Skip to main content

CWE archive

CWE-345 CVEs

Programmatic archive

650 CVEs tagged with CWE-34583 Critical, 259 High, 266 Medium, 42 Low, 0 Unrated.

CVE-2022-2789

Published Aug 19, 2022

Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulnerable to CWE-345 Insufficient Verification of Data Authenticity, and can display logic that is different…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-28757

Published Aug 18, 2022

The Zoom Client for Meetings for macOS (Standard and for IT Admin) starting with version 5.7.3 and before 5.11.6 contains a vulnerability in the auto update process. A local low-p…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-1755

Published Aug 16, 2022

In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, X-Forwarded-For headers could be used to spoof a user's IP, in order to bypass remote address checks.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-30273

Published Jul 26, 2022

The Motorola MDLC protocol through 2022-05-02 mishandles message integrity. It supports three security modes: Plain, Legacy Encryption, and New Encryption. In Legacy Encryption mo…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-5236

Published Jul 7, 2022

It was discovered that the IcedTea-Web used codebase attribute of the <applet> tag on the HTML page that hosts Java applet in the Same Origin Policy (SOP) checks. As the specified…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-32252

Published Jun 14, 2022

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). The application does not perform the integrity check of the update packages. Without val…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-27759

Published May 6, 2022

This vulnerability arises because the application allows the user to perform some sensitive action without verifying that the request was sent intentionally. An attacker can cause…

CVSS 2.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-24889

Published Apr 27, 2022

Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Prior to versions 21.0.8, 22.2.4, and 23.0.1, it is possible to trick administrato…

CVSS 2.4 · Low
Vendor/product tagsBeta · best-effort
Showing 401-425 of 650 CVEsPage 17 of 26