Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-345 (对数据真实性的验证不充分) — Vulnerability Class 218

218 vulnerabilities classified as CWE-345 (对数据真实性的验证不充分). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2026-6967 Missing Delegated Metadata Validation in awslabs/tough — tough 5.9 Medium2026-04-24
CVE-2026-40323 SP1 V6 Recursion Circuit Row-Count Binding Gap — sp1 7.1AIHighAI2026-04-17
CVE-2026-35659 OpenClaw < 2026.3.22 - Unresolved Service Metadata Routing via Bonjour and DNS-SD Discovery — OpenClaw 4.6 Medium2026-04-10
CVE-2026-39366 WWBN AVideo Affected by a PayPal IPN Replay Attack Enabling Wallet Balance Inflation via Missing Transaction Deduplication in ipn.php — AVideo 6.5 Medium2026-04-07
CVE-2026-3177 Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More <= 1.8.9.7 - Insufficient Verification of Data Authenticity to Unauthenticated Donation Status Forgery via Stripe Webhook — Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More 5.3 Medium2026-04-07
CVE-2026-35042 fast-jwt accepts unknown `crit` header extensions (RFC 7515 §4.1.11 MUST violation) — fast-jwt 7.5 High2026-04-06
CVE-2026-35039 fast-jwt Affected by Cache Confusion via cacheKeyBuilder Collisions Can Return Claims From a Different Token (Identity/Authorization Mixup) — fast-jwt 9.1 Critical2026-04-06
CVE-2026-34061 nimiq/core-rs-albatross: Macro block proposal interlink bug — core-rs-albatross 4.9 Medium2026-04-03
CVE-2026-33221 Nhost Storage Affected by MIME Type Spoofing via Trusted Client Content-Type Header in Storage Upload — nhost 9.1 -2026-03-20
CVE-2026-33243 barebox: FIT Signature Verification Bypass Vulnerability — barebox 8.3 High2026-03-20
CVE-2026-33143 OneUptime: WhatsApp Webhook Missing Signature Verification — oneuptime 5.3 -2026-03-20
CVE-2026-32029 OpenClaw < 2026.2.21 - Client IP Spoofing via X-Forwarded-For Header Parsing — OpenClaw 5.3 Medium2026-03-19
CVE-2026-28500 ONNX Untrusted Model Repository Warnings Suppressed by silent=True in onnx.hub.load() — Silent Supply-Chain Attack — onnx 8.6 High2026-03-18
CVE-2026-32294 JetKVM insufficient firmware verification — JetKVM 4.7 Medium2026-03-17
CVE-2026-32290 GL-iNet Comet (GL-RM1) KVM insufficient firmware verification — Comet KVM 4.7 Medium2026-03-17
CVE-2026-32597 PyJWT accepts unknown `crit` header extensions (RFC 7515 §4.1.11 MUST violation) — pyjwt 7.5 High2026-03-12
CVE-2026-23656 Windows App Installer Spoofing Vulnerability — Windows App Client for Windows Desktop 5.9 Medium2026-03-10
CVE-2026-30920 OneUptime has broken access control in GitHub App installation flow that allows unauthorized project binding — oneuptime 8.6 High2026-03-09
CVE-2026-28454 OpenClaw < 2026.2.2 - Authorization Bypass via Unauthenticated Telegram Webhook — OpenClaw 7.5 High2026-03-05
CVE-2026-25921 Gogs: Cross-repository LFS object overwrite via missing content hash verification — gogs 9.3 Critical2026-03-05
CVE-2026-30798 RustDesk Client Accepts Unauthenticated stop-service Command via Strategy Payload — RustDesk Client 9.8 -2026-03-05
CVE-2026-2428 Fluent Forms Pro Add On Pack <= 6.1.17 - Missing Authorization to Unauthenticated Payment Status modification — Fluent Forms Pro Add On Pack 7.5 High2026-02-27
CVE-2026-27510 Unitree Go2 Mobile Program Tampering Enables Root RCE — Unitree Go2 9.6 Critical2026-02-26
CVE-2026-27700 Hono is Vulnerable to Authentication Bypass by IP Spoofing in AWS Lambda ALB conninfo — hono 8.2 High2026-02-25
CVE-2026-2385 The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.4.7 - Unauthenticated Email Relay — The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce 5.3 Medium2026-02-22
CVE-2026-26327 OpenClaw allows unauthenticated discovery TXT records to steer routing and TLS pinning — openclaw 9.3 -2026-02-19
CVE-2026-25474 OpenClaw has a Telegram webhook request forgery (missing `channels.telegram.webhookSecret`) → auth bypass — openclaw 7.5 High2026-02-19
CVE-2025-14444 RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login <= 6.0.6.9 - Unauthenticated Payment Bypass via rm_process_paypal_sdk_payment — RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login 5.3 Medium2026-02-18
CVE-2026-26007 cryptography Subgroup Attack Due to Missing Subgroup Validation for SECT Curves — cryptography 6.5 -2026-02-10
CVE-2026-24775 OpenProject has Forced Actions, Content Spoofing, and Persistent DoS via ID Manipulation in OpenProject Blocknote Editor Extension — openproject 6.3 Medium2026-01-28

Vulnerabilities classified as CWE-345 (对数据真实性的验证不充分) represent 218 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.