CWE-345 · 694 kayıt
Insufficient Verification of Data Authenticity
Bu sınıftaki CVE’ler
695 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
91Hemen | CVE-2023-38831Silahlaştırılmış | RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive.rarlab · winrar · CWE-345 | Yüksek7,8 | KEV | %99,8 | 23 Ağu 2023 |
75Bu hafta | CVE-2022-26871Silahlaştırılmış | An arbitrary file upload vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to upload an arbitrary filtrendmicro · apex central · CWE-345 | Kritik9,8 | KEV | %19,5 | 29 Mar 2022 |
58Planlayın | CVE-2016-4553İstismar yok | client_side.cc in Squid before 3.5.18 and 4.x before 4.0.10 does not properly ignore the Host header when absolute-URI is provided, which alcanonical · ubuntu linux · CWE-345 | Yüksek8,6 | — | %80,0 | 10 May 2016 |
46Planlayın | CVE-2016-4554İstismar yok | mime_header.cc in Squid before 3.5.18 allows remote attackers to bypass intended same-origin restrictions and possibly conduct cache-poisonioracle · linux · CWE-345 | Yüksek8,6 | — | %38,9 | 10 May 2016 |
42Planlayın | CVE-2014-4936Silahlaştırılmış | The upgrade functionality in Malwarebytes Anti-Malware (MBAM) consumer before 2.0.3 and Malwarebytes Anti-Exploit (MBAE) consumer 1.04.1.101malwarebytes · malwarebytes anti-exploit · CWE-345 | Kritik9,3 | — | %16,8 | 16 Ara 2014 |
41Planlayın | CVE-2014-8165İstismar yok | scripts/amsvis/powerpcAMS/amsnet.py in powerpc-utils-python uses the pickle Python module unsafely, which allows remote attackers to executepowerpc-utils project · powerpc-utils · CWE-345 | Kritik10,0 | — | %2,8 | 19 Şub 2015 |
40Planlayın | CVE-2019-11235İstismar yok | FreeRADIUS before 3.0.19 mishandles the "each participant verifies that the received scalar is within a range, and that the received group efreeradius · freeradius · CWE-345 | Kritik9,8 | — | %3,6 | 22 Nis 2019 |
40Planlayın | CVE-2018-19971İstismar yok | JFrog Artifactory Pro 6.5.9 has Incorrect Access Control.jfrog · artifactory · CWE-345 | Kritik9,8 | — | %3,0 | 16 Nis 2019 |
40Planlayın | CVE-2021-43616Kavram kanıtı | The npm ci command in npm 7.x and 8.x through 8.1.3 proceeds with an installation even if dependency information in package-lock.json differnpmjs · npm · CWE-345 | Kritik9,8 | — | %2,7 | 13 Kas 2021 |
40Planlayın | CVE-2021-37421İstismar yok | Zoho ManageEngine ADSelfService Plus 6103 and prior is vulnerable to admin portal access-restriction bypass.zohocorp · manageengine adselfservice plus · CWE-345 | Kritik9,8 | — | %2,5 | 30 Ağu 2021 |
40Planlayın | CVE-2020-28900İstismar yok | Insufficient Verification of Data Authenticity in Nagios Fusion 4.1.8 and earlier and Nagios XI 5.7.5 and earlier allows for Escalation of Pnagios · fusion · CWE-345 | Kritik9,8 | — | %2,4 | 24 May 2021 |
40Planlayın | CVE-2013-2167İstismar yok | python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache signing bypassopenstack · python-keystoneclient · CWE-345 | Kritik9,8 | — | %2,0 | 10 Ara 2019 |
40Planlayın | CVE-2022-22994İstismar yok | Insufficient Verification of Data Authenticity Remote Code Execution Vulnerability on Western Digital My Cloud devices.westerndigital · my cloud os · CWE-345 | Kritik9,8 | — | %1,9 | 28 Oca 2022 |
40Planlayın | CVE-2026-62874İstismar yok | Azure Billing Elevation of Privilege Vulnerabilitymicrosoft · azure billing · CWE-345 | Kritik10,0 | — | %0,4 | 17 Eyl 2026 |
40Planlayın | CVE-2026-45674Kavram kanıtı | Netty Vulnerable to DNS Cache Poisoning via Missing Bailiwick Checks in CNAME Recordsnetty · netty · CWE-345 | Kritik10,0 | — | %0,4 | 12 Haz 2026 |
40Planlayın | CVE-2026-47691İstismar yok | Netty has Insufficient Bailiwick Validation for NS Recordsnetty · netty · CWE-345 | Kritik10,0 | — | %0,4 | 12 Haz 2026 |
