An insufficient verification of data vulnerability exists in BIG-IP Edge Client Installer on macOS that may allow an at
Arduino Create Agent is a package to help manage Arduino development. The vulnerability affects the endpoint `/v2/pkgs/t
Altenergy Power Control Software C1.2.5 was discovered to contain a remote code execution (RCE) vulnerability via the co
Bashis, a Security Researcher at IPVM has found a flaw that allows for a remote code execution during the installation o
vantage6 is a framework to manage and deploy privacy enhancing technologies like Federated Learning (FL) and Multi-Party
An insufficient verification of data vulnerability exists in BIG-IP Edge Client for Windows and macOS that may allow an
A local user could edit the VideoEdge configuration file and interfere with VideoEdge operation.
A flaw was found in Open vSwitch that allows ICMPv6 Neighbor Advertisement packets between virtual machines to bypass Op
Home assistant is an open source home automation. Whilst auditing the frontend code to identify hidden parameters, Cure5
Kyverno is a policy engine designed for Kubernetes. An issue was found in Kyverno that allowed an attacker to control th
ManageEngine ADSelfService Plus GINA Client Insufficient Verification of Data Authenticity Authentication Bypass Vulnera
xml-security is a library that implements XML signatures and encryption. Validation of an XML signature requires verific
Snap One Wattbox WB-300-IP-3 versions WB10.9a17 and prior use a proprietary local area network (LAN) protocol that does
A GRE dataset file within Systems Manager can be tampered with and distributed to PCUs.
A vulnerability in the iPXE boot function of Cisco IOS XR software could allow an authenticated, local attacker to insta
Insufficient checks in SEV may lead to a malicious hypervisor disclosing the launch secret potentially resulting in comp
Akuvox E11 does not ensure that a file extension is associated with the file provided. This could allow an attacker to u
A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists in the Data Server that could cause acces
A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists in the Data Server that could allow the r
The Hide My WP Ghost – Security Plugin plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and
Insufficient data validation in DevTools in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to bypass nav
Insufficient Verification of Data Authenticity vulnerability in Apache InLong.This issue affects Apache InLong: from 1.4
OpenZeppelin Contracts for Cairo is a library for secure smart contract development written in Cairo for StarkNet, a dec
In JetBrains IntelliJ IDEA before 2023.3.2 code execution was possible in Untrusted Project mode via a malicious plugin
Kyverno is a policy engine designed for Kubernetes. A security vulnerability was found in Kyverno where an attacker coul
Electron is an open source framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Thi
An issue in AsyncSSH before 2.14.1 allows attackers to control the extension info message (RFC 8308) via a man-in-the-mi
In modem, there is a possible missing verification of HashMME value in Security Mode Command. This could local denial of
A man in the middle can redirect traffic to a malicious server in a compromised configuration.
IBM Aspera Faspex 5.0.5 could allow a remote attacked to bypass IP restrictions due to improper access controls. IBM X-
A insufficient verification of data authenticity vulnerability [CWE-345] in FortiAnalyzer version 7.4.0 and below 7.2.3
When using the default implementation of Verify to check a Captcha, verification can be bypassed. For example, if the fi
Postfix through 3.8.5 allows SMTP smuggling unless configured with smtpd_data_restrictions=reject_unauth_pipelining and
sendmail through 8.17.2 allows SMTP smuggling in certain configurations. Remote attackers can use a published exploitati
Exim before 4.97.1 allows SMTP smuggling in certain PIPELINING/CHUNKING configurations. Remote attackers can use a publi
The firmware update package for the wireless card is not properly signed and can be modified.
Jenkins SAML Single Sign On(SSO) Plugin 2.0.2 and earlier does not perform hostname validation when connecting to miniOr
A vulnerability classified as critical has been found in Zerocoin libzerocoin. Affected is the function CoinSpend::CoinS
In JetBrains IntelliJ IDEA before 2023.1 in some cases, Gradle and Maven projects could be imported without the “Trust P
Insufficient validation of address mapping to IO in ASP (AMD Secure Processor) may result in a loss of memory integrity
The Brizy Page Builder plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 2.4.1
Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 0.35.0, p
Graylog is a free and open log management platform. Graylog makes use of only one single source port for DNS queries. Gr
Stronger revision number limitations were required on file serving endpoints to improve cache poisoning protection.
A vulnerability was found in EmpowerID up to 7.205.0.0. It has been rated as problematic. This issue affects some unknow
HashiCorp Boundary up to 0.10.1 did not properly perform data integrity checks to ensure the resources were associated w
Pexip Infinity Connect before 1.8.0 omits certain provisioning authenticity checks. Thus, untrusted code may execute.
In JetBrains Hub before 2022.1.14434, SAML request takeover was possible.
A command injection vulnerability exists in the Xiaomi Router AX3600. The vulnerability is caused by a lack of inspectio
An arbitrary file upload vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to upl
Frequently Asked Questions
What is CWE-345?
CWE-345 (CWE-345) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-345?
There are 819 CVE records associated with CWE-345 in our database. Of these, 88 are critical severity, 254 are high severity, and 289 are medium severity.
How can I protect against CWE-345 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-345 using AI-powered security agents.
Detect CWE-345 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-345 vulnerabilities across your infrastructure.
Get Started