A vulnerability in the web UI feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduc
The move_uploaded_file function in godomall5 does not perform an integrity check of extension or authority when user upl
A flaw was found in openstack-neutron's default Open vSwitch firewall rules. By sending carefully crafted packets, anyon
A flaw was found in RPM's signature check functionality when reading a package file. This flaw allows an attacker who ca
The USB firmware update script of homee Brain Cube v2 (2.28.2 and 2.28.4) devices allows an attacker with physical acces
Insufficient verification of data authenticity in Peloton TTR01 up to and including PTV55G allows an attacker with physi
There is a denial of service vulnerability in some versions of ManageOne. In specific scenarios, due to the insufficient
Through complicated navigations with new windows, an HTTP page could have inherited a secure lock icon from an HTTPS pag
Dell EMC PowerFlex, v3.5.x contain a Cross-Site WebSocket Hijacking Vulnerability in the Presentation Server/WebUI. An u
The ftp client in GNU Inetutils before 2.2 does not validate addresses returned by PASV/LSPV responses to make sure they
Enbra EWM 1.7.29 does not check for or detect replay attacks sent by wireless M-Bus Security mode 5 devices. Instead tim
The programmer installation utility does not perform a cryptographic authenticity or integrity checks of the software on
An issue was discovered in bluetoothd in BlueZ through 5.48. The vulnerability lies in the handling of a SVC_ATTR_REQ by
An insufficient verification of data authenticity vulnerability (CWE-345) in the user interface of FortiProxy verison 2.
wolfSSL before 4.8.1 incorrectly skips OCSP verification in certain situations of irrelevant response data that contains
When curl >= 7.20.0 and <= 7.78.0 connects to an IMAP or POP3 server to retrieve data using STARTTLS to upgrade to TLS s
in-toto-golang is a go implementation of the in-toto framework to protect software supply chain integrity. In affected v
An issue was discovered in Pillow before 8.2.0. For BLP data, BlpImagePlugin did not properly check that reads (after ju
A component of the HarmonyOS has a Insufficient Verification of Data Authenticity vulnerability. Local attackers may exp
A component of the HarmonyOS has a Insufficient Verification of Data Authenticity vulnerability. Local attackers may exp
FFmpeg N-98388-g76a3ee996b allows attackers to cause a denial of service (DoS) via a crafted audio file due to insuffici
A ZTE's product of the transport network access layer has a security vulnerability. Because the system does not sufficie
JWT is a library to work with JSON Web Token and JSON Web Signature. Prior to versions 3.4.6, 4.0.4, and 4.1.5, users of
Address bar search suggestions in private browsing mode were re-using session data from normal mode. *This bug only affe
GNOME Evolution through 3.38.3 produces a "Valid signature" message for an unknown identifier on a previously trusted ke
matrix-react-sdk is an npm package which is a Matrix SDK for React Javascript. In matrix-react-sdk before version 3.15.0
In FreeBSD 12.0-RELEASE before 12.0-RELEASE-p13, a missing check in the ipsec packet processor allows reinjection of an
Insufficient type checks were employed prior to casting input data in SimpleXMLElement_exportNode and simplexml_import_d
An issue was discovered on Samsung mobile devices with N(7.1), O(8.x), P(9.0), and Q(10.0) software. Arbitrary code exec
A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists which could allow the attacker to execute
In NETGEAR Nighthawk X10-R900 prior to 1.0.4.26, an attacker may bypass all authentication checks on the device's "NETGE
An exploitable remote code execution vulnerability exists in the Cloud Connectivity functionality of WAGO PFC200 version
An Insufficient Verification of Data Authenticity vulnerability in FortiManager 6.2.1, 6.2.0, 6.0.6 and below may allow
Insufficient data validation in developer tools in Google Chrome prior to 81.0.4044.92 allowed a remote attacker who had
An exploitable code execution vulnerability exists in the PLC_Task functionality of 3S-Smart Software Solutions GmbH COD
Mozilla Developer Iain Ireland discovered a missing type check during unboxed objects removal, resulting in a crash. We
Python TUF (The Update Framework) reference implementation before version 0.12 it will incorrectly trust a previously do
The pc-kernel snap build process hardcoded the --allow-insecure-repositories and --allow-unauthenticated apt options whe
HashiCorp Vault and Vault Enterprise versions 0.7.1 and newer, when configured with the AWS IAM auth method, may be vuln
PackageKit's apt backend mistakenly treated all local debs as trusted. The apt security model is based on repository tru
In Eclipse Theia versions 0.3.9 through 0.15.0, one of the default pre-packaged Theia extensions is "Mini-Browser", publ
An issue was discovered in OpenWrt 18.06.0 to 18.06.6 and 19.07.0, and LEDE 17.01.0 to 17.01.7. A bug in the fork of the
UR+ (Universal Robots+) is a platform of hardware and software component sellers, for Universal Robots robots. When inst
Mids' Reborn Hero Designer 2.6.0.7 downloads the update manifest, as well as update files, over cleartext HTTP. Addition
Ledger Live before 2.7.0 does not handle Bitcoin's Replace-By-Fee (RBF). It increases the user's balance with the value
In Foxit Reader and PhantomPDF before 10.0.1, and PhantomPDF before 9.7.3, attackers can obtain sensitive information ab
In ORY Fosite (the security first OAuth2 & OpenID Connect framework for Go) before version 0.31.0, when using "private_k
A bug in Nextcloud Server 17.0.1 causes the workflow rules to depend their behaviour on the file extension when checking
NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the service host component, in which the ap
An issue was discovered in ClamXAV 3 before 3.1.1. A malicious actor could use a properly signed copy of ClamXAV 2 (runn
Frequently Asked Questions
What is CWE-345?
CWE-345 (CWE-345) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-345?
There are 819 CVE records associated with CWE-345 in our database. Of these, 88 are critical severity, 254 are high severity, and 289 are medium severity.
How can I protect against CWE-345 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-345 using AI-powered security agents.
Detect CWE-345 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-345 vulnerabilities across your infrastructure.
Get Started