İçeriğe atla
Noroxi

CWE-345 · 694 kayıt

Insufficient Verification of Data Authenticity

Bu sınıftaki CVE’ler

695 kayıt

  • RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive.

    YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %100

    rarlab · winrar23 Ağu 2023

  • CVE-2022-26871
    75Bu hafta

    An arbitrary file upload vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to upload an arbitrary fil

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %19

    trendmicro · apex central29 Mar 2022

  • CVE-2016-4553
    58Planlayın

    client_side.cc in Squid before 3.5.18 and 4.x before 4.0.10 does not properly ignore the Host header when absolute-URI is provided, which al

    YüksekCVSS 8,6İstismar yokEPSS %80

    canonical · ubuntu linux10 May 2016

  • CVE-2016-4554
    46Planlayın

    mime_header.cc in Squid before 3.5.18 allows remote attackers to bypass intended same-origin restrictions and possibly conduct cache-poisoni

    YüksekCVSS 8,6İstismar yokEPSS %39

    oracle · linux10 May 2016

  • CVE-2014-4936
    42Planlayın

    The upgrade functionality in Malwarebytes Anti-Malware (MBAM) consumer before 2.0.3 and Malwarebytes Anti-Exploit (MBAE) consumer 1.04.1.101

    KritikCVSS 9,3SilahlaştırılmışEPSS %17

    malwarebytes · malwarebytes anti-exploit16 Ara 2014

  • CVE-2014-8165
    41Planlayın

    scripts/amsvis/powerpcAMS/amsnet.py in powerpc-utils-python uses the pickle Python module unsafely, which allows remote attackers to execute

    KritikCVSS 10,0İstismar yokEPSS %3

    powerpc-utils project · powerpc-utils19 Şub 2015

  • CVE-2019-11235
    40Planlayın

    FreeRADIUS before 3.0.19 mishandles the "each participant verifies that the received scalar is within a range, and that the received group e

    KritikCVSS 9,8İstismar yokEPSS %4

    freeradius · freeradius22 Nis 2019

  • CVE-2018-19971
    40Planlayın

    JFrog Artifactory Pro 6.5.9 has Incorrect Access Control.

    KritikCVSS 9,8İstismar yokEPSS %3

    jfrog · artifactory16 Nis 2019

  • CVE-2021-43616
    40Planlayın

    The npm ci command in npm 7.x and 8.x through 8.1.3 proceeds with an installation even if dependency information in package-lock.json differ

    KritikCVSS 9,8Kavram kanıtıEPSS %3

    npmjs · npm13 Kas 2021

  • CVE-2021-37421
    40Planlayın

    Zoho ManageEngine ADSelfService Plus 6103 and prior is vulnerable to admin portal access-restriction bypass.

    KritikCVSS 9,8İstismar yokEPSS %2

    zohocorp · manageengine adselfservice plus30 Ağu 2021

  • CVE-2020-28900
    40Planlayın

    Insufficient Verification of Data Authenticity in Nagios Fusion 4.1.8 and earlier and Nagios XI 5.7.5 and earlier allows for Escalation of P

    KritikCVSS 9,8İstismar yokEPSS %2

    nagios · fusion24 May 2021

  • CVE-2013-2167
    40Planlayın

    python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache signing bypass

    KritikCVSS 9,8İstismar yokEPSS %2

    openstack · python-keystoneclient10 Ara 2019

  • CVE-2022-22994
    40Planlayın

    Insufficient Verification of Data Authenticity Remote Code Execution Vulnerability on Western Digital My Cloud devices.

    KritikCVSS 9,8İstismar yokEPSS %2

    westerndigital · my cloud os28 Oca 2022

  • CVE-2026-62874
    40Planlayın

    Azure Billing Elevation of Privilege Vulnerability

    KritikCVSS 10,0İstismar yokEPSS %0

    microsoft · azure billing17 Eyl 2026

  • CVE-2026-45674
    40Planlayın

    Netty Vulnerable to DNS Cache Poisoning via Missing Bailiwick Checks in CNAME Records

    KritikCVSS 10,0Kavram kanıtıEPSS %0

    netty · netty12 Haz 2026

  • CVE-2026-47691
    40Planlayın

    Netty has Insufficient Bailiwick Validation for NS Records

    KritikCVSS 10,0İstismar yokEPSS %0

    netty · netty12 Haz 2026

  • CVE-2022-3703
    40Planlayın

    ETIC Telecom Remote Access Server Insufficient Verification of Data Authenticity

    KritikCVSS 10,0İstismar yokEPSS %0

    etictelecom · remote access server firmware10 Kas 2022

  • CVE-2017-3198
    39İzleyin

    GIGABYTE BRIX UEFI firmware is not cryptographically signed

    KritikCVSS 9,8İstismar yokEPSS %2

    gigabyte · gb-bsi7h-6500 firmware9 Tem 2018

  • CVE-2022-31800
    39İzleyin

    Insufficient Verification of Data Vulnerability in PHOENIX CONTACT classic line industrial controllers

    KritikCVSS 9,8İstismar yokEPSS %2

    phoenixcontact · axc 1050 firmware21 Haz 2022

  • CVE-2022-25262
    39İzleyin

    In JetBrains Hub before 2022.1.14434, SAML request takeover was possible.

    KritikCVSS 9,8Kavram kanıtıEPSS %1

    jetbrains · hub25 Şub 2022

  • CVE-2020-14115
    39İzleyin

    A command injection vulnerability exists in the Xiaomi Router AX3600.

    KritikCVSS 9,8İstismar yokEPSS %1

    mi · ax3600 firmware10 Mar 2022

  • CVE-2022-31801
    39İzleyin

    Insufficient Verification of Data Vulnerability in ProConOS/ProConOS eCLR SDK and MULTIPROG Engineering tool

    KritikCVSS 9,8İstismar yokEPSS %1

    phoenixcontact · multiprog21 Haz 2022

  • CVE-2022-30315
    39İzleyin

    Honeywell Experion PKS Safety Manager (SM and FSC) through 2022-05-06 has Insufficient Verification of Data Authenticity.

    KritikCVSS 9,8İstismar yokEPSS %1

    honeywell · safety manager firmware28 Tem 2022

  • CVE-2015-3956
    39İzleyin

    Hospira Plum A+ Infusion System version 13.4 and prior, Plum A+3 Infusion System version 13.6 and prior, and Symbiq Infusion System, version

    KritikCVSS 9,8İstismar yokEPSS %1

    pifzer · plum a\+ infusion system firmware25 Mar 2019

  • CVE-2019-18835
    39İzleyin

    Matrix Synapse before 1.5.0 mishandles signature checking on some federation APIs.

    KritikCVSS 9,8İstismar yokEPSS %1

    matrix · synapse7 Kas 2019

Tüm zafiyet sınıfları