Vulnerabilities > Insufficient Verification of Data Authenticity

DATE CVE VULNERABILITY TITLE RISK
2022-01-02 CVE-2021-36751 Insufficient Verification of Data Authenticity vulnerability in Encsecurity Datavault
ENC DataVault 7.2.3 and before, and OEM versions, use an encryption algorithm that is vulnerable to data manipulation (without knowledge of the key).
high complexity
encsecurity CWE-345
4.2
2021-12-28 CVE-2020-7878 Insufficient Verification of Data Authenticity vulnerability in 4NB Videooffice X2.9
An arbitrary file download and execution vulnerability was found in the VideoOffice X2.9 and earlier versions (CVE-2020-7878).
network
low complexity
4nb CWE-345
critical
9.8
2021-12-22 CVE-2021-45419 Insufficient Verification of Data Authenticity vulnerability in Starcharge products
Certain Starcharge products are affected by Improper Input Validation.
network
low complexity
starcharge CWE-345
8.8
2021-12-10 CVE-2021-37188 Insufficient Verification of Data Authenticity vulnerability in Digi products
An issue was discovered on Digi TransPort devices through 2021-07-21.
network
low complexity
digi CWE-345
8.8
2021-12-08 CVE-2021-26103 Insufficient Verification of Data Authenticity vulnerability in Fortinet Fortios and Fortiproxy
An insufficient verification of data authenticity vulnerability (CWE-345) in the user interface of FortiProxy verison 2.0.3 and below, 1.2.11 and below and FortiGate verison 7.0.0, 6.4.6 and below, 6.2.9 and below of SSL VPN portal may allow a remote, unauthenticated attacker to conduct a cross-site request forgery (CSRF) attack .
network
low complexity
fortinet CWE-345
8.8
2021-11-29 CVE-2019-8921 Insufficient Verification of Data Authenticity vulnerability in multiple products
An issue was discovered in bluetoothd in BlueZ through 5.48.
low complexity
bluez debian CWE-345
6.5
2021-11-16 CVE-2021-26315 Insufficient Verification of Data Authenticity vulnerability in AMD products
When the AMD Platform Security Processor (PSP) boot rom loads, authenticates, and subsequently decrypts an encrypted FW, due to insufficient verification of the integrity of decrypted image, arbitrary code may be executed in the PSP when encrypted firmware images are used.
local
low complexity
amd CWE-345
7.8
2021-11-13 CVE-2021-43616 Insufficient Verification of Data Authenticity vulnerability in multiple products
The npm ci command in npm 7.x and 8.x through 8.1.3 proceeds with an installation even if dependency information in package-lock.json differs from package.json.
network
low complexity
npmjs netapp fedoraproject CWE-345
critical
9.8
2021-11-10 CVE-2020-23906 Insufficient Verification of Data Authenticity vulnerability in Ffmpeg 4.2
FFmpeg N-98388-g76a3ee996b allows attackers to cause a denial of service (DoS) via a crafted audio file due to insufficient verification of data authenticity.
local
low complexity
ffmpeg CWE-345
5.5
2021-10-28 CVE-2021-22460 Insufficient Verification of Data Authenticity vulnerability in Huawei Harmonyos 2.0
A component of the HarmonyOS has a Insufficient Verification of Data Authenticity vulnerability.
local
low complexity
huawei CWE-345
5.5