VYPR

CWE-345

Insufficient Verification of Data Authenticity

ClassDraft

Description

The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-141 · CAPEC-142 · CAPEC-148 · CAPEC-218 · CAPEC-384 · CAPEC-385 · CAPEC-386 · CAPEC-387 · CAPEC-388 · CAPEC-665 · CAPEC-701

CVEs mapped to this weakness (809)

page 24 of 41
  • CVE-2022-23556HigDec 22, 2022
    risk 0.39cvss 7.0epss 0.00

    CodeIgniter is a PHP full-stack web framework. This vulnerability may allow attackers to spoof their IP address when the server is behind a reverse proxy. This issue has been patched, please upgrade to version 4.2.11 or later, and configure `Config\App::$proxyIPs`. As a…

  • CVE-2022-26579MedDec 16, 2022
    risk 0.39cvss 6.0epss 0.00

    PAX A930 device with PayDroid_7.1.1_Virgo_V04.3.26T1_20210419 can allow a root privileged attacker to install unsigned packages. The attacker must have shell access to the device and gain root privileges in order to exploit this vulnerability.

  • CVE-2021-20271HigMar 26, 2021
    risk 0.39cvss 7.0epss 0.01

    A flaw was found in RPM's signature check functionality when reading a package file. This flaw allows an attacker who can convince a victim to install a seemingly verifiable package, whose signature header was modified, to cause RPM database corruption and execute code. The…

  • CVE-2026-19941MedSep 16, 2026
    risk 0.38cvss 5.9epss 0.00

    An inapplicable NSEC record may be accepted by a `named` resolver as proof that no wildcard exists, which could allow an attacker at the same or an upstream level of the zone name to mask the existence of a victim's wildcard record. This issue affects BIND 9 versions 9.11.0…

  • CVE-2026-82215MedSep 11, 2026
    risk 0.38cvss 5.9epss 0.00

    The Payment Gateway PayPay for WooCommerce WordPress plugin from 0.5 to 0.9.3 does not verify the authenticity of the payment notifications it receives before acting on them, allowing unauthenticated attackers who know the store's merchant identifier to mark arbitrary orders as…

  • CVE-2026-20355MedSep 2, 2026
    risk 0.38cvss 5.9epss 0.00

    Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality of Cisco Secure Email could allow an unauthenticated, remote attacker to recover plain text from encrypted email messages. These vulnerabilities are due to…

  • CVE-2026-15211MedAug 7, 2026
    risk 0.38cvss 5.9epss 0.00

    The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not validate the payment amount or bind the PayPal order token to the order being completed on the WooCommerce order-received flow: it captures a client-supplied token and marks the order paid whenever the…

  • CVE-2026-12901MedAug 6, 2026
    risk 0.38cvss 5.9epss 0.00

    The GetPaid WordPress plugin before 2.8.55 does not verify the authenticity of incoming Worldpay payment notifications, allowing unauthenticated attackers to forge a notification that marks a pending invoice as paid without any payment being made.

  • CVE-2026-11361MedAug 6, 2026
    risk 0.38cvss 5.9epss 0.00

    The Formidable Forms WordPress plugin before 6.32.1 does not properly validate the status of a PayPal subscription payment before marking it complete, allowing unauthenticated users to bypass payment and trigger paid form actions — such as digital content access, license…

  • CVE-2026-13188MedJul 22, 2026
    risk 0.38cvss 5.9epss 0.00

    In Progress® Telerik® UI for AJAX prior to v2026.2.708, DialogHandler request parameters may be tampered with, potentially altering dialog server-side behavior and enabling chained exploitation.

  • CVE-2026-46538MedMay 27, 2026
    risk 0.38cvss 5.9epss 0.00

    Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.1-4-ge2626659, Microsoft UFO's constellation client tracks pending task responses by session_id only and does not verify that a TASK_END message came from the device that…

  • CVE-2026-6967MedApr 24, 2026
    risk 0.38cvss 5.9epss 0.00

    Missing expiration, hash, and length enforcement in delegated metadata validation in awslabs/tough before tough-v0.22.0 allows remote authenticated users with delegated signing authority to bypass TUF specification integrity checks for delegated targets metadata and poison the…

  • CVE-2026-23656MedMar 10, 2026
    risk 0.38cvss 5.9epss 0.00

    Insufficient verification of data authenticity in Windows App Installer allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2025-51471MedJul 22, 2025
    risk 0.38cvss 6.9epss 0.14

    Cross-Domain Token Exposure in server.auth.getAuthorizationToken in Ollama 0.6.7 allows remote attackers to steal authentication tokens and bypass access controls via a malicious realm value in a WWW-Authenticate header returned by the /api/pull endpoint.

  • CVE-2024-24557MedFeb 1, 2024
    risk 0.38cvss 6.9epss 0.00

    Moby is an open-source project created by Docker to enable software containerization. The classic builder cache system is prone to cache poisoning if the image is built FROM scratch. Also, changes to some instructions (most important being HEALTHCHECK and ONBUILD) would not…

  • CVE-2022-2793MedAug 19, 2022
    risk 0.38cvss 5.9epss 0.00

    Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulenrable to CWE-353 Missing Support for Integrity Check, and has no authentication or authorization of data packets after establishing a connection for the SRTP protocol.

  • CVE-2022-34763MedJul 13, 2022
    risk 0.38cvss 5.9epss 0.00

    A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists that could cause loading of unauthorized firmware images due to improper verification of the firmware signature. Affected Products: X80 advanced RTU Communication Module (BMENOR2200H) (V2.01 and…

  • CVE-2022-20795MedApr 21, 2022
    risk 0.38cvss 5.8epss 0.01

    A vulnerability in the implementation of the Datagram TLS (DTLS) protocol in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause high CPU utilization, resulting in a denial of…

  • CVE-2019-5291MedDec 13, 2019
    risk 0.38cvss 5.9epss 0.00

    Some Huawei products have an insufficient verification of data authenticity vulnerability. A remote, unauthenticated attacker has to intercept specific packets between two devices, modify the packets, and send the modified packets to the peer device. Due to insufficient…

  • CVE-2019-6475MedOct 17, 2019
    risk 0.38cvss 5.9epss 0.01

    Mirror zones are a BIND feature allowing recursive servers to pre-cache zone data provided by other servers. A mirror zone is similar to a zone of type secondary, except that its data is subject to DNSSEC validation before being used in answers, as if it had been looked up via…