Vulnerability index

Browse CVEs

732 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Signature VerificationCWE-347 × clear
Secure Client HIGH 7.8
CVE-2025-20206

A vulnerability in the interprocess communication (IPC) channel of Cisco Secure Client for Windows could allow an authenticated, local attacker to pe…

Fix: 5.1.8.105+
Fix from $1,950 2025-03-05
Vasion Print CRITICAL 9.8
CVE-2025-27670

Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Insufficient Signature Validation OVE-202305…

Fix: 20.0.1923 / 22.0.843+
Fix from $2,300 2025-03-05
Unclassified CRITICAL 9.3
CVE-2024-11957

Improper verification of the digital signature in ksojscore.dll in Kingsoft WPS Office in versions equal or less than 12.1.0.18276 on Windows allow…

Mitigation only
Fix from $2,300 2025-03-04
Unclassified MEDIUM 5.6
CVE-2025-27498

aes-gcm is a pure Rust implementation of the AES-GCM. In decrypt_in_place_detached, the decrypted ciphertext (which is the correct ciphertext) is exp…

Patch available
Fix from $1,600 2025-03-03
Lti Jupyterhub Authenticator CRITICAL 9.8
CVE-2023-25574

`jupyterhub-ltiauthenticator` is a JupyterHub authenticator for learning tools interoperability (LTI). LTI13Authenticator that was introduced in `jup…

Mitigation only
Fix from $2,300 2025-02-25
Unclassified HIGH 7.2
CVE-2024-10237

There is a vulnerability in the BMC firmware image authentication design at Supermicro MBD-X12DPG-OA6 . An attacker can modify the firmware to by…

Mitigation only
Fix from $1,950 2025-02-04
Unclassified HIGH 7.2
CVE-2024-56161

Improper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator privilege to load malicious CPU …

Mitigation only
Fix from $1,950 2025-02-03
Unclassified CRITICAL 9.3
CVE-2025-24800

Hyperbridge is a hyper-scalable coprocessor for verifiable, cross-chain interoperability. A critical vulnerability was discovered in the ismp-grandpa…

Patch available
Fix from $2,300 2025-01-28
Enterprise Server HIGH 8.8
CVE-2025-23369

An improper verification of cryptographic signature vulnerability was identified in GitHub Enterprise Server that allowed signature spoofing for unau…

Fix: 3.12.14 / 3.13.10+
Fix from $1,950 2025-01-21
Aws Cloud Development Kit HIGH 8.1
CVE-2025-23206

The AWS Cloud Development Kit (AWS CDK) is an open-source software development framework to define cloud infrastructure in code and provision it thro…

Fix: 2.177.0+
Fix from $1,950 2025-01-17
Endpoint Manager HIGH 7.8
CVE-2024-13172

Improper signature verification in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote …

Fix: 2022+
Fix from $1,950 2025-01-14
Neo Impact HIGH 8.2
CVE-2024-7344

Howyar UEFI Application "Reloader" (32-bit and 64-bit) is vulnerable to execution of unsigned software in a hardcoded path.

Fix: 8.4.022-20241127 / 10.1.024-20241127+
Fix from $1,950 2025-01-14
Unclassified CRITICAL 9.1
CVE-2024-54150

cjwt is a C JSON Web Token (JWT) Implementation. Algorithm confusion occurs when a system improperly verifies the type of signature used, allowing at…

Patch available
Fix from $2,300 2024-12-19
Onenote HIGH 7.1
CVE-2024-41159

A library injection vulnerability exists in Microsoft OneNote 16.83 for macOS. A specially crafted library can leverage OneNote's access privileges, …

No fix yet
Fix from $1,950 2024-12-18
Word CRITICAL 9.1
CVE-2024-41165

A library injection vulnerability exists in Microsoft Word 16.83 for macOS. A specially crafted library can leverage Word's access privileges, leadin…

No fix yet
Fix from $2,300 2024-12-18
Teams CRITICAL 9.8
CVE-2024-42004

A library injection vulnerability exists in Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially crafted library can leverage…

No fix yet
Fix from $2,300 2024-12-18
Outlook CRITICAL 9.1
CVE-2024-42220

A library injection vulnerability exists in Microsoft Outlook 16.83.3 for macOS. A specially crafted library can leverage Outlook's access privileges…

No fix yet
Fix from $2,300 2024-12-18
Excel CRITICAL 9.1
CVE-2024-43106

A library injection vulnerability exists in Microsoft Excel 16.83 for macOS. A specially crafted library can leverage Excel's access privileges, lead…

No fix yet
Fix from $2,300 2024-12-18
Powerpoint CRITICAL 9.1
CVE-2024-39804

A library injection vulnerability exists in Microsoft PowerPoint 16.83 for macOS. A specially crafted library can leverage PowerPoint's access privil…

No fix yet
Fix from $2,300 2024-12-18
Teams CRITICAL 9.8
CVE-2024-41138

A library injection vulnerability exists in the com.microsoft.teams2.modulehost.app helper app of Microsoft Teams (work or school) 24046.2813.2770.10…

No fix yet
Fix from $2,300 2024-12-18
Teams CRITICAL 9.8
CVE-2024-41145

A library injection vulnerability exists in the WebView.app helper app of Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A speciall…

No fix yet
Fix from $2,300 2024-12-18
Recoverpoint For Virtual Machines HIGH 8.8
CVE-2024-22461

Dell RecoverPoint for Virtual Machines 6.0.x contains an OS Command injection vulnerability. A low privileged remote attacker could potentially explo…

Mitigation only
Fix from $1,950 2024-12-13
Unclassified HIGH 8.5
CVE-2024-54126

This vulnerability exists in the TP-Link Archer C50 due to improper signature verification mechanism in the firmware upgrade process at its web inter…

Mitigation only
Fix from $1,950 2024-12-05
Networker Management Console HIGH 7.8
CVE-2024-47476

Dell NetWorker Management Console, version(s) 19.11, contain(s) an Improper Verification of Cryptographic Signature vulnerability. An unauthenticated…

Mitigation only
Fix from $1,950 2024-12-03
Android HIGH 7.8
CVE-2024-49413

Improper Verification of Cryptographic Signature in SmartSwitch prior to SMR Dec-2024 Release 1 allows local attackers to install malicious applicati…

Mitigation only
Fix from $1,950 2024-12-03
Iota C.ai HIGH 7.2
CVE-2024-52958

A improper verification of cryptographic signature vulnerability in plugin management in iota C.ai Conversational Platform from 1.0.0 through 2.1.3 a…

Fix: after 2.1.3
Fix from $1,950 2024-11-27
Unclassified MEDIUM 5.5
CVE-2024-53267

sigstore-java is a sigstore java client for interacting with sigstore infrastructure. sigstore-java has insufficient verification for a situation whe…

Patch available
Fix from $1,600 2024-11-26
Firefox MEDIUM 5.4
CVE-2024-11696

The application failed to account for exceptions thrown by the `loadManifestFromFile` method during add-on signature verification. This flaw, trigger…

Fix: 128.5.0 / 133.0+
Fix from $1,600 2024-11-26
Forticlient MEDIUM 6.7
CVE-2024-40592

An improper verification of cryptographic signature vulnerability [CWE-347] in FortiClient MacOS version 7.4.0, version 7.2.4 and below, version 7.0.…

Fix: 7.2.5+
Fix from $1,600 2024-11-12
Enterprise Linux MEDIUM 5.3
CVE-2024-49394

In mutt and neomutt the In-Reply-To email header field is not protected by cryptographic signing which allows an attacker to reuse an unencrypted but…

Patch available
Fix from $1,600 2024-11-12