Vulnerabilities > Insufficient Verification of Data Authenticity

DATE CVE VULNERABILITY TITLE RISK
2023-09-13 CVE-2023-20236 Insufficient Verification of Data Authenticity vulnerability in Cisco IOS XR
A vulnerability in the iPXE boot function of Cisco IOS XR software could allow an authenticated, local attacker to install an unverified software image on an affected device. This vulnerability is due to insufficient image verification.
local
low complexity
cisco CWE-345
7.8
2023-09-06 CVE-2023-4589 Insufficient Verification of Data Authenticity vulnerability in Delinea Secret Server 10.9.000002
Insufficient verification of data authenticity vulnerability in Delinea Secret Server, in its v10.9.000002 version.
network
low complexity
delinea CWE-345
7.2
2023-08-23 CVE-2023-38831 Insufficient Verification of Data Authenticity vulnerability in Rarlab Winrar
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive.
local
low complexity
rarlab CWE-345
7.8
2023-08-11 CVE-2023-22955 Insufficient Verification of Data Authenticity vulnerability in Audiocodes products
An issue was discovered on AudioCodes VoIP desk phones through 3.4.4.1000.
local
low complexity
audiocodes CWE-345
7.8
2023-08-08 CVE-2023-36541 Insufficient Verification of Data Authenticity vulnerability in Zoom
Insufficient verification of data authenticity in Zoom Desktop Client for Windows before 5.14.5 may allow an authenticated user to enable an escalation of privilege via network access.
network
low complexity
zoom CWE-345
8.8
2023-08-06 CVE-2023-4177 Insufficient Verification of Data Authenticity vulnerability in Empowerid 7.205.0.0
A vulnerability was found in EmpowerID up to 7.205.0.0.
low complexity
empowerid CWE-345
5.7
2023-08-04 CVE-2023-36134 Insufficient Verification of Data Authenticity vulnerability in PHPjabbers Class Scheduling System 1.0
In PHP Jabbers Class Scheduling System 1.0, lack of verification when changing an email address and/or password (on the Profile Page) allows remote attackers to take over accounts.
network
low complexity
phpjabbers CWE-345
critical
9.8
2023-08-04 CVE-2023-36139 Insufficient Verification of Data Authenticity vulnerability in PHPjabbers Cleaning Business Software 1.0
In PHPJabbers Cleaning Business Software 1.0, lack of verification when changing an email address and/or password (on the Profile Page) allows remote attackers to take over accounts.
network
low complexity
phpjabbers CWE-345
critical
9.8
2023-08-03 CVE-2023-3749 Insufficient Verification of Data Authenticity vulnerability in Johnsoncontrols Videoedge 5.4.1/5.7.1
A local user could edit the VideoEdge configuration file and interfere with VideoEdge operation.
local
low complexity
johnsoncontrols CWE-345
5.5
2023-07-29 CVE-2023-2314 Insufficient Verification of Data Authenticity vulnerability in Google Chrome
Insufficient data validation in DevTools in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
network
low complexity
google CWE-345
6.5