CWE-354 · 170 kayıt
Improper Validation of Integrity Check Value
Bu sınıftaki CVE’ler
170 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
51Planlayın | CVE-2023-48795Kavram kanıtı | The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypasssh · ssh · CWE-354 | Orta5,9 | — | %93,5 | 18 Ara 2023 |
43Planlayın | CVE-2019-1166İstismar yok | A tampering vulnerability exists in Microsoft Windows when a man-in-the-middle attacker is able to successfully bypass the NTLM MIC (Messagemicrosoft · windows 10 · CWE-354 | Orta5,9 | — | %68,1 | 10 Eki 2019 |
40Planlayın | CVE-2024-3596Kavram kanıtı | RADIUS Protocol under RFC2865 is vulnerable to forgery attacks.freeradius · freeradius · CWE-354 | Kritik9,0 | — | %14,9 | 9 Tem 2024 |
39İzleyin | CVE-2017-15994İstismar yok | rsync 3.1.3-development before 2017-10-24 mishandles archaic checksums, which makes it easier for remote attackers to bypass intended accesssamba · rsync · CWE-354 | Kritik9,8 | — | %1,0 | 29 Eki 2017 |
39İzleyin | CVE-2023-33668Kavram kanıtı | DigiExam up to v14.0.2 lacks integrity checks for native modules, allowing attackers to access PII and takeover accounts on shared computersdigiexam · digiexam · CWE-354 | Kritik9,8 | — | %0,5 | 12 Tem 2023 |
39İzleyin | CVE-2023-28386İstismar yok | Snap One OvrC Pro devices versions 7.2 and prior do not validate firmware updates correctly.snapone · orvc · CWE-354 | Kritik9,8 | — | %0,4 | 22 May 2023 |
39İzleyin | CVE-2024-25678İstismar yok | In LiteSpeed QUIC (LSQUIC) Library before 4.0.4, DCID validation is mishandled.litespeedtech · lsquic · CWE-354 | Kritik9,8 | — | %0,4 | 9 Şub 2024 |
38İzleyin | CVE-2025-11543İstismar yok | Improper Validation of Integrity Check Value vulnerability in Sharp Display Solutions projectors allows a attacker may create and run unauthsharp · np-p502h firmware · CWE-354 | Kritik9,5 | — | %0,2 | 22 Ara 2025 |
38İzleyin | GHSA-pvmv-cwg8-v6c8İstismar yok | Zebra v4.4.0 still accepts V5 SIGHASH_SINGLE without a corresponding outputcrates.io · zebrad · CWE-354 | Kritik9,5 | — | — | 8 May 2026 |
38İzleyin | GHSA-cwfq-rfcr-8hmpİstismar yok | Zebra's Transparent SIGHASH_SINGLE Handling Diverges from zcashd for Corresponding Outputscrates.io · zebrad · CWE-354 | Kritik9,5 | — | — | 7 May 2026 |
37İzleyin | CVE-2026-32105İstismar yok | xrdp: RDP MAC signature (dataSignature) never verified on receive — integrity bypass in non-TLS modeneutrinolabs · xrdp · CWE-354 | Kritik9,3 | — | %0,2 | 17 Nis 2026 |
36İzleyin | CVE-2026-34182İstismar yok | CMS AuthEnvelopedData Processing May Accept Forged Messagesopenssl · openssl · CWE-354 | Kritik9,1 | — | %1,1 | 9 Haz 2026 |
36İzleyin | CVE-2022-29898İstismar yok | Remote Code Execution in all versions of various RAD-ISM-900-EN-* devices by PHOENIX CONTACTphoenixcontact · rad-ism-900-en-bd firmware · CWE-354 | Kritik9,1 | — | %0,6 | 11 May 2022 |
36İzleyin | CVE-2025-54887Kavram kanıtı | jwe: Missing AES-GCM authentication tag validation in encrypted JWEsjwt · ruby-jwe · CWE-354 | Kritik9,1 | — | %0,3 | 7 Ağu 2025 |
36İzleyin | CVE-2026-75625İstismar yok | Kraken Agents Peer-to-Peer Download Cache Poisoning via Digest Verification Bypassuber · kraken · CWE-354 | Kritik9,1 | — | %0,2 | 18 Ağu 2026 |
