CWE-345: CWE-345

119
Total CVEs
27
Critical
62
High
7.8
Avg CVSS

Yearly Trend

2026
13
2025
29
2024
24
2023
22
2022
15

Top Affected Vendors

1 Google 4
2 Fedoraproject 4
3 Mozilla 3
4 Cisco 3
5 Redhat 3
6 Mi 2
7 Honeywell 2
8 Certifi 2
9 Motorola 2
10 Openproject 2

All CWE-345 CVEs (119)

CVE-2025-0510
6.5

Thunderbird email client displays incorrect sender addresses when emails use invalid group name syntax in the From field. This allows attackers to spo...

Feb 4, 2025
CVE-2024-53259
6.5

An off-path attacker can disrupt QUIC connections by injecting forged ICMP Packet Too Large packets, forcing the connection to use smaller MTU sizes t...

Dec 2, 2024
CVE-2026-24775
6.3

OpenProject versions 17.0.0-17.0.1 contain a server-side request forgery (SSRF) vulnerability in the collaborative document editor. Attackers can craf...

Jan 28, 2026
CVE-2024-5684
6.3

This vulnerability allows attackers on the same network as affected EV chargers to bypass password authentication on the web configuration interface b...

Jun 6, 2024
CVE-2025-27735
6.0

This vulnerability allows an authorized attacker with local access to bypass security features in Windows Virtualization-Based Security (VBS) Enclave ...

Apr 8, 2025
CVE-2024-3049
5.9

This vulnerability in Booth cluster ticket manager allows an attacker to bypass HMAC validation by providing a specially-crafted hash to gcry_md_get_a...

Jun 6, 2024
CVE-2026-22703
5.5

Cosign versions prior to 2.6.2 and 3.0.4 have a vulnerability where crafted bundles can bypass verification checks, allowing malicious actors with com...

Jan 10, 2026
CVE-2026-2385
5.3

This vulnerability allows unauthenticated attackers to manipulate email routing and redirection in the The Plus Addons for Elementor WordPress plugin....

Feb 22, 2026
CVE-2025-14444
5.3

This vulnerability allows unauthenticated attackers to bypass paid registration in the RegistrationMagic WordPress plugin by manipulating PayPal payme...

Feb 18, 2026
CVE-2026-0939
5.3

The Rede ItaΓΊ for WooCommerce WordPress plugin has a vulnerability that allows unauthenticated attackers to manipulate WooCommerce order statuses. At...

Jan 16, 2026
CVE-2025-12752
5.3

The Subscriptions & Memberships for PayPal WordPress plugin fails to properly verify PayPal IPN requests, allowing unauthenticated attackers to create...

Nov 22, 2025
CVE-2025-12245
5.3

This CVE describes an origin validation vulnerability in Chatwoot's widget SDK that allows attackers to bypass security controls by manipulating the b...

Oct 27, 2025
CVE-2022-33861
5.1

CVE-2022-33861 is an insufficient data verification vulnerability in Eaton's IPP software that allows attackers to send invalid data that the system w...

Nov 25, 2024
CVE-2026-1195
5.0

This vulnerability in MineAdmin's JWT token refresh function allows attackers to bypass authentication by manipulating insufficiently verified data. I...

Jan 20, 2026
CVE-2022-48431
4.5

This vulnerability in JetBrains IntelliJ IDEA allows Gradle and Maven projects to be imported without requiring the 'Trust Project' confirmation dialo...

Mar 29, 2023
CVE-2023-6323
4.3

CVE-2023-6323 is an authentication bypass vulnerability in ThroughTek Kalay SDK where message authenticity isn't verified, allowing attackers to imper...

May 15, 2024
CVE-2025-59700
3.9

This vulnerability allows a physically proximate attacker with root access to modify the Recovery Partition on Entrust nShield HSM devices due to lack...

Dec 2, 2025
CVE-2026-2968
3.7

This vulnerability in Cesanta Mongoose allows attackers to bypass cryptographic signature verification in the ChaCha20-Poly1305 decryption function. A...

Feb 23, 2026
CVE-2025-34337
N/A

This vulnerability in eGovFramework's common components allows unauthenticated attackers to bypass access controls and retrieve arbitrary stored files...

Nov 19, 2025

About CWE-345 (CWE-345)

Our database tracks 119 CVEs classified as CWE-345, with 27 rated critical and 62 rated high severity. The average CVSS score for CWE-345 vulnerabilities is 7.8.

External reference: View CWE-345 on MITRE CWE →

Monitor CWE-345 Vulnerabilities

Get alerted when new CWE-345 CVEs affect your infrastructure.

Start Monitoring Free