The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.
Volume of CVEs assigned to CWE-345 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
650 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-38831HIGH RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive. The issue occurs because a ZIP archive may inc | Aug 23, 2023 | 7.8 | 97 | YES | YES |
CVE-2022-26871CRITICAL An arbitrary file upload vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to upload an arbitrary file which could lead to remote code execut | Mar 29, 2022 | 9.8 | 78 | YES | NO |
CVE-2016-4553HIGH client_side.cc in Squid before 3.5.18 and 4.x before 4.0.10 does not properly ignore the Host header when absolute-URI is provided, which allows remote attackers to conduct cache-p | May 10, 2016 | 8.6 | 69 | NO | NO |
CVE-2014-4936HIGH The upgrade functionality in Malwarebytes Anti-Malware (MBAM) consumer before 2.0.3 and Malwarebytes Anti-Exploit (MBAE) consumer 1.04.1.1012 and earlier allow man-in-the-middle at | Dec 16, 2014 | 9.3 | 59 | NO | YES |
CVE-2016-4554HIGH mime_header.cc in Squid before 3.5.18 allows remote attackers to bypass intended same-origin restrictions and possibly conduct cache-poisoning attacks via a crafted HTTP Host heade | May 10, 2016 | 8.6 | 45 | NO | NO |
CVE-2026-50195CRITICAL containerd is an open-source container runtime. Versions prior to 2.3.2, 2.2.5 and 2.1.9 contain a vulnerability in the CRI checkpoint import process where it fails to validate the | Jul 1, 2026 | 9.9 | 44 | NO | NO |
CVE-2026-47691CRITICAL Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's `DnsResolveContext` insufficient | Jun 12, 2026 | 10.0 | 42 | NO | NO |
CVE-2026-45674CRITICAL Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's DnsResolveContext fails to valid | Jun 12, 2026 | 10.0 | 42 | NO | NO |
CVE-2026-53513CRITICAL Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, the @better-auth/sso plugin's POST /sso/register and POST /sso/update-provider endpoints | Jul 15, 2026 | 9.6 | 41 | NO | NO |
CVE-2026-35051CRITICAL Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is an authentication bypass vulnerability in Traefik's ForwardAuth midd | Apr 30, 2026 | 10.0 | 41 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.