36İzleyin | CVE-2026-75803İstismar yok | AEAD Forgeries with Empty Ciphertext When Using EVP_Cipher()openssl · openssl · CWE-354 | Kritik9,1 | — | %0,2 | 25 Ağu 2026 |
35İzleyin | CVE-2020-25758İstismar yok | An issue was discovered on D-Link DSR-250 3.17 devices.dlink · dsr-150 firmware · CWE-354 | Yüksek8,8 | — | %1,3 | 15 Ara 2020 |
35İzleyin | CVE-2022-29173İstismar yok | No protection against rollback attacks in go-tuftheupdateframework · go-tuf · CWE-354 | Yüksek8,8 | — | %0,6 | 5 May 2022 |
35İzleyin | CVE-2017-4961İstismar yok | An issue was discovered in Cloud Foundry Foundation BOSH Release 261.x versions prior to 261.3 and all 260.x versions.cloud foundry · bosh · CWE-354 | Yüksek8,8 | — | %0,5 | 13 Haz 2017 |
35İzleyin | CVE-2020-14120İstismar yok | Some Xiaomi models have a vulnerability in a certain application.mi · miui · CWE-354 | Yüksek8,8 | — | %0,4 | 21 Nis 2022 |
35İzleyin | CVE-2023-4929İstismar yok | NPort 5000 Series Firmware Improper Validation of Integrity Check Vulnerabilitymoxa · nport 5150ai-m12-ct-t firmware · CWE-354 | Yüksek8,8 | — | %0,3 | 3 Eki 2023 |
35İzleyin | CVE-2026-32148İstismar yok | Lockfile checksums not verified in Hex allows dependency integrity bypasshex · hex · CWE-354 | Yüksek8,9 | — | %0,3 | 30 Nis 2026 |
34İzleyin | CVE-2024-48930İstismar yok | secp256k1-node vulnerable to private key extraction over ECDHcryptocoinjs · secp256k1-node · CWE-354 | Yüksek8,7 | — | %0,4 | 21 Eki 2024 |
34İzleyin | CVE-2026-76852İstismar yok | Netcore NR268 1.7.121109 Forgeable Firmware Authenticity Check in mtd_writenetcore · nr268 · CWE-354 | Yüksek8,7 | — | %0,3 | 15 Eyl 2026 |
34İzleyin | CVE-2026-58061İstismar yok | CCM-family modes write plaintext to caller buffer before tag checkbouncycastle · bc-java · CWE-354 | Yüksek8,7 | — | %0,2 | 2 Ağu 2026 |
- CVE-2023-4879551Planlayın
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypas
OrtaCVSS 5,9Kavram kanıtıEPSS %94ssh · ssh18 Ara 2023
- CVE-2019-116643Planlayın
A tampering vulnerability exists in Microsoft Windows when a man-in-the-middle attacker is able to successfully bypass the NTLM MIC (Message
OrtaCVSS 5,9İstismar yokEPSS %68microsoft · windows 1010 Eki 2019
- CVE-2024-359640Planlayın
RADIUS Protocol under RFC2865 is vulnerable to forgery attacks.
KritikCVSS 9,0Kavram kanıtıEPSS %15freeradius · freeradius9 Tem 2024
- CVE-2017-1599439İzleyin
rsync 3.1.3-development before 2017-10-24 mishandles archaic checksums, which makes it easier for remote attackers to bypass intended access
KritikCVSS 9,8İstismar yokEPSS %1samba · rsync29 Eki 2017
- CVE-2023-3366839İzleyin
DigiExam up to v14.0.2 lacks integrity checks for native modules, allowing attackers to access PII and takeover accounts on shared computers
KritikCVSS 9,8Kavram kanıtıEPSS %1digiexam · digiexam12 Tem 2023
- CVE-2023-2838639İzleyin
Snap One OvrC Pro devices versions 7.2 and prior do not validate firmware updates correctly.
KritikCVSS 9,8İstismar yokEPSS %0snapone · orvc22 May 2023
- CVE-2024-2567839İzleyin
In LiteSpeed QUIC (LSQUIC) Library before 4.0.4, DCID validation is mishandled.
