CWE-345
Insufficient Verification of Data Authenticity
MITRENo catalog description on file. The MITRE CWE site has the canonical reference.
Recent CVEs
showing 11 of 11- CVE-2026-45674—EPSS 0%20 h ago
Netty Vulnerable to DNS Cache Poisoning via Missing Bailiwick Checks in CNAME Records
maven - CVE-2026-53406High· 7.821 h ago
Insufficient Verification of Data Authenticity in Remote Control for Zoom Contact Center for Windows before version 7.0.0 may allow an authenticated user to enable an escalation of privilege via local access.
- CVE-2026-47691High· 8.7EPSS 0%23 h ago
Netty has Insufficient Bailiwick Validation for NS Records
maven - CVE-2026-48096Medium· 5.0EPSS 0%1 d ago
OpenFGA has cache-key delimiter injection in shared-iterator and v2 iterator that caches enables intra-store authorization-decision poisoning
go - CVE-2026-46654—EPSS 0%2 d ago
Plonky3 MultiField32Challenger: transcript malleability and challenge entropy loss
crates.io - CVE-2026-46539Medium· 5.9EPSS 0%2 d ago
Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to version 1.4.0, a logic flaw in BlockInclusionProof::is_block_proven causes the function to return true without performi
crates.io - CVE-2026-3012High· 8.0EPSS 0%2 d ago
A flaw was found in Samba’s certificate auto-enrollment Group Policy handling. When certificate auto-enrollment is enabled, Samba may retrieve a CA certificate over an unencrypted HTTP connection and install it into the local trust store wi
- CVE-2023-48238High· 7.5EPSS 0%4 d ago
json-web-token library is vulnerable to a JWT algorithm confusion attack
npm - CVE-2026-7792Medium· 5.3EPSS 0%5 d ago
The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in versions up to and including 1.10.0.1. This is due to the
- CVE-2026-8608Medium· 5.3EPSS 0%5 d ago
The Event Monster – Event Management, Events Calendar, Tickets plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in versions up to, and including, 2.1.0. This is due to the capture_payment() AJAX handler (
- CVE-2026-50214Critical· 9.8EPSS 0%5 d ago
The /v1/Plan service relies entirely on a shared global API token for full administrative management, allowing arbitrary creation of zero-cost network access plans.
CWE catalog data sourced from MITRE. CVE associations come from NVD weakness mappings; some CVEs carry multiple CWEs.