40Planlayın | CVE-2022-3703İstismar yok | ETIC Telecom Remote Access Server Insufficient Verification of Data Authenticityetictelecom · remote access server firmware · CWE-345 | Kritik10,0 | — | %0,3 | 10 Kas 2022 |
39İzleyin | CVE-2017-3198İstismar yok | GIGABYTE BRIX UEFI firmware is not cryptographically signedgigabyte · gb-bsi7h-6500 firmware · CWE-345 | Kritik9,8 | — | %1,6 | 9 Tem 2018 |
39İzleyin | CVE-2022-31800İstismar yok | Insufficient Verification of Data Vulnerability in PHOENIX CONTACT classic line industrial controllersphoenixcontact · axc 1050 firmware · CWE-345 | Kritik9,8 | — | %1,6 | 21 Haz 2022 |
39İzleyin | CVE-2022-25262Kavram kanıtı | In JetBrains Hub before 2022.1.14434, SAML request takeover was possible.jetbrains · hub · CWE-345 | Kritik9,8 | — | %1,4 | 25 Şub 2022 |
39İzleyin | CVE-2020-14115İstismar yok | A command injection vulnerability exists in the Xiaomi Router AX3600.mi · ax3600 firmware · CWE-345 | Kritik9,8 | — | %1,1 | 10 Mar 2022 |
39İzleyin | CVE-2022-31801İstismar yok | Insufficient Verification of Data Vulnerability in ProConOS/ProConOS eCLR SDK and MULTIPROG Engineering toolphoenixcontact · multiprog · CWE-345 | Kritik9,8 | — | %1,1 | 21 Haz 2022 |
39İzleyin | CVE-2022-30315İstismar yok | Honeywell Experion PKS Safety Manager (SM and FSC) through 2022-05-06 has Insufficient Verification of Data Authenticity.honeywell · safety manager firmware · CWE-345 | Kritik9,8 | — | %1,0 | 28 Tem 2022 |
39İzleyin | CVE-2015-3956İstismar yok | Hospira Plum A+ Infusion System version 13.4 and prior, Plum A+3 Infusion System version 13.6 and prior, and Symbiq Infusion System, versionpifzer · plum a\+ infusion system firmware · CWE-345 | Kritik9,8 | — | %1,0 | 25 Mar 2019 |
39İzleyin | CVE-2019-18835İstismar yok | Matrix Synapse before 1.5.0 mishandles signature checking on some federation APIs.matrix · synapse · CWE-345 | Kritik9,8 | — | %0,9 | 7 Kas 2019 |
- CVE-2023-3883191Hemen
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive.
YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %100rarlab · winrar23 Ağu 2023
- CVE-2022-2687175Bu hafta
An arbitrary file upload vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to upload an arbitrary fil
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %19trendmicro · apex central29 Mar 2022
- CVE-2016-455358Planlayın
client_side.cc in Squid before 3.5.18 and 4.x before 4.0.10 does not properly ignore the Host header when absolute-URI is provided, which al
YüksekCVSS 8,6İstismar yokEPSS %80canonical · ubuntu linux10 May 2016
- CVE-2016-455446Planlayın
mime_header.cc in Squid before 3.5.18 allows remote attackers to bypass intended same-origin restrictions and possibly conduct cache-poisoni
YüksekCVSS 8,6İstismar yokEPSS %39oracle · linux10 May 2016
- CVE-2014-493642Planlayın
The upgrade functionality in Malwarebytes Anti-Malware (MBAM) consumer before 2.0.3 and Malwarebytes Anti-Exploit (MBAE) consumer 1.04.1.101
KritikCVSS 9,3SilahlaştırılmışEPSS %17malwarebytes · malwarebytes anti-exploit16 Ara 2014
- CVE-2014-816541Planlayın
scripts/amsvis/powerpcAMS/amsnet.py in powerpc-utils-python uses the pickle Python module unsafely, which allows remote attackers to execute
KritikCVSS 10,0İstismar yokEPSS %3powerpc-utils project · powerpc-utils19 Şub 2015
- CVE-2019-1123540Planlayın
FreeRADIUS before 3.0.19 mishandles the "each participant verifies that the received scalar is within a range, and that the received group e
KritikCVSS 9,8İstismar yokEPSS %4freeradius · freeradius22 Nis 2019
- CVE-2018-1997140Planlayın
JFrog Artifactory Pro 6.5.9 has Incorrect Access Control.
