PAX A930 device with PayDroid_7.1.1_Virgo_V04.3.26T1_20210419 can allow a root privileged attacker to install unsigned p
A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists that could cause loading of unauthorized
Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulenrable to CWE-353 Missing Support for Integrity
A vulnerability in the implementation of the Datagram TLS (DTLS) protocol in Cisco Adaptive Security Appliance (ASA) Sof
immudb is a database with built-in cryptographic proof and verification. immudb client SDKs use server's UUID to disting
Some Xiaomi phones have information leakage vulnerabilities, and some of them may be able to forge a specific identity d
In SettingsActivity.java, there is a possible way to make a device discoverable over Bluetooth, without permission or us
A logic issue was addressed with improved state management. This issue is fixed in Safari 16.2, tvOS 16.2, iCloud for Wi
Due to insufficient input validation, SAP Business Objects - version 420, allows an authenticated attacker to submit a m
immudb is a database with built-in cryptographic proof and verification. In versions prior to 1.4.1, a malicious immudb
In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, X-Forwarded-For headers could be used to spoof a user's IP, in order to
An issue in Netgear WNR2000 v1 1.2.3.7 and earlier allows authenticated attackers to cause a Denial of Service (DoS) via
Select Dell Client Commercial and Consumer platforms are vulnerable to an insufficient verification of data authenticity
Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulnerable to CWE-345 Insufficient Verification of
An insufficient verification of data authenticity vulnerability [CWE-345] in FortiClient, FortiMail and FortiOS AV engin
An issue was discovered in certain Verbatim drives through 2022-03-31. Due to missing integrity checks, an attacker can
Insufficient check of the process type in Trusted OS (TOS) may allow an attacker with privileges to enable a lesser priv
The Custom Content Shortcode WordPress plugin before 4.0.2 does not validate the data passed to its load shortcode, whic
It was found that a specially crafted LUKS header could trick cryptsetup into disabling encryption during the recovery o
BigBlueButton is an open source web conferencing system. Versions prior to 2.4.3, are subject to Insufficient Verificati
BigBlueButton is an open source web conferencing system. Versions prior to 2.4-rc-6 are subject to Ineffective user bans
When loading a script with Subresource Integrity, attackers with an injection capability could trigger the reuse of prev
ENC DataVault 7.2.3 and before, and OEM versions, use an encryption algorithm that is vulnerable to data manipulation (w
A firmware update vulnerability exists in the sysupgrade functionality of Robustel R1510 3.1.16 and 3.3.0. A specially-c
Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Prior to versions 21.0.
This vulnerability arises because the application allows the user to perform some sensitive action without verifying tha
Monal before 4.9 does not implement proper sender verification on MAM and Message Carbon (XEP-0280) results. This allows
Insufficient Verification of Data Authenticity in Nagios Fusion 4.1.8 and earlier and Nagios XI 5.7.5 and earlier allows
Zoho ManageEngine ADSelfService Plus 6103 and prior is vulnerable to admin portal access-restriction bypass.
A vulnerability in Base Software for SoftControl allows an attacker to insert and run arbitrary code in a computer runni
An arbitrary file download and execution vulnerability was found in the VideoOffice X2.9 and earlier versions (CVE-2020-
There is a improper privilege management vulnerability in some Huawei smartphone. Successful exploitation of this vulner
The npm ci command in npm 7.x and 8.x through 8.1.3 proceeds with an installation even if dependency information in pack
wire-ios is the iOS version of Wire, an open-source secure messaging app. wire-ios versions 3.8.0 and earlier have a bug
A vulnerability has been identified in Mendix SAML Module (All versions < V2.1.2). The configuration of the SAML module
NVCaffe's python required dependencies list used to contain `gfortran`version prior to 0.17.4, entry which does not exis
An arbitrary file download and execution vulnerability was found in the HShell.dll of handysoft Co., Ltd groupware Activ
An issue was discovered on Digi TransPort devices through 2021-07-21. An authenticated attacker may load customized firm
Certain Starcharge products are affected by Improper Input Validation. The affected products include: Nova 360 Cabinet <
A vulnerability in the Multi-Pod or Multi-Site network configurations for Cisco Nexus 9000 Series Fabric Switches in App
PuTTY through 0.75 proceeds with establishing an SSH session even if it has never sent a substantive authentication resp
CODESYS Development System 3 before 3.5.17.0 displays or executes malicious documents or files embedded in libraries wit
In JetBrains PyCharm before 2020.3.4, local code execution was possible because of insufficient checks when getting the
TensorFlow is an open source platform for machine learning. In affected versions an attacker can trigger undefined behav
When the AMD Platform Security Processor (PSP) boot rom loads, authenticates, and subsequently decrypts an encrypted FW,
The Portable SDK for UPnP Devices is an SDK for development of UPnP device and control point applications. The server pa
show_default.php in the LocalFilesEditor extension before 11.4.0.1 for Piwigo allows Local File Inclusion because the fi
The server in Luca through 1.1.14 allows remote attackers to cause a denial of service (insertion of many fake records r
A lack of target address verification in the selfdestructs() function of ICOVO 1.0 allows attackers to steal tokens from
A lack of target address verification in the BurnMe() function of Rob The Bank 1.0 allows attackers to steal tokens from
Frequently Asked Questions
What is CWE-345?
CWE-345 (CWE-345) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-345?
There are 819 CVE records associated with CWE-345 in our database. Of these, 88 are critical severity, 254 are high severity, and 289 are medium severity.
How can I protect against CWE-345 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-345 using AI-powered security agents.
Detect CWE-345 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-345 vulnerabilities across your infrastructure.
Get Started