Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 1.0.750 Application 20.0.1442 allows Insecure Firmwar
IEEE P802.11-REVme D1.1 through D7.0 allows FragAttacks against mesh networks. In mesh networks using Wi-Fi Protected Ac
Fabio is an HTTP(S) and TCP router for deploying applications managed by consul. Prior to version 1.6.6, Fabio allows cl
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. The offici
The backup ZIPs are not signed by the application, leading to the possibility that an attacker can download a backup ZIP
The executable file warning did not warn users before opening files with the `terminal` extension. *This bug only affec
OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the password reset workflo
Insufficient data authenticity verification vulnerability in Janto, versions prior to r12. This allows an unauthenticate
libsignal-service-rs is a Rust version of the libsignal-service-java library which implements the core functionality to
Vela is a Pipeline Automation (CI/CD) framework built on Linux container technology written in Golang. Prior to versions
In HDP Server versions below 4.6.2.2978 on Linux, unauthorized access could occur via IP spoofing using the X-Forwarded-
React Router is a router for React. In versions on the 7.0 branch prior to version 7.5.2, it's possible to modify pre-re
A vulnerability classified as critical was found in Comodo Internet Security Premium 12.3.4.8162. This vulnerability aff
Ceph is a distributed object, block, and file storage platform. In versions 19.2.3 and below, it is possible to send an
A vulnerability has been identified within Rancher Manager whereby the SAML authentication from the Rancher CLI tool is
Insufficient verification of data authenticity in some Intel(R) DSA software before version 23.4.39 may allow an authent
Acceptance of extraneous untrusted data with trusted data in UrlMon allows an unauthorized attacker to bypass a security
Clerk helps developers build user management. Applications that use the verifyWebhook() helper to verify incoming Clerk
An attacker spoofing answers to ECS enabled requests sent out by the Recursor has a chance of success higher than non-EC
Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.4, Authlib’s JWS verific
There is a vulnerability in the BMC firmware image authentication design at Supermicro MBD-X12DPG-OA6 . An attacker
A vulnerability was determined in Belkin AX1800 1.1.00.016. Affected by this vulnerability is an unknown functionality o
eprosima Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management
Cross-Domain Token Exposure in server.auth.getAuthorizationToken in Ollama 0.6.7 allows remote attackers to steal authen
Pioneer DMH-WT7600NEX Software Update Signing Insufficient Verification of Data Authenticity Vulnerability. This vulnera
Pioneer DMH-WT7600NEX Root Filesystem Insufficient Verification of Data Authenticity Vulnerability. This vulnerability a
LocalSend is an open-source app to securely share files and messages with nearby devices over local networks without nee
An issue in the firmware update mechanism of Nous W3 Smart WiFi Camera v1.33.50.82 allows unauthenticated and physically
A vulnerability was determined in D-Link DIR-619L 6.02CN02. Affected is the function FirmwareUpgrade of the component bo
A vulnerability was identified in Tenda AC15 15.13.07.13. Affected by this vulnerability is the function check_fw_type/s
A vulnerability has been found in Tenda G1 16.01.7.8(3660). Affected by this issue is the function check_upload_file of
A weakness has been identified in D-Link DAP-2695 2.00RC13. The affected element is the function sub_40C6B8 of the compo
Thunderbird displayed an incorrect sender address if the From field of an email used the invalid group name syntax that
picklescan before 0.0.23 is vulnerable to a ZIP archive manipulation attack that causes it to crash when attempting to e
Insufficient verification of data authenticity in some Zoom Workplace Apps may allow an unprivileged user to conduct a d
fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to 5.0.6, the fast-jwt library does not properly valid
In handleBondStateChanged of AdapterService.java, there is a possible permission bypass due to misleading or insufficien
Insufficient Verification of Data Authenticity vulnerability in GE Vernova UR IED family devices allows an authenticated
Insufficient verification of data authenticity in Windows Virtualization-Based Security (VBS) Enclave allows an authoriz
A vulnerability has been found in IROAD Dash Cam X5 and Dash Cam X6 up to 20250308 and classified as problematic. This v
A mail spoofing vulnerability in Xerox Workplace Suite allows attackers to forge email headers, making it appear as thou
A vulnerability was identified in chatwoot up to 4.7.0. This vulnerability affects the function initPostMessageCommunica
The Subscriptions & Memberships for PayPal plugin for WordPress is vulnerable to fake payment creation in all versions u
A security vulnerability has been detected in PbootCMS up to 3.2.12. The affected element is the function get_user_ip of
regclient is a Docker and OCI Registry Client in Go. A malicious registry could return a different digest for a pinned m
Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (
A vulnerability classified as problematic has been found in gradio-app gradio up to 5.29.1. This affects the function is
A vulnerability classified as problematic was found in Eluktronics Control Center 5.23.51.41. Affected by this vulnerabi
Rapid7 AppSpider Pro versions below 7.5.021 suffer from a project name validation vulnerability, whereby an attacker can
An insufficient verification of data authenticity vulnerability exists in BIG-IP APM Access Policy endpoint inspection t
Frequently Asked Questions
What is CWE-345?
CWE-345 (CWE-345) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-345?
There are 819 CVE records associated with CWE-345 in our database. Of these, 88 are critical severity, 254 are high severity, and 289 are medium severity.
How can I protect against CWE-345 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-345 using AI-powered security agents.
Detect CWE-345 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-345 vulnerabilities across your infrastructure.
Get Started