New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to versio
SimpleSAMLphp versions before 1.18.6 contain an information disclosure vulnerability. Prior to 2.4.7 and 2.5.2, SimpleSA
Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tamperin
An issue in the firmware update mechanism of Qianniao QN-L23PA0904 v20250721.1640 allows attackers to gain root access,
pnpm is a package manager. Prior to 10.34.0 and 11.4.0, `pnpm install` in non-frozen mode can accept new remote package
NextAuth.js provides authentication for Next.js. Prior to@auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, Auth
openssl_encrypt before 1.4.9 fails to prevent namespace collisions between own identities and contacts in IdentityStore,
EMQX is a scalable and reliable MQTT broker for AI, IoT, IIoT, and connected vehicles. Prior to versions 5.8.11, 5.9.3,
SiYuan versions before v3.7.4 fail to validate that packageName matches the downloaded package content in bazaar install
Crafted delegations or IP fragments can poison cached delegations in Recursor.
User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attack
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5,
OpenClaw is a personal AI assistant. Discovery beacons (Bonjour/mDNS and DNS-SD) include TXT records such as `lanHost`,
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the PayPal IPN v1 handler at plugin/PayPalYPT/
TypeBot is a chatbot builder tool. In versions 3.16.0 and prior, the WhatsApp Cloud API webhook endpoint (POST /v1/works
Firefox for iOS used partial domain matching when attaching cookies to PDF requests, allowing a malicious site on a suff
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, the Body Limit M
vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.22.0, vLLM's revision pinning contr
Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, the AWS SES bounce
sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 3.1.1, @sigstore/verify deriv
WWBN AVideo is an open source video platform. In versions prior to 29.0, the Authorize.Net webhook handler at plugin/Aut
In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when an auth/rpz zone has a configured primary hostname that res
Knot DNS before 3.4.10 and 3.5.x before 3.5.4 contains a vulnerability in mod-onlinesign where the next NSEC owner name
marimo before 0.23.15 contains a configuration injection vulnerability that allows notebook authors to exfiltrate operat
A flaw was found in openshift/oauth-proxy. On paths configured to bypass authentication (skip-auth-regex), the proxy for
An issue in the billing and license activation subsystem allows remote attackers to bypass payment authorization workflo
Insufficient verification of data authenticity in Smart Switch trouble scanning mode prior to version 3.7.72.6 allows ad
Cleartext storage in PostgreSQL pgcrypto disabled ciphers allows a user to recover cleartext, via direct observation of
go-chi/chi versions 0.9.0 before 5.3.0 contains an IP spoofing vulnerability in the RealIP middleware, which resolves th
CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, canonicalizeParams in src/utils/cache.t
WWBN AVideo through commit 9c39d8c8b4c1f75540788d6b391740852ceb0732 contains an authorization bypass vulnerability in th
joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standar
pac4j-oidc before 6.5.6 accepts OIDC callbacks carrying only an access token without authorization code or ID token vali
OpenProject is an open-source, web-based project management software. In the new editor for collaborative documents base
Wazuh 5.0.0-beta1 (fixed in 5.0.0-beta3) does not validate or override the cluster_name and cluster_node fields in inven
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other
A vulnerability exists in NGINX OSS and NGINX Plus when configured to proxy to upstream Transport Layer Security (TLS) s
Insufficient verification of data authenticity in Windows App Installer allows an unauthorized attacker to perform spoof
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to version
Missing expiration, hash, and length enforcement in delegated metadata validation in awslabs/tough before tough-v0.22.0
Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.1-4-ge2626659, Micro
Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to
In Progress® Telerik® UI for AJAX prior to v2026.2.708, DialogHandler request parameters may be tampered with, potential
The Formidable Forms WordPress plugin before 6.32.1 does not properly validate the status of a PayPal subscription payme
The GetPaid WordPress plugin before 2.8.55 does not verify the authenticity of incoming Worldpay payment notifications,
The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not validate the payment amount or bind the PayPal
Traefik is an HTTP reverse proxy and load balancer. Prior to v2.11.51, v3.6.22, and v3.7.6, Traefik's ForwardAuth middle
Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7,
HCL AION is affected by a vulnerability where generated containers may execute binaries with root-level privileges. Runn
Frequently Asked Questions
What is CWE-345?
CWE-345 (CWE-345) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-345?
There are 819 CVE records associated with CWE-345 in our database. Of these, 88 are critical severity, 254 are high severity, and 289 are medium severity.
How can I protect against CWE-345 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-345 using AI-powered security agents.
Detect CWE-345 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-345 vulnerabilities across your infrastructure.
Get Started