Skip to main content

CWE archive

CWE-353 CVEs

Programmatic archive

41 CVEs tagged with CWE-3531 Critical, 17 High, 22 Medium, 1 Low, 0 Unrated.

CVE-2026-12705

Published Jul 17, 2026

Missing support for integrity check vulnerability in ABB KNX Update Tool (ABB), ABB KNX Update Tool (BJE). This issue affects KNX Update Tool (ABB): through 2.0.175; KNX Update T…

CVSS 5.9 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-48995

Published Jun 25, 2026

pnpm is a package manager. Prior to 10.33.4 and 11.0.7, a malicious codeload.github.com server can serve whatever tarball it wants and pnpm will install it regardless of the lockf…

CVSS 4.8 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-7574

Published Jun 24, 2026

Anthropic Claude Desktop Cowork VM image handling (confirmed across v1.1348.0 through v1.2278.0, including v1.1348.0, v1.1617.0, and v1.2278.0) validates only file presence and a…

CVSS 8.7 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-42428

Published Apr 28, 2026

OpenClaw versions before 2026.4.8 fail to enforce integrity verification on downloaded plugin archives. Attackers can install malicious or tampered plugin packages without detecti…

CVSS 7.5 · High
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2026-33261

Published Apr 22, 2026

A zone transition from NSEC to NSEC3 might trigger an internal inconsistency and cause a denial of service.

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-3856

Published Mar 17, 2026

IBM Db2 Recovery Expert for Linux, UNIX and Windows 5.5 IF 2 could allow an attacker to modify or corrupt data due to an insecure mechanism used for verifying the integrity of the…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-10010

Published Feb 24, 2026

The CPSD CryptoPro Secure Disk application boots a small Linux operating system to perform user authentication before using BitLocker to decrypt the Windows partition. The system…

CVSS 6.8 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-15364

Published Jan 6, 2026

The Download Manager plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.3.40. This is due to the plugin not pr…

CVSS 7.3 · High
evidence mentions
3
Buzz score
20.4

CVE-2026-21437

Published Jan 1, 2026

eopkg is a Solus package manager implemented in python3. In versions prior to 4.4.0, a malicious package could include files that are not tracked by `eopkg`. This requires the ins…

CVSS 2.0 · Low
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2025-65203

Published Dec 17, 2025

KeePassXC-Browser thru 1.9.9.2 autofills or prompts to fill stored credentials into documents rendered under a browser-enforced CSP directive and iframe attribute sandbox, allowin…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-46917

Published Aug 29, 2025

Diebold Nixdorf Vynamic Security Suite through 4.3.0 SR01 does not validate file attributes or the contents of /root during integrity validation. This allows code execution, recov…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-47123

Published Sep 26, 2024

The goTenna Pro App uses AES CTR type encryption for short, encrypted messages without any additional integrity checking mechanisms. This leaves messages malleable to an attacke…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-43108

Published Sep 26, 2024

The goTenna Pro ATAK Plugin uses AES CTR type encryption for short, encrypted messages without any additional integrity checking mechanisms. This leaves messages malleable to an…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-24404

Published Oct 19, 2023

Lack of cryptographic integrity check on TETRA air-interface encrypted traffic. Since a stream cipher is employed, this allows an active adversary to manipulate cleartext data in…

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-29290

Published Jun 15, 2023

Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by an Incorrect Authorization vulnerability that could result in a secu…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-2793

Published Aug 19, 2022

Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulenrable to CWE-353 Missing Support for Integrity Check, and has no authentication or authorization of data…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 41 CVEsPage 1 of 2