KritikCVSS 9,8İstismar yokEPSS %0litespeedtech · lsquic9 Şub 2024
- CVE-2025-1154338İzleyin
Improper Validation of Integrity Check Value vulnerability in Sharp Display Solutions projectors allows a attacker may create and run unauth
KritikCVSS 9,5İstismar yokEPSS %0sharp · np-p502h firmware22 Ara 2025
- GHSA-pvmv-cwg8-v6c838İzleyin
Zebra v4.4.0 still accepts V5 SIGHASH_SINGLE without a corresponding output
KritikCVSS 9,5İstismar yokcrates.io · zebrad8 May 2026
- GHSA-cwfq-rfcr-8hmp38İzleyin
Zebra's Transparent SIGHASH_SINGLE Handling Diverges from zcashd for Corresponding Outputs
KritikCVSS 9,5İstismar yokcrates.io · zebrad7 May 2026
- CVE-2026-3210537İzleyin
xrdp: RDP MAC signature (dataSignature) never verified on receive — integrity bypass in non-TLS mode
KritikCVSS 9,3İstismar yokEPSS %0neutrinolabs · xrdp17 Nis 2026
- CVE-2026-3418236İzleyin
CMS AuthEnvelopedData Processing May Accept Forged Messages
KritikCVSS 9,1İstismar yokEPSS %1openssl · openssl9 Haz 2026
- CVE-2022-2989836İzleyin
Remote Code Execution in all versions of various RAD-ISM-900-EN-* devices by PHOENIX CONTACT
KritikCVSS 9,1İstismar yokEPSS %1phoenixcontact · rad-ism-900-en-bd firmware11 May 2022
- CVE-2025-5488736İzleyin
jwe: Missing AES-GCM authentication tag validation in encrypted JWEs
KritikCVSS 9,1Kavram kanıtıEPSS %0jwt · ruby-jwe7 Ağu 2025
- CVE-2026-7562536İzleyin
Kraken Agents Peer-to-Peer Download Cache Poisoning via Digest Verification Bypass
KritikCVSS 9,1İstismar yokEPSS %0uber · kraken18 Ağu 2026
- CVE-2026-7580336İzleyin
AEAD Forgeries with Empty Ciphertext When Using EVP_Cipher()
KritikCVSS 9,1İstismar yokEPSS %0openssl · openssl25 Ağu 2026
- CVE-2020-2575835İzleyin
An issue was discovered on D-Link DSR-250 3.17 devices.
YüksekCVSS 8,8İstismar yokEPSS %1dlink · dsr-150 firmware15 Ara 2020
- CVE-2022-2917335İzleyin
No protection against rollback attacks in go-tuf
YüksekCVSS 8,8İstismar yokEPSS %1theupdateframework · go-tuf5 May 2022
- CVE-2017-496135İzleyin
An issue was discovered in Cloud Foundry Foundation BOSH Release 261.x versions prior to 261.3 and all 260.x versions.
YüksekCVSS 8,8İstismar yokEPSS %0cloud foundry · bosh13 Haz 2017
- CVE-2020-1412035İzleyin
Some Xiaomi models have a vulnerability in a certain application.
YüksekCVSS 8,8İstismar yokEPSS %0mi · miui21 Nis 2022
- CVE-2023-492935İzleyin
NPort 5000 Series Firmware Improper Validation of Integrity Check Vulnerability
YüksekCVSS 8,8İstismar yokEPSS %0moxa · nport 5150ai-m12-ct-t firmware3 Eki 2023
- CVE-2026-3214835İzleyin
Lockfile checksums not verified in Hex allows dependency integrity bypass
YüksekCVSS 8,9İstismar yokEPSS %0hex · hex30 Nis 2026
- CVE-2024-4893034İzleyin
secp256k1-node vulnerable to private key extraction over ECDH
YüksekCVSS 8,7İstismar yokEPSS %0cryptocoinjs · secp256k1-node21 Eki 2024
- CVE-2026-7685234İzleyin
Netcore NR268 1.7.121109 Forgeable Firmware Authenticity Check in mtd_write
YüksekCVSS 8,7İstismar yokEPSS %0netcore · nr26815 Eyl 2026
- CVE-2026-5806134İzleyin
CCM-family modes write plaintext to caller buffer before tag check
YüksekCVSS 8,7İstismar yokEPSS %0bouncycastle · bc-java2 Ağu 2026