Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is an authe
Note Mark is an open-source note-taking application. Prior to 0.19.4, no minimum length or entropy is enforced on the JW
Traefik is an HTTP reverse proxy and load balancer. Prior to v2.11.51, v3.6.22, and v3.7.6, Traefik's BasicAuth, DigestA
Postiz is an AI social media scheduling tool. In versions prior to 2.21.8, the Skool integration callback signed an atta
containerd is an open-source container runtime. Versions prior to 2.3.2, 2.2.5 and 2.1.9 contain a vulnerability in the
Insufficient Verification of Data Authenticity vulnerability in TECNO Mobile com.Afmobi.Boomplayer allows Authentication
OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Z
Rack::Session is a session management implementation for Rack. From 2.0.0 to before 2.1.2, Rack::Session::Cookie incorre
The /v1/Plan service relies entirely on a shared global API token for full administrative management, allowing arbitrary
Unauthenticated Broken Authentication in Log in with Google <= 1.4.2 versions.
openssl_encrypt versions before 1.4.0 silently skip JSON schema validation when the jsonschema library is not installed,
openssl_encrypt before 1.4.9 fails to re-derive and validate fingerprints when loading identities from identity.json, al
Unitree Go2 firmware versions 1.1.7 through 1.1.11, when used with the Unitree Go2 Android application (com.unitree.dogg
nimiq-block contains block primitives to be used in Nimiq's Rust implementation. `SkipBlockProof::verify` computes its q
Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, the @better-auth/sso plugin'
Gradient is a nix-based continuous integration system. In 1.1.0, when GRADIENT_DISCOVERABLE=true (the default, and the N
Cap-go before 12.128.2 contains an authentication bypass vulnerability in OTP verification that allows attackers to bypa
Gogs is an open source self-hosted Git service. Prior to version 0.14.2, overwritable LFS object across different repos
ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad 5.0.0, halo2_gadgets 0.5.0, orchard 0.14.0, zcash_primit
sm-crypto provides JavaScript implementations of the Chinese cryptographic algorithms SM2, SM3, and SM4. A private key r
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version
fast-jwt provides fast JSON Web Token (JWT) implementation. From 0.0.1 to before 6.2.0, setting up a custom cacheKeyBuil
OpenClaw before 2026.4.10 contains an input validation vulnerability that allows external hook metadata to be enqueued a
Insufficient Verification of Data Authenticity vulnerability in Apache APISIX. The openid-connect plugin under default
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.1
Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, the legacy oidcProvider and
Logto bypasses OIDC nonce validation when the nonce claim is absent from the id_token, enabling replay of authentication
@fastify/aws-lambda version 6.4.0 decorates each Fastify request with request.awsLambda.event and request.awsLambda.cont
Apache CXF's JwtRequestCodeFilter copies all claims from a signed request JWT into the authorization parameter map witho
Apache CXF’s OIDC relying-party token validation could accept self-issued ID tokens without enforcing required claim che
OpenProject is an open-source, web-based project management software. To enable the real time collaboration on documents
Postiz is an AI social media scheduling tool. Prior to version 2.21.6, a file upload validation bypass allows any authen
OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.1, when JWT authentica
pnpm is a package manager. Prior to 10.34.2 and 11.5.3, pnpm can persist package-manager bootstrap metadata in the first
CyberPanel 2.4.3, fixed in commit eca0c3c, contains an authenticated remote code execution vulnerability in the remote b
Insufficient verification of data authenticity in Azure Entra ID allows an authorized attacker to perform spoofing over
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Fina
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Fina
A flaw was found in the lighthouse component of Red Hat Advanced Cluster Management for Kubernetes. This vulnerability s
OneUptime is a solution for monitoring and managing online services. Prior to 10.0.19, OneUptime's GitHub App callback t
Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. In versions up to and inc
Dräger Infinity Acute Care System and Standalone Infinity M540 patient monitors versions VG4.1.1, VG4.0.3, and lower (wi
A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). When processing Kubernetes Deployments, AC
A flaw was found in multicluster-global-hub. The manager component improperly validates the source identity of incoming
CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to validate the integrity of the DataStore, a non-partition
Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, Better Auth's OAuth callback
A vulnerability was identified in Linux Foundation Magma 1.9.0. This affects an unknown function of the component Securi
Hono is a Web application framework that provides support for any JavaScript runtime. In versions 4.12.0 and 4.12.1, whe
Improper session management in D-Link Wireless N 300 ADSL2+ Modem Router DSL-124 ME_1.00 allows attackers to execute a s
ZeptoClaw is a personal AI assistant. Prior to 0.7.6, the generic webhook channel trusts caller-supplied identity fields
Frequently Asked Questions
What is CWE-345?
CWE-345 (CWE-345) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-345?
There are 248 CVE records associated with CWE-345 in our database. Of these, 30 are critical severity, 73 are high severity, and 103 are medium severity.
How can I protect against CWE-345 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-345 using AI-powered security agents.
Detect CWE-345 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-345 vulnerabilities across your infrastructure.
Get Started