Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-345

MITRE ↗

CWE-345

88
CRITICAL
254
HIGH
289
MEDIUM
41
LOW
702 CVEs · Page 6/15
9.1
CVE-2025-27680

Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 1.0.750 Application 20.0.1442 allows Insecure Firmwar

9.1
CVE-2025-27558

IEEE P802.11-REVme D1.1 through D7.0 allows FragAttacks against mesh networks. In mesh networks using Wi-Fi Protected Ac

9.1
CVE-2025-48865

Fabio is an HTTP(S) and TCP router for deploying applications managed by consul. Prior to version 1.6.6, Fabio allows cl

9.1
CVE-2025-59951

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. The offici

8.8
CVE-2025-49199

The backup ZIPs are not signed by the application, leading to the possibility that an attacker can download a backup ZIP

8.8
CVE-2025-6426

The executable file warning did not warn users before opening files with the `terminal` extension. *This bug only affec

8.8
CVE-2025-66225

OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the password reset workflo

8.6
CVE-2025-1108

Insufficient data authenticity verification vulnerability in Janto, versions prior to r12. This allows an unauthenticate

8.5
CVE-2025-24903

libsignal-service-rs is a Rust version of the libsignal-service-java library which implements the core functionality to

8.5
CVE-2025-27616

Vela is a Pipeline Automation (CI/CD) framework built on Linux container technology written in Golang. Prior to versions

8.4
CVE-2025-6504

In HDP Server versions below 4.6.2.2978 on Linux, unauthorized access could occur via IP spoofing using the X-Forwarded-

8.2
CVE-2025-43865

React Router is a router for React. In versions on the 7.0 branch prior to version 7.5.2, it's possible to modify pre-re

8.1
CVE-2025-7096

A vulnerability classified as critical was found in Comodo Internet Security Premium 12.3.4.8162. This vulnerability aff

8.1
CVE-2024-48916

Ceph is a distributed object, block, and file storage platform. In versions 19.2.3 and below, it is possible to send an

8.0
CVE-2024-58267

A vulnerability has been identified within Rancher Manager whereby the SAML authentication from the Rancher CLI tool is

7.8
CVE-2024-39805

Insufficient verification of data authenticity in some Intel(R) DSA software before version 23.4.39 may allow an authent

7.5
CVE-2025-29842

Acceptance of extraneous untrusted data with trusted data in UrlMon allows an unauthorized attacker to bypass a security

7.5
CVE-2025-53548

Clerk helps developers build user management. Applications that use the verifyWebhook() helper to verify incoming Clerk

7.5
CVE-2025-30192

An attacker spoofing answers to ECS enabled requests sent out by the Recursor has a chance of success higher than non-EC

7.5
CVE-2025-59420

Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.4, Authlib’s JWS verific

7.2
CVE-2024-10237

There is a vulnerability in the BMC firmware image authentication design at Supermicro MBD-X12DPG-OA6 . An attacker

7.2
CVE-2025-9379

A vulnerability was determined in Belkin AX1800 1.1.00.016. Affected by this vulnerability is an unknown functionality o

7.1
CVE-2025-24807

eprosima Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management

6.9
CVE-2025-51471

Cross-Domain Token Exposure in server.auth.getAuthorizationToken in Ollama 0.6.7 allows remote attackers to steal authen

6.8
CVE-2025-5832

Pioneer DMH-WT7600NEX Software Update Signing Insufficient Verification of Data Authenticity Vulnerability. This vulnera

6.8
CVE-2025-5833

Pioneer DMH-WT7600NEX Root Filesystem Insufficient Verification of Data Authenticity Vulnerability. This vulnerability a

6.8
CVE-2025-54792

LocalSend is an open-source app to securely share files and messages with nearby devices over local networks without nee

6.8
CVE-2025-56438

An issue in the firmware update mechanism of Nous W3 Smart WiFi Camera v1.33.50.82 allows unauthenticated and physically

6.6
CVE-2025-8978

A vulnerability was determined in D-Link DIR-619L 6.02CN02. Affected is the function FirmwareUpgrade of the component bo

6.6
CVE-2025-8979

A vulnerability was identified in Tenda AC15 15.13.07.13. Affected by this vulnerability is the function check_fw_type/s

6.6
CVE-2025-8980

A vulnerability has been found in Tenda G1 16.01.7.8(3660). Affected by this issue is the function check_upload_file of

6.6
CVE-2025-12295

A weakness has been identified in D-Link DAP-2695 2.00RC13. The affected element is the function sub_40C6B8 of the compo

6.5
CVE-2025-0510

Thunderbird displayed an incorrect sender address if the From field of an email used the invalid group name syntax that

6.5
CVE-2025-1944

picklescan before 0.0.23 is vulnerable to a ZIP archive manipulation attack that causes it to crash when attempting to e

6.5
CVE-2025-0149

Insufficient verification of data authenticity in some Zoom Workplace Apps may allow an unprivileged user to conduct a d

6.5
CVE-2025-30144

fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to 5.0.6, the fast-jwt library does not properly valid

6.5
CVE-2025-0092

In handleBondStateChanged of AdapterService.java, there is a possible permission bypass due to misleading or insufficien

6.1
CVE-2025-27257

Insufficient Verification of Data Authenticity vulnerability in GE Vernova UR IED family devices allows an authenticated

6.0
CVE-2025-27735

Insufficient verification of data authenticity in Windows Virtualization-Based Security (VBS) Enclave allows an authoriz

5.6
CVE-2025-2346

A vulnerability has been found in IROAD Dash Cam X5 and Dash Cam X6 up to 20250308 and classified as problematic. This v

5.3
CVE-2024-55929

A mail spoofing vulnerability in Xerox Workplace Suite allows attackers to forge email headers, making it appear as thou

5.3
CVE-2025-12245

A vulnerability was identified in chatwoot up to 4.7.0. This vulnerability affects the function initPostMessageCommunica

5.3
CVE-2025-12752

The Subscriptions & Memberships for PayPal plugin for WordPress is vulnerable to fake payment creation in all versions u

5.3
CVE-2025-15154

A security vulnerability has been detected in PbootCMS up to 3.2.12. The affected element is the function get_user_ip of

5.2
CVE-2025-24882

regclient is a Docker and OCI Registry Client in Go. A malicious registry could return a different digest for a pinned m

3.9
CVE-2025-59700

Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (

3.7
CVE-2025-5320

A vulnerability classified as problematic has been found in gradio-app gradio up to 5.29.1. This affects the function is

3.3
CVE-2025-7884

A vulnerability classified as problematic was found in Eluktronics Control Center 5.23.51.41. Affected by this vulnerabi

3.3
CVE-2025-11195

Rapid7 AppSpider Pro versions below 7.5.021 suffer from a project name validation vulnerability, whereby an attacker can

3.1
CVE-2025-23415

An insufficient verification of data authenticity vulnerability exists in BIG-IP APM Access Policy endpoint inspection t

Frequently Asked Questions

What is CWE-345?

CWE-345 (CWE-345) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-345?

There are 819 CVE records associated with CWE-345 in our database. Of these, 88 are critical severity, 254 are high severity, and 289 are medium severity.

How can I protect against CWE-345 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-345 using AI-powered security agents.

Detect CWE-345 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-345 vulnerabilities across your infrastructure.

Get Started