of…

  • CVE-2020-15222HigSep 24, 2020
    risk 0.46cvss 8.1epss 0.01

    In ORY Fosite (the security first OAuth2 & OpenID Connect framework for Go) before version 0.31.0, when using "private_key_jwt" authentication the uniqueness of the `jti` value is not checked. When using client authentication method "private_key_jwt", OpenId specification says…

  • CVE-2019-16007HigSep 23, 2020
    risk 0.46cvss 7.1epss 0.00

    A vulnerability in the inter-service communication of Cisco AnyConnect Secure Mobility Client for Android could allow an unauthenticated, local attacker to perform a service hijack attack on an affected device or cause a denial of service (DoS) condition. The vulnerability is…

  • CVE-2020-16250HigAug 26, 2020
    risk 0.46cvss 8.2epss 0.02

    HashiCorp Vault and Vault Enterprise versions 0.7.1 and newer, when configured with the AWS IAM auth method, may be vulnerable to authentication bypass. Fixed in 1.2.5, 1.3.8, 1.4.4, and 1.5.1..

  • CVE-2019-17636HigMar 10, 2020
    risk 0.46cvss 8.1epss 0.01

    In Eclipse Theia versions 0.3.9 through 0.15.0, one of the default pre-packaged Theia extensions is "Mini-Browser", published as "@theia/mini-browser" on npmjs.com. This extension, for its own needs, exposes a HTTP endpoint that allows to read the content of files on the host's…

  • CVE-2019-3786HigApr 24, 2019
    risk 0.46cvss 7.1epss 0.01

    Cloud Foundry BOSH Backup and Restore CLI, all versions prior to 1.5.0, does not check the authenticity of backup scripts in BOSH. A remote authenticated malicious user can modify the metadata file of a Bosh Backup and Restore job to request extra backup files from different…

  • CVE-2026-54174higJul 10, 2026
    risk 0.45cvss epss

    Previously, Apko verified the control section hash (`.PKGINFO` etc.) against the signed `APKINDEX`, but never verified the data section hash (the actual package files that get installed). An attacker who could compromise a mirror, poison a cache, or MITM a package fetch could…

  • CVE-2026-57122higJun 18, 2026
    risk 0.45cvss epss

    The WhatsApp and Linear bot adapters verify the inbound webhook HMAC signature only when a secret is configured. When the secret environment variable is unset — the default on a fresh install and common in development — verification is skipped entirely and the webhook body…

  • CVE-2026-56832higJun 18, 2026
    risk 0.45cvss epss

    # DiscordApproval accepts unrelated channel messages as dangerous-tool approvals ## Summary `praisonai.bots.DiscordApproval` approves a pending dangerous tool call when it sees any later non-bot message in the configured Discord channel whose text is classified as approval,…

  • CVE-2026-3012HigMay 27, 2026
    risk 0.45cvss 8.0epss 0.00

    A flaw was found in Samba’s certificate auto-enrollment Group Policy handling. When certificate auto-enrollment is enabled, Samba may retrieve a CA certificate over an unencrypted HTTP connection and install it into the local trust store without proper verification. An…