Vulnerability index

Browse CVEs

732 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Signature VerificationCWE-347 × clear
Enterprise Linux MEDIUM 6.5
CVE-2024-49393

In neomutt and mutt, the To and Cc email headers are not validated by cryptographic signing which allows an attacker that intercepts a message to cha…

Patch available
Fix from $1,600 2024-11-12
Dataease CRITICAL 9.1
CVE-2024-47073

DataEase is an open source data visualization analysis tool that helps users quickly analyze data and gain insights into business trends. In affected…

Fix: 2.10.2+
Fix from $2,300 2024-11-07
Harmonyos MEDIUM 5.5
CVE-2024-51526

Permission control vulnerability in the hidebug module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

No fix yet
Fix from $1,600 2024-11-05
Unclassified MEDIUM 6.3
CVE-2024-50347

Laravel Reverb provides a real-time WebSocket communication backend for Laravel applications. Prior to 1.4.0, there is an issue where verification si…

Patch available
Fix from $1,600 2024-10-31
Unclassified MEDIUM 5.9
CVE-2024-8036

ABB is aware of privately reported vulnerabilities in the product versions referenced in this CVE. An attacker could exploit these vulnerabilities by…

No fix yet
Fix from $1,600 2024-10-25
Unclassified CRITICAL 9.8
CVE-2024-47943

The firmware upgrade function in the admin web interface of the Rittal IoT Interface & CMC III Processing Unit devices checks if the patch files are…

Mitigation only
Fix from $2,300 2024-10-15
Unclassified HIGH 7.2
CVE-2024-8531

CWE-347: Improper Verification of Cryptographic Signature vulnerability exists that could compromise the Data Center Expert software when an upgrade …

Mitigation only
Fix from $1,950 2024-10-11
Enterprise Server CRITICAL 9.1
CVE-2024-9487EPSS 25%

An improper verification of cryptographic signature vulnerability was identified in GitHub Enterprise Server that allowed SAML SSO authentication to …

Fix: 3.11.16 / 3.12.10+
Fix from $2,300 2024-10-10
Elliptic CRITICAL 9.1
CVE-2024-48949

The verify function in lib/elliptic/eddsa/index.js in the Elliptic package before 6.5.6 for Node.js omits "sig.S().gte(sig.eddsa.curve.n) || sig.S().…

Fix: 6.5.6+
Fix from $2,300 2024-10-10
Ssoready CRITICAL 9.8
CVE-2024-47832

ssoready is a single sign on provider implemented via docker. Affected versions are vulnerable to XML signature bypass attacks. An attacker can carry…

Fix: 2024-10-09+
Fix from $2,300 2024-10-09
Unclassified HIGH 8.8
CVE-2024-7479

Improper verification of cryptographic signature during installation of a VPN driver via the TeamViewer_service.exe component of TeamViewer Remote Cl…

Mitigation only
Fix from $1,950 2024-09-25
Unclassified HIGH 8.8
CVE-2024-7481

Improper verification of cryptographic signature during installation of a Printer driver via the TeamViewer_service.exe component of TeamViewer Remot…

Mitigation only
Fix from $1,950 2024-09-25
Unclassified HIGH 7.7
CVE-2024-8698

A flaw exists in the SAML signature validation method within the Keycloak XMLSignatureUtil class. The method incorrectly determines whether a SAML si…

Mitigation only
Fix from $1,950 2024-09-19
Libreoffice HIGH 7.8
CVE-2024-7788

Improper Digital Signature Invalidation  vulnerability in Zip Repair Mode of The Document Foundation LibreOffice allows Signature forgery vulnerabili…

Fix: 24.2.5+
Fix from $1,950 2024-09-17
Whatsapp Api Js MEDIUM 5.3
CVE-2024-45607EPSS 14%

whatsapp-api-js is a TypeScript server agnostic Whatsapp's Official API framework. It's possible to check the payload validation using the WhatsAppAP…

