Vulnerability index

Browse CVEs

732 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Signature VerificationCWE-347 × clear
Websphere Application Server HIGH 8.8
CVE-2024-37532

IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to identity spoofing by an authenticated user due to improper signature validation. IBM X…

Mitigation only
Fix from $1,950 2024-06-20
Unclassified MEDIUM 5.3
CVE-2024-36277

Improper verification of cryptographic signature issue exists in "FreeFrom - the nostr client" App versions prior to 1.3.5 for Android and iOS. The a…

Mitigation only
Fix from $1,600 2024-06-17
Storagegrid MEDIUM 5.3
CVE-2024-21988

StorageGRID (formerly StorageGRID Webscale) versions prior to 11.7.0.9 and 11.8.0.5 are susceptible to disclosure of sensitive information via comp…

Fix: 11.7.0.9 / 11.8.0.5+
Fix from $1,600 2024-06-14
Android CRITICAL 9.8
CVE-2024-32911

There is a possible escalation of privilege due to improperly used crypto. This could lead to remote escalation of privilege with no additional execu…

No fix yet
Fix from $2,300 2024-06-13
Authlib HIGH 7.5
CVE-2024-37568

lepture Authlib before 1.3.1 has algorithm confusion with asymmetric public keys. Unless an algorithm is specified in a jwt.decode call, HMAC verific…

Fix: 1.3.1+
Fix from $1,950 2024-06-09
Unclassified MEDIUM 6.4
CVE-2024-2451

Improper fingerprint validation in the TeamViewer Client (Full & Host) prior Version 15.54 for Windows and macOS allows an attacker with administrati…

Mitigation only
Fix from $1,600 2024-05-28
Unclassified MEDIUM 5.6
CVE-2024-1721

Improper Verification of Cryptographic Signature vulnerability in HYPR Passwordless on Windows allows Malicious Software Update.This issue affects HY…

Mitigation only
Fix from $1,600 2024-05-21
Workplace Virtual Desktop Infrastructure HIGH 7.8
CVE-2024-27244

Insufficient verification of data authenticity in the installer for Zoom Workplace VDI App for Windows may allow an authenticated user to conduct an…

Fix: 5.15.0 / 5.17.10+
Fix from $1,950 2024-05-15
TYPO3 MEDIUM 5.3
CVE-2024-34358

TYPO3 is an enterprise content management system. Starting in version 9.0.0 and prior to versions 9.5.48 ELTS, 10.4.45 ELTS, 11.5.37 LTS, 12.4.15 LTS…

Fix: 9.5.48 / 10.4.45+
Fix from $1,600 2024-05-14
Parallels Desktop HIGH 7.8
CVE-2023-50228

Parallels Desktop Updater Improper Verification of Cryptographic Signature Local Privilege Escalation Vulnerability. This vulnerability allows local …

Fix: 19.1.0_+
Fix from $1,950 2024-05-03
Unclassified CRITICAL 10.0
CVE-2024-32962

xml-crypto is an xml digital signature and encryption library for Node.js. In affected versions the default configuration does not check authorizatio…

Patch available
Fix from $2,300 2024-05-02
Client Connector CRITICAL 9.8
CVE-2024-23480

A fallback mechanism in code sign checking on macOS may allow arbitrary code execution. