Vulnerability index

Browse CVEs

732 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Signature VerificationCWE-347 × clear
Unclassified HIGH 8.1
CVE-2025-9210

Missing signature validation in JSON Web Tokens in Otalio Ship Property Management System versions before 2.22.0 allows authenticated attackers to es…

Fix unknown
Fix from $4,900 2026-08-18
Unclassified CRITICAL 9.8
CVE-2026-74901

openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerability in pqc.py where AES-GCM decryption failures trigger fallback to …

Fix unknown
Fix from $5,750 2026-08-17
Unclassified CRITICAL 9.8
CVE-2026-74876

openssl_encrypt versions before 1.4.0 contain a vulnerability in PublicKeyBundle.from_dict() that creates key bundles from untrusted data without ver…

Fix unknown
Fix from $5,750 2026-08-17
Unclassified HIGH 8.1
CVE-2026-18500

@fastify/jwt is a JSON Web Token plugin for Fastify. In versions before 10.2.2, a per-request verification key passed to request.jwtVerify({ key }) i…

No fix yet
Fix from $4,900 2026-08-15
Unclassified MEDIUM 5.9
CVE-2026-74244

A flaw was found in Red Hat Quay's Stripe billing webhook handler. This vulnerability allows an unauthenticated attacker to forge billing events by s…

No fix yet
Fix from $4,000 2026-08-14
Unclassified HIGH 7.5
CVE-2026-19910

PAX Technology Q80 Application Installer Signature Verification Bypass Remote Code Execution Vulnerability. This vulnerability allows network-adjacen…

No fix yet
Fix from $4,900 2026-08-14
Unclassified HIGH 7.5
CVE-2026-56864

A malicious GOSUMDB was capable of serving arbitrary module content not contained within the transparency log. This attack allows for a coordinating …

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 8.4
CVE-2026-56865

A malicious GOPROXY was previously capable of forging up to two sumdb tiles that allow for a requested module to bypass the GOSUMDB check and persist…

No fix yet
Fix from $4,900 2026-08-13
Unclassified CRITICAL 9.8
CVE-2026-28148

Unauthenticated Bypass Vulnerability in Headless Single Sign On <= 1.6 versions.

No fix yet
Fix from $5,750 2026-08-13
Unclassified HIGH 8.8
CVE-2026-12263

Zohocorp ManageEngine Password Manager Pro versions before 13232 and PAM360 versions before 8551 are vulnerable to an authentication bypass vulnerabi…

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 7.2
CVE-2026-68759

A holder of a valid integration credential may impersonate other users under specific conditions.

No fix yet
Fix from $4,900 2026-08-12
Unclassified HIGH 7.5
CVE-2026-68757

A user with access to a valid SAML response may impersonate another user under specific conditions.

No fix yet
Fix from $4,900 2026-08-12
Unclassified CRITICAL 9.1
CVE-2025-59324

CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to properly validate LUKS encryption and, if encryption is present, all CryptoPro file i…

No fix yet
Fix from $5,750 2026-08-12
Unclassified HIGH 7.5
CVE-2025-59327

In CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4, bootxsa.efi fails to properly validate LUKS encryption and, if encryption is present, all …

No fix yet
Fix from $4,900 2026-08-12
Windows 10 1607 MEDIUM 5.9
CVE-2026-62757

Improper verification of cryptographic signature in Windows Schannel allows an unauthorized attacker to bypass a security feature over a network.

Fix: 10.0.14393.9418 / 10.0.17763.9115+
Fix from $4,000 2026-08-11
Unclassified CRITICAL 9.8
CVE-2026-10579

A flaw was found in Picketlink Federation SAML; the unsolcited response handler would accept forged assertions with no verification or validation, pe…

No fix yet
Fix from $5,750 2026-08-11
Unclassified HIGH 8.1
CVE-2026-15556

A flaw was found in Picketlink's SP signature validation; a SAML response containing zero assertion elements matching the signature check can allow a…

No fix yet
Fix from $4,900 2026-08-11
Unclassified MEDIUM 5.9
CVE-2026-66776

SAP Approuter does not consistently enforce integrity verification on certain session-related request headers under specific conditions. An attacker …

No fix yet
Fix from $4,000 2026-08-11
Unclassified HIGH 8.6
CVE-2026-10754

Pega Platform versions 8.5.0 through 25.1.2 are affected by an improper validation of cryptographic signatures that may allow an attacker to bypass s…

No fix yet
Fix from $4,900 2026-08-10
Unclassified MEDIUM 6.7
CVE-2026-16742

systemd-homed contains a local privilege escalation bug via arbitrary system group addition to a local, logged in, homed-managed user

No fix yet
Fix from $4,000 2026-08-10
Unclassified HIGH 7.1
CVE-2026-58262

Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, header signature verification counts the unused padding bits o…

No fix yet
Fix from $1,950 2026-08-07
Windows Admin Center CRITICAL 9.8
CVE-2026-62873

Improper verification of cryptographic signature in Microsoft 365 Admin Center allows an unauthorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2026-08-07
Teams HIGH 7.5
CVE-2026-62918

Improper verification of cryptographic signature in Microsoft Teams allows an unauthorized attacker to perform spoofing over a network.

No fix yet
Fix from $1,950 2026-08-07
Api Control Plane CRITICAL 10.0
CVE-2026-5430

The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker t…

Fix: 4.1.0.257 / 4.2.0.197+
Fix from $2,300 2026-08-06
Unclassified CRITICAL 9.1
CVE-2026-7557

An improper verification of cryptographic signature vulnerability in the SAML authentication module of Progress MarkLogic Server before 11.3.6 and 12…

No fix yet
Fix from $2,300 2026-08-05
Build Of Keycloak CRITICAL 9.1
CVE-2026-16443

A flaw was found in the SAML metadata import functionality of the keycloak-services component, which is the core engine for identity brokering in Red…

Fix: 26.4.14 / 26.6.5+
Fix from $2,300 2026-08-05
Unclassified CRITICAL 9.2
CVE-2026-46713

Misskey is an open source, federated social media platform. Versions 12.37.0 and later, but prior to 2026.5.4, contain a vulnerability in the JSON-LD…

Mitigation only
Fix from $2,300 2026-08-03
\ HIGH 7.5
CVE-2026-18568

XML::Sig versions from 0.29 before 0.72 for Perl allow signature verification bypass because verify returns true when every signature was skipped bef…

Fix: 0.72+
Fix from $1,950 2026-08-03
\ CRITICAL 9.1
CVE-2026-9487

XML::Sig versions before 0.71 for Perl allow signature wrapping via duplicate ID. _get_signed_xml() in lib/XML/Sig.pm, called from verify(), resolve…

Fix: 0.71+
Fix from $2,300 2026-08-03
Net\ HIGH 8.1
CVE-2026-18092

Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass via XML signature wrapping because new_from_xml reads assertion identity wi…

Fix: 0.86+
Fix from $1,950 2026-08-03