Fix: 4.0.3+
Fix from $1,600 2024-09-12
Omniauth Saml CRITICAL 9.8
CVE-2024-45409EPSS 11%

The Ruby SAML library is for implementing the client side of a SAML authorization. Ruby-SAML in <= 12.2 and 1.13.0 <= 1.16.0 does not properly verify…

Fix: 1.12.3 / 1.17.0+
Fix from $2,300 2024-09-10
Unclassified MEDIUM 6.3
CVE-2024-38807

Applications that use spring-boot-loader or spring-boot-loader-classic and contain custom code that performs signature verification of nested jar fil…

Mitigation only
Fix from $1,600 2024-08-23
Enterprise Server CRITICAL 9.8
CVE-2024-6800

An XML signature wrapping vulnerability was present in GitHub Enterprise Server (GHES) when using SAML authentication with specific identity provider…

Fix: 3.10.16 / 3.11.14+
Fix from $2,300 2024-08-20
Client Connector HIGH 7.5
CVE-2024-23456

Anti-tampering can be disabled under certain conditions without signature validation. This affects Zscaler Client Connector <4.2.0.190 with anti-tamp…

Fix: 4.2.0.190+
Fix from $1,950 2024-08-06
Client Connector HIGH 7.8
CVE-2024-23460

The Zscaler Updater process does not validate the digital signature of the installer before execution, allowing arbitrary code to be locally executed…

Fix: 4.2+
Fix from $1,950 2024-08-06
Client Connector MEDIUM 6.5
CVE-2023-28806

An Improper Validation of signature in Zscaler Client Connector on Windows allows an authenticated user to disable anti-tampering. This issue affects…

Fix: 4.2.0.190+
Fix from $1,600 2024-08-06
Elliptic MEDIUM 5.3
CVE-2024-42459

In the Elliptic package 6.5.6 for Node.js, EDDSA signature malleability occurs because there is a missing signature length check, and thus zero-value…

Patch available
Fix from $1,600 2024-08-02
Elliptic CRITICAL 9.1
CVE-2024-42461

In the Elliptic package 6.5.6 for Node.js, ECDSA signature malleability occurs because BER-encoded signatures are allowed.

Patch available
Fix from $2,300 2024-08-02
Filestash MEDIUM 5.3
CVE-2024-41258

An issue was discovered in filestash v0.4. The usage of the ssh.InsecureIgnoreHostKey() disables host key verification, possibly allowing attackers t…

Fix: after 0.4
Fix from $1,600 2024-07-31
Litestream MEDIUM 5.3
CVE-2024-41254

An issue was discovered in litestream v0.3.13. The usage of the ssh.InsecureIgnoreHostKey() disables host key verification, possibly allowing attacke…

Fix: after 0.3.13
Fix from $1,600 2024-07-31
Unclassified MEDIUM 6.8
CVE-2024-5912

An improper file signature check in Palo Alto Networks Cortex XDR agent may allow an attacker to bypass the Cortex XDR agent's executable blocking ca…

Mitigation only
Fix from $1,600 2024-07-10
Windows 10 1507 HIGH 7.0
CVE-2024-38069

Windows Enroll Engine Security Feature Bypass Vulnerability

Fix: 10.0.10240.20710 / 10.0.14393.7159+
Fix from $1,950 2024-07-09
Ipworks Ssh MEDIUM 6.5
CVE-2024-6580

The /n software IPWorks SSH library SFTPServer component can be induced to make unintended filesystem or network path requests when loading a SSH pub…

Mitigation only
Fix from $1,600 2024-07-08
Rtl819x Jungle Software Development Kit HIGH 7.2
CVE-2023-34435

A firmware update vulnerability exists in the boa formUpload functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted network packets…

Mitigation only
Fix from $1,950 2024-07-08
Android HIGH 7.8
CVE-2024-20892

Improper verification of signature in FilterProvider prior to SMR Jul-2024 Release 1 allows local attackers to execute privileged behaviors. User int…

Mitigation only
Fix from $1,950 2024-07-02