İçeriğe atla
Noroxi

CWE-354 · 170 kayıt

Improper Validation of Integrity Check Value

Bu sınıftaki CVE’ler

170 kayıt

  • CVE-2023-48795
    51Planlayın

    The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypas

    OrtaCVSS 5,9Kavram kanıtıEPSS %94

    ssh · ssh18 Ara 2023

  • CVE-2019-1166
    43Planlayın

    A tampering vulnerability exists in Microsoft Windows when a man-in-the-middle attacker is able to successfully bypass the NTLM MIC (Message

    OrtaCVSS 5,9İstismar yokEPSS %68

    microsoft · windows 1010 Eki 2019

  • CVE-2024-3596
    40Planlayın

    RADIUS Protocol under RFC2865 is vulnerable to forgery attacks.

    KritikCVSS 9,0Kavram kanıtıEPSS %15

    freeradius · freeradius9 Tem 2024

  • CVE-2017-15994
    39İzleyin

    rsync 3.1.3-development before 2017-10-24 mishandles archaic checksums, which makes it easier for remote attackers to bypass intended access

    KritikCVSS 9,8İstismar yokEPSS %1

    samba · rsync29 Eki 2017

  • CVE-2023-33668
    39İzleyin

    DigiExam up to v14.0.2 lacks integrity checks for native modules, allowing attackers to access PII and takeover accounts on shared computers

    KritikCVSS 9,8Kavram kanıtıEPSS %1

    digiexam · digiexam12 Tem 2023

  • CVE-2023-28386
    39İzleyin

    Snap One OvrC Pro devices versions 7.2 and prior do not validate firmware updates correctly.

    KritikCVSS 9,8İstismar yokEPSS %0

    snapone · orvc22 May 2023

  • CVE-2024-25678
    39İzleyin

    In LiteSpeed QUIC (LSQUIC) Library before 4.0.4, DCID validation is mishandled.

    KritikCVSS 9,8İstismar yokEPSS %0

    litespeedtech · lsquic9 Şub 2024

  • CVE-2025-11543
    38İzleyin

    Improper Validation of Integrity Check Value vulnerability in Sharp Display Solutions projectors allows a attacker may create and run unauth

    KritikCVSS 9,5İstismar yokEPSS %0

    sharp · np-p502h firmware22 Ara 2025

  • Zebra v4.4.0 still accepts V5 SIGHASH_SINGLE without a corresponding output

    KritikCVSS 9,5İstismar yok

    crates.io · zebrad8 May 2026

  • Zebra's Transparent SIGHASH_SINGLE Handling Diverges from zcashd for Corresponding Outputs

    KritikCVSS 9,5İstismar yok

    crates.io · zebrad7 May 2026

  • CVE-2026-32105
    37İzleyin

    xrdp: RDP MAC signature (dataSignature) never verified on receive — integrity bypass in non-TLS mode

    KritikCVSS 9,3İstismar yokEPSS %0

    neutrinolabs · xrdp17 Nis 2026

  • CVE-2026-34182
    36İzleyin

    CMS AuthEnvelopedData Processing May Accept Forged Messages

    KritikCVSS 9,1İstismar yokEPSS %1

    openssl · openssl9 Haz 2026

  • CVE-2022-29898
    36İzleyin

    Remote Code Execution in all versions of various RAD-ISM-900-EN-* devices by PHOENIX CONTACT

    KritikCVSS 9,1İstismar yokEPSS %1

    phoenixcontact · rad-ism-900-en-bd firmware11 May 2022

  • CVE-2025-54887
    36İzleyin

    jwe: Missing AES-GCM authentication tag validation in encrypted JWEs

    KritikCVSS 9,1Kavram kanıtıEPSS %0

    jwt · ruby-jwe7 Ağu 2025

  • CVE-2026-75625
    36İzleyin

    Kraken Agents Peer-to-Peer Download Cache Poisoning via Digest Verification Bypass

    KritikCVSS 9,1İstismar yokEPSS %0

    uber · kraken18 Ağu 2026

  • CVE-2026-75803
    36İzleyin

    AEAD Forgeries with Empty Ciphertext When Using EVP_Cipher()

    KritikCVSS 9,1İstismar yokEPSS %0

    openssl · openssl25 Ağu 2026

  • CVE-2020-25758
    35İzleyin

    An issue was discovered on D-Link DSR-250 3.17 devices.

    YüksekCVSS 8,8İstismar yokEPSS %1

    dlink · dsr-150 firmware15 Ara 2020

  • CVE-2022-29173
    35İzleyin

    No protection against rollback attacks in go-tuf

    YüksekCVSS 8,8İstismar yokEPSS %1

    theupdateframework · go-tuf5 May 2022

  • CVE-2017-4961
    35İzleyin

    An issue was discovered in Cloud Foundry Foundation BOSH Release 261.x versions prior to 261.3 and all 260.x versions.

    YüksekCVSS 8,8İstismar yokEPSS %0

    cloud foundry · bosh13 Haz 2017

  • CVE-2020-14120
    35İzleyin

    Some Xiaomi models have a vulnerability in a certain application.

    YüksekCVSS 8,8İstismar yokEPSS %0

    mi · miui21 Nis 2022

  • CVE-2023-4929
    35İzleyin

    NPort 5000 Series Firmware Improper Validation of Integrity Check Vulnerability

    YüksekCVSS 8,8İstismar yokEPSS %0

    moxa · nport 5150ai-m12-ct-t firmware3 Eki 2023

  • CVE-2026-32148
    35İzleyin

    Lockfile checksums not verified in Hex allows dependency integrity bypass

    YüksekCVSS 8,9İstismar yokEPSS %0

    hex · hex30 Nis 2026

  • CVE-2024-48930
    34İzleyin

    secp256k1-node vulnerable to private key extraction over ECDH

    YüksekCVSS 8,7İstismar yokEPSS %0

    cryptocoinjs · secp256k1-node21 Eki 2024

  • CVE-2026-76852
    34İzleyin

    Netcore NR268 1.7.121109 Forgeable Firmware Authenticity Check in mtd_write

    YüksekCVSS 8,7İstismar yokEPSS %0

    netcore · nr26815 Eyl 2026

  • CVE-2026-58061
    34İzleyin

    CCM-family modes write plaintext to caller buffer before tag check

    YüksekCVSS 8,7İstismar yokEPSS %0

    bouncycastle · bc-java2 Ağu 2026

Tüm zafiyet sınıfları