KritikCVSS 9,8İstismar yokEPSS %3jfrog · artifactory16 Nis 2019
- CVE-2021-4361640Planlayın
The npm ci command in npm 7.x and 8.x through 8.1.3 proceeds with an installation even if dependency information in package-lock.json differ
KritikCVSS 9,8Kavram kanıtıEPSS %3npmjs · npm13 Kas 2021
- CVE-2021-3742140Planlayın
Zoho ManageEngine ADSelfService Plus 6103 and prior is vulnerable to admin portal access-restriction bypass.
KritikCVSS 9,8İstismar yokEPSS %2zohocorp · manageengine adselfservice plus30 Ağu 2021
- CVE-2020-2890040Planlayın
Insufficient Verification of Data Authenticity in Nagios Fusion 4.1.8 and earlier and Nagios XI 5.7.5 and earlier allows for Escalation of P
KritikCVSS 9,8İstismar yokEPSS %2nagios · fusion24 May 2021
- CVE-2013-216740Planlayın
python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache signing bypass
KritikCVSS 9,8İstismar yokEPSS %2openstack · python-keystoneclient10 Ara 2019
- CVE-2022-2299440Planlayın
Insufficient Verification of Data Authenticity Remote Code Execution Vulnerability on Western Digital My Cloud devices.
KritikCVSS 9,8İstismar yokEPSS %2westerndigital · my cloud os28 Oca 2022
- CVE-2026-6287440Planlayın
Azure Billing Elevation of Privilege Vulnerability
KritikCVSS 10,0İstismar yokEPSS %0microsoft · azure billing17 Eyl 2026
- CVE-2026-4567440Planlayın
Netty Vulnerable to DNS Cache Poisoning via Missing Bailiwick Checks in CNAME Records
KritikCVSS 10,0Kavram kanıtıEPSS %0netty · netty12 Haz 2026
- CVE-2026-4769140Planlayın
Netty has Insufficient Bailiwick Validation for NS Records
KritikCVSS 10,0İstismar yokEPSS %0netty · netty12 Haz 2026
- CVE-2022-370340Planlayın
ETIC Telecom Remote Access Server Insufficient Verification of Data Authenticity
KritikCVSS 10,0İstismar yokEPSS %0etictelecom · remote access server firmware10 Kas 2022
- CVE-2017-319839İzleyin
GIGABYTE BRIX UEFI firmware is not cryptographically signed
KritikCVSS 9,8İstismar yokEPSS %2gigabyte · gb-bsi7h-6500 firmware9 Tem 2018
- CVE-2022-3180039İzleyin
Insufficient Verification of Data Vulnerability in PHOENIX CONTACT classic line industrial controllers
KritikCVSS 9,8İstismar yokEPSS %2phoenixcontact · axc 1050 firmware21 Haz 2022
- CVE-2022-2526239İzleyin
In JetBrains Hub before 2022.1.14434, SAML request takeover was possible.
KritikCVSS 9,8Kavram kanıtıEPSS %1jetbrains · hub25 Şub 2022
- CVE-2020-1411539İzleyin
A command injection vulnerability exists in the Xiaomi Router AX3600.
KritikCVSS 9,8İstismar yokEPSS %1mi · ax3600 firmware10 Mar 2022
- CVE-2022-3180139İzleyin
Insufficient Verification of Data Vulnerability in ProConOS/ProConOS eCLR SDK and MULTIPROG Engineering tool
KritikCVSS 9,8İstismar yokEPSS %1phoenixcontact · multiprog21 Haz 2022
- CVE-2022-3031539İzleyin
Honeywell Experion PKS Safety Manager (SM and FSC) through 2022-05-06 has Insufficient Verification of Data Authenticity.
KritikCVSS 9,8İstismar yokEPSS %1honeywell · safety manager firmware28 Tem 2022
- CVE-2015-395639İzleyin
Hospira Plum A+ Infusion System version 13.4 and prior, Plum A+3 Infusion System version 13.6 and prior, and Symbiq Infusion System, version
KritikCVSS 9,8İstismar yokEPSS %1pifzer · plum a\+ infusion system firmware25 Mar 2019
- CVE-2019-1883539İzleyin
Matrix Synapse before 1.5.0 mishandles signature checking on some federation APIs.
KritikCVSS 9,8İstismar yokEPSS %1matrix · synapse7 Kas 2019