VYPR

CWE-345

Insufficient Verification of Data Authenticity

ClassDraft

Description

The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-141 · CAPEC-142 · CAPEC-148 · CAPEC-218 · CAPEC-384 · CAPEC-385 · CAPEC-386 · CAPEC-387 · CAPEC-388 · CAPEC-665 · CAPEC-701

CVEs mapped to this weakness (809)

page 5 of 41
  • CVE-2026-33729CriMar 27, 2026
    risk 0.57cvss 9.8epss 0.00

    OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. In versions prior to 1.13.1, under specific conditions, models using conditions with caching enabled can result in two different check requests…

  • CVE-2025-66225HigNov 29, 2025
    risk 0.57cvss 8.8epss 0.00

    OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the password reset workflow does not enforce that the username submitted in the final reset request matches the account for which the reset process was originally initiated. After…

  • CVE-2025-34337HigNov 19, 2025
    risk 0.57cvss —epss 0.00

    eGovFramework/egovframe-common-components versions up to and including 4.3.1 includes Web Editor image upload and related file delivery functionality that uses symmetric encryption to protect URL parameters, but exposes an encryption oracle that allows attackers to generate…

  • CVE-2025-6426HigJun 24, 2025
    risk 0.57cvss 8.8epss 0.00

    The executable file warning did not warn users before opening files with the `terminal` extension. *This bug only affects Firefox for macOS. Other versions of Firefox are unaffected.*. This vulnerability was fixed in Firefox 140, Firefox ESR 128.12, Thunderbird 140, and…

  • CVE-2025-49199HigJun 12, 2025
    risk 0.57cvss 8.8epss 0.00

    The backup ZIPs are not signed by the application, leading to the possibility that an attacker can download a backup ZIP, modify and re-upload it. This allows the attacker to disrupt the application by configuring the services in a way that they are unable to run, …

  • CVE-2025-1945CriMar 10, 2025
    risk 0.57cvss 9.8epss 0.01

    picklescan before 0.0.23 fails to detect malicious pickle files inside PyTorch model archives when certain ZIP file flag bits are modified. By flipping specific bits in the ZIP file headers, an attacker can embed malicious pickle files that remain undetected by PickleScan while…

  • CVE-2024-45410CriSep 19, 2024
    risk 0.57cvss 9.8epss 0.02

    Traefik is a golang, Cloud Native Application Proxy. When a HTTP request is processed by Traefik, certain HTTP headers such as X-Forwarded-Host or X-Forwarded-Port are added by Traefik before the request is routed to the application. For a HTTP client, it should not be possible…

  • CVE-2024-7256HigAug 1, 2024
    risk 0.57cvss 8.8epss 0.01

    Insufficient data validation in Dawn in Google Chrome on Android prior to 127.0.6533.88 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)

  • CVE-2024-3173HigJul 16, 2024
    risk 0.57cvss 8.8epss 0.00

    Insufficient data validation in Updater in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: High)

  • CVE-2023-27360HigMay 3, 2024
    risk 0.57cvss 8.8epss 0.00

    NETGEAR RAX30 lighttpd Misconfiguration Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR RAX30. Authentication is not required to exploit this vulnerability. The specific…

  • CVE-2024-27773HigMar 18, 2024
    risk 0.57cvss 8.8epss 0.00

    Unitronics Unistream Unilogic – Versions prior to 1.35.227 - CWE-348: Use of Less Trusted Source may allow RCE

  • CVE-2015-8371HigSep 21, 2023
    risk 0.57cvss 8.8epss 0.01

    Composer before 2016-02-10 allows cache poisoning from other projects built on the same host. This results in attacker-controlled code entering a server-side build process. The issue occurs because of the way that dist packages are cached. The cache key is derived from the…

  • CVE-2023-2987CriMay 31, 2023
    risk 0.57cvss 9.8epss 0.01

    The Wordapp plugin for WordPress is vulnerable to authorization bypass due to an use of insufficiently unique cryptographic signature on the 'wa_pdx_op_config_set' function in versions up to, and including, 1.6.0. This makes it possible for unauthenticated attackers to the…

  • CVE-2023-27982HigMar 21, 2023
    risk 0.57cvss 8.8epss 0.00

    A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists in the Data Server that could cause manipulation of dashboard files in the IGSS project report directory, when an attacker sends specific crafted messages to the Data Server TCP port, this could lead…

  • CVE-2022-31877HigNov 28, 2022
    risk 0.57cvss 8.8epss 0.00

    An issue in the component MSI.TerminalServer.exe of MSI Center v1.0.41.0 allows attackers to escalate privileges via a crafted TCP packet.

  • CVE-2022-38625HigAug 29, 2022
    risk 0.57cvss 8.8epss 0.01

    Patlite NH-FB v1.46 and below was discovered to contain insufficient firmware validation during the upgrade firmware file upload process. This vulnerability allows authenticated attackers to create and upload their own custom-built firmware and inject malicious code. NOTE: the…

  • CVE-2022-28757HigAug 18, 2022
    risk 0.57cvss 8.8epss 0.00

    The Zoom Client for Meetings for macOS (Standard and for IT Admin) starting with version 5.7.3 and before 5.11.6 contains a vulnerability in the auto update process. A local low-privileged user could exploit this vulnerability to escalate their privileges to root.

  • CVE-2022-30269HigJul 26, 2022
    risk 0.57cvss 8.8epss 0.00

    Motorola ACE1000 RTUs through 2022-05-02 mishandle application integrity. They allow for custom application installation via either STS software, the C toolkit, or the ACE1000 Easy Configurator. In the case of the Easy Configurator, application images (as PLX/DAT/APP/CRC files)…

  • CVE-2021-26625HigApr 19, 2022
    risk 0.57cvss 8.8epss 0.01

    Insufficient Verification of input Data leading to arbitrary file download and execute was discovered in Nexacro platform. This vulnerability is caused by an automatic update function that does not verify input data except version information. Remote attackers can use this…

  • CVE-2022-22994HigJan 28, 2022
    risk 0.57cvss 8.8epss 0.02

    A remote code execution vulnerability was discovered on Western Digital My Cloud devices where an attacker could trick a NAS device into loading through an unsecured HTTP call. This was a result insufficient verification of calls to the device. The vulnerability was addressed by…