The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to payment bypass in all versi
Insufficient verification of data authenticity issue in Survey Maker prior to 3.6.4 allows a remote unauthenticated atta
sshpiper is a reverse proxy for sshd. Starting in version 1.0.50 and prior to version 1.3.0, the way the proxy protocol
Insufficient Verification of Data Authenticity vulnerability in Cozmoslabs Profile Builder allows Functionality Bypass.T
The Claudio Sanches – Checkout Cielo for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of
The Authorize.net Payment Gateway For WooCommerce plugin for WordPress is vulnerable to payment bypass in all versions u
In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, due to a code logic error, filtering funct
The Web Application Firewall plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including,
Dovecot accepts dot LF DOT LF symbol as end of DATA command. RFC requires that it should always be CR LF DOT CR LF. This
The Limit Login Attempts Plus plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including
The goTenna Pro ATAK Plugin uses AES CTR type encryption for short, encrypted messages without any additional integrity
The goTenna Pro App uses AES CTR type encryption for short, encrypted messages without any additional integrity checkin
IPP software versions prior to v1.71 do not sufficiently verify the authenticity of data, in a way that causes it to acc
An insufficient verification of data authenticity vulnerability [CWE-345] in Fortinet FortiOS SSL-VPN tunnel mode versio
The WooCommerce POS plugin for WordPress is vulnerable to information disclosure in all versions up to, and including, 1
ThroughTek Kalay SDK does not verify the authenticity of received messages, allowing an attacker to impersonate an autho
A vulnerability was found in OIDC-Client. When using the RH SSO OIDC adapter with EAP 7.x or when using the elytron-oidc
Use of Less Trusted Source vulnerability in SolidWP Solid Security allows HTTP DoS.This issue affects Solid Security: fr
Insufficient verification of data authenticity in the configuration state machine may allow a local attacker to potentia
Client use of server error message in PostgreSQL allows a server not trusted under current SSL or GSS settings to furnis
Missing Authentication for Critical Function vulnerability in Mitsubishi Electric Corporation MELSEC-F Series CPU module
BlackVue DR750-2CH LTE v.1.012_2022.10.26 does not employ authenticity check for uploaded firmware. This can allow attac
The Wordapp plugin for WordPress is vulnerable to authorization bypass due to an use of insufficiently unique cryptograp
Controller may be loaded with malicious firmware which could enable remote code execution. See Honeywell Security Notifi
In PHP Jabbers Class Scheduling System 1.0, lack of verification when changing an email address and/or password (on the
In PHPJabbers Cleaning Business Software 1.0, lack of verification when changing an email address and/or password (on th
authentik is an open-source Identity Provider. Due to an insufficient access check, a recovery flow link that is created
AMI MegaRAC SPx12 and SPx13 devices have Insufficient Verification of Data Authenticity.
Insufficient verification of data authenticity vulnerability in Delinea Secret Server, in its v10.9.000002 version. An a
A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists in the Data Server that could cause manip
In EVE OS, the “measured boot” mechanism prevents a compromised device from accessing the encrypted data located in t
Composer before 2016-02-10 allows cache poisoning from other projects built on the same host. This results in attacker-c
Insufficient data validation in USB in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to perform out of
Snap One OvrC Pro devices versions 7.2 and prior do not validate firmware updates correctly. The device only calculates
Insufficient authentication in the MQTT backend (broker) allows an attacker to access and even manipulate the telemetry
Home assistant is an open source home automation. The Home Assistant Companion for Android app up to version 2023.8.2 is
The CMS Commander plugin for WordPress is vulnerable to authorization bypass due to the use of an insufficiently unique
Insufficient verification of data authenticity in Zoom Desktop Client for Windows before 5.14.5 may allow an authenticat
The driver installation package created by Printer Driver Packager NX v1.0.02 to v1.1.25 fails to detect its modificatio
An issue was discovered on AudioCodes VoIP desk phones through 3.4.4.1000. The validation of firmware images only consis
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. An attacker with the ability
SwagPayPal is a PayPal integration for shopware/platform. If JavaScript-based PayPal checkout methods are used (PayPal P
Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verify
Versions of the package sidekiq before 7.1.3 are vulnerable to Denial of Service (DoS) due to insufficient checks in the
When the Node.js policy feature checks the integrity of a resource against a trusted manifest, the application can inter
joaquimserafim/json-web-token is a javascript library use to interact with JSON Web Tokens (JWT) which are a compact URL
Insufficient Verification of Data Authenticity vulnerability in Routine prior to versions 2.6.30.6 in Android Q(10), 3.1
Rumpus - FTP server version 9.0.7.1 Improper Token Verification– vulnerability may allow bypassing identity verification
If an attacker can trick an authenticated user into loading a maliciously crafted .zip file onto Advantech WebAccess ve
Frequently Asked Questions
What is CWE-345?
CWE-345 (CWE-345) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-345?
There are 819 CVE records associated with CWE-345 in our database. Of these, 88 are critical severity, 254 are high severity, and 289 are medium severity.
How can I protect against CWE-345 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-345 using AI-powered security agents.
Detect CWE-345 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-345 vulnerabilities across your infrastructure.
Get Started