Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-345

MITRE ↗

CWE-345

88
CRITICAL
254
HIGH
289
MEDIUM
41
LOW
702 CVEs · Page 9/15
7.3
CVE-2023-5450

An insufficient verification of data vulnerability exists in BIG-IP Edge Client Installer on macOS that may allow an at

7.3
CVE-2023-43800

Arduino Create Agent is a package to help manage Arduino development. The vulnerability affects the endpoint `/v2/pkgs/t

7.2
CVE-2023-31502

Altenergy Power Control Software C1.2.5 was discovered to contain a remote code execution (RCE) vulnerability via the co

7.2
CVE-2023-5747

Bashis, a Security Researcher at IPVM has found a flaw that allows for a remote code execution during the installation o

7.2
CVE-2023-47631

vantage6 is a framework to manage and deploy privacy enhancing technologies like Federated Learning (FL) and Multi-Party

7.1
CVE-2023-36858

An insufficient verification of data vulnerability exists in BIG-IP Edge Client for Windows and macOS that may allow an

7.1
CVE-2023-3749

A local user could edit the VideoEdge configuration file and interfere with VideoEdge operation.

7.1
CVE-2023-5366

A flaw was found in Open vSwitch that allows ICMPv6 Neighbor Advertisement packets between virtual machines to bypass Op

7.1
CVE-2023-41896

Home assistant is an open source home automation. Whilst auditing the frontend code to identify hidden parameters, Cure5

7.1
CVE-2023-47630

Kyverno is a policy engine designed for Kubernetes. An issue was found in Kyverno that allowed an attacker to control th

6.8
CVE-2023-35719

ManageEngine ADSelfService Plus GINA Client Insufficient Verification of Data Authenticity Authentication Bypass Vulnera

6.8
CVE-2023-49087

xml-security is a library that implements XML signatures and encryption. Validation of an XML signature requires verific

6.7
CVE-2023-22315

Snap One Wattbox WB-300-IP-3 versions WB10.9a17 and prior use a proprietary local area network (LAN) protocol that does

6.7
CVE-2023-30562

A GRE dataset file within Systems Manager can be tampered with and distributed to PCUs.

6.7
CVE-2023-20236

A vulnerability in the iPXE boot function of Cisco IOS XR software could allow an authenticated, local attacker to insta

6.5
CVE-2021-26403

Insufficient checks in SEV may lead to a malicious hypervisor disclosing the launch secret potentially resulting in comp

6.5
CVE-2023-0350

Akuvox E11 does not ensure that a file extension is associated with the file provided. This could allow an attacker to u

6.5
CVE-2023-27977

A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists in the Data Server that could cause acces

6.5
CVE-2023-27979

A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists in the Data Server that could allow the r

6.5
CVE-2022-4537

The Hide My WP Ghost – Security Plugin plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and

6.5
CVE-2023-2314

Insufficient data validation in DevTools in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to bypass nav

6.5
CVE-2023-43666

Insufficient Verification of Data Authenticity vulnerability in Apache InLong.This issue affects Apache InLong: from 1.4

6.4
CVE-2023-23940

OpenZeppelin Contracts for Cairo is a library for secure smart contract development written in Cairo for StarkNet, a dec

6.3
CVE-2023-51655

In JetBrains IntelliJ IDEA before 2023.3.2 code execution was possible in Untrusted Project mode via a malicious plugin

6.1
CVE-2023-42816

Kyverno is a policy engine designed for Kubernetes. A security vulnerability was found in Kyverno where an attacker coul

6.1
CVE-2023-44402

Electron is an open source framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Thi

5.9
CVE-2023-46445

An issue in AsyncSSH before 2.14.1 allows attackers to control the extension info message (RFC 8308) via a man-in-the-mi

5.5
CVE-2022-44420

In modem, there is a possible missing verification of HashMME value in Security Mode Command. This could local denial of

5.4
CVE-2023-26467

A man in the middle can redirect traffic to a malicious server in a compromised configuration.

5.3
CVE-2023-35906

IBM Aspera Faspex 5.0.5 could allow a remote attacked to bypass IP restrictions due to improper access controls. IBM X-

5.3
CVE-2023-42782

A insufficient verification of data authenticity vulnerability [CWE-345] in FortiAnalyzer version 7.4.0 and below 7.2.3

5.3
CVE-2023-45292

When using the default implementation of Verify to check a Captcha, verification can be bypassed. For example, if the fi

5.3
CVE-2023-51764

Postfix through 3.8.5 allows SMTP smuggling unless configured with smtpd_data_restrictions=reject_unauth_pipelining and

5.3
CVE-2023-51765

sendmail through 8.17.2 allows SMTP smuggling in certain configurations. Remote attackers can use a published exploitati

5.3
CVE-2023-51766

Exim before 4.97.1 allows SMTP smuggling in certain PIPELINING/CHUNKING configurations. Remote attackers can use a publi

5.2
CVE-2023-30559

The firmware update package for the wireless card is not properly signed and can be modified.

4.8
CVE-2023-32993

Jenkins SAML Single Sign On(SSO) Plugin 2.0.2 and earlier does not perform hostname validation when connecting to miniOr

4.6
CVE-2017-20180

A vulnerability classified as critical has been found in Zerocoin libzerocoin. Affected is the function CoinSpend::CoinS

4.5
CVE-2022-48431

In JetBrains IntelliJ IDEA before 2023.1 in some cases, Gradle and Maven projects could be imported without the “Trust P

4.4
CVE-2021-26396

Insufficient validation of address mapping to IO in ASP (AMD Secure Processor) may result in a loss of memory integrity

3.7
CVE-2023-2897

The Brizy Page Builder plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 2.4.1

3.7
CVE-2023-37264

Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 0.35.0, p

3.7
CVE-2023-41045

Graylog is a free and open log management platform. Graylog makes use of only one single source port for DNS queries. Gr

3.3
CVE-2023-5548

Stronger revision number limitations were required on file serving endpoints to improve cache poisoning protection.

2.6
CVE-2023-4177

A vulnerability was found in EmpowerID up to 7.205.0.0. It has been rated as problematic. This issue affects some unknow

9.9
CVE-2022-36130

HashiCorp Boundary up to 0.10.1 did not properly perform data integrity checks to ensure the resources were associated w

9.8
CVE-2021-29655

Pexip Infinity Connect before 1.8.0 omits certain provisioning authenticity checks. Thus, untrusted code may execute.

9.8
CVE-2022-25262

In JetBrains Hub before 2022.1.14434, SAML request takeover was possible.

9.8
CVE-2020-14115

A command injection vulnerability exists in the Xiaomi Router AX3600. The vulnerability is caused by a lack of inspectio

9.8
CVE-2022-26871 KEV

An arbitrary file upload vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to upl

Frequently Asked Questions

What is CWE-345?

CWE-345 (CWE-345) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-345?

There are 819 CVE records associated with CWE-345 in our database. Of these, 88 are critical severity, 254 are high severity, and 289 are medium severity.

How can I protect against CWE-345 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-345 using AI-powered security agents.

Detect CWE-345 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-345 vulnerabilities across your infrastructure.

Get Started