stats is a macOS system monitor in for the menu bar. The Stats application is vulnerable to a local privilege escalation
Hickory DNS is a Rust based DNS client, server, and resolver. A vulnerability present starting in version 0.8.0 and prio
RISC Zero is a general computing platform based on zk-STARKs and the RISC-V microarchitecture. Due to a missing constrai
Matrix JavaScript SDK is a Matrix Client-Server SDK for JavaScript and TypeScript. matrix-js-sdk before 38.2.0 has insuf
On Wear OS devices, when Google Messages is configured as the default SMS/MMS/RCS application, the handling of ACTION_SE
eGovFramework/egovframe-common-components versions up to and including 4.3.1 includes Web Editor image upload and relate
CGGMP24 is a state-of-art ECDSA TSS protocol that supports 1-round signing (requires 3 preprocessing rounds), identifiab
The `fetch()` API and navigation incorrectly shared the same cache, as the cache key did not include the optional header
A code injection vulnerability exists in the scan_lib.bin functionality of AutomationDirect P3-550E 1.2.10.9. A speciall
Traefik is a golang, Cloud Native Application Proxy. When a HTTP request is processed by Traefik, certain HTTP headers s
Affected devices beacon to eCharge cloud infrastructure asking if there are any command they should run. This communicat
dnsjava is an implementation of DNS in Java. Records in DNS replies are not checked for their relevance to the query, al
Unitronics Unistream Unilogic – Versions prior to 1.35.227 - CWE-348: Use of Less Trusted Source may allow RCE
NETGEAR RAX30 lighttpd Misconfiguration Remote Code Execution Vulnerability. This vulnerability allows network-adjacent
Insufficient data validation in Updater in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to perform OS-
Insufficient data validation in Dawn in Google Chrome on Android prior to 127.0.6533.88 allowed a remote attacker to exe
Insufficient data validation in Installer in Google Chrome on Windows prior to 128.0.6613.84 allowed a local attacker to
Insufficient data validation in Installer in Google Chrome on Windows prior to 128.0.6613.84 allowed a local attacker to
Visteon Infotainment VIP MCU Code Insufficient Validation of Data Authenticity Local Privilege Escalation Vulnerability.
VULNERABILITY DETAILS Rockwell Automation used the latest versions of the CVSS scoring system to assess the following v
To address a cache poisoning risk in Moodle, additional validation for local storage was required.
Vulnerability of trust relationships being inaccurate in distributed scenarios. Successful exploitation of this vulnerab
Astro-Shield is an integration to enhance website security with SubResource Integrity hashes, Content-Security-Policy he
Vulnerability of package name verification being bypassed in the Calendar app. Impact: Successful exploitation of this v
Insufficient verification of data authenticity issue exists in NJ Series CPU Unit all versions and NX Series CPU Unit al
In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can modify the plaintext Extra Count field of a confidential GSS
Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verify
Windows DNS Spoofing Vulnerability
Windows Print Spooler Elevation of Privilege Vulnerability
An issue was discovered in Technitium through 11.0.3. It enables attackers to conduct a DNS cache poisoning attack and i
Gradio is an open-source Python package designed for quick prototyping. This vulnerability is a **lack of integrity chec
A flaw was found in Red Hat Enterprise Application Platform 8. When an OIDC app that serves multiple tenants attempts to
Invision Community through 4.7.16 allows remote code execution via the applications/core/modules/admin/editor/toolbar.ph
Moby is an open-source project created by Docker to enable software containerization. The classic builder cache system i
gitoxide An idiomatic, lean, fast & safe pure Rust implementation of Git. `gix-path` can be tricked into running another
Sony XAV-AX5500 Insufficient Firmware Update Validation Remote Code Execution Vulnerability. This vulnerability allows p
An attacker who can execute arbitrary Operating Systems commands, can bypass code signing enforcements in the kernel, an
Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR15, 4.0.0 SR05, 4.1.0 SR03, and 4.2.0 SR02 fails to validate
CMSaaSStarter is a SaaS template/boilerplate built with SvelteKit, Tailwind, and Supabase. Any forks of the CMSaaSStarte
A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions < V3.0.1.1), SIMATIC
ESP-NOW Component provides a connectionless Wi-Fi communication protocol. An replay attacks vulnerability was discovered
quic-go is an implementation of the QUIC protocol in Go. An off-path attacker can inject an ICMP Packet Too Large packet
Meshtastic is an open source, off-grid, decentralized, mesh network built to run on affordable, low-power devices. Mesht
An attacker with access to the private network (the charger is connected to) or local access to the Ethernet-Interface c
IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security V
A flaw was found in Booth, a cluster ticket manager. If a specially-crafted hash is passed to gcry_md_get_algo_dlen(), i
Read/Write vulnerability in the image decoding module Impact: Successful exploitation of this vulnerability will affect
Querybook is a Big Data Querying UI, combining collocated table metadata and a simple notebook interface. Querybook's da
Matrix Tafnit v8 - CWE-646: Reliance on File Name or Extension of Externally-Supplied File
aiosmtpd is a reimplementation of the Python stdlib smtpd.py based on asyncio. aiosmtpd is vulnerable to inbound SMTP sm
Frequently Asked Questions
What is CWE-345?
CWE-345 (CWE-345) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-345?
There are 819 CVE records associated with CWE-345 in our database. Of these, 88 are critical severity, 254 are high severity, and 289 are medium severity.
How can I protect against CWE-345 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-345 using AI-powered security agents.
Detect CWE-345 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-345 vulnerabilities across your infrastructure.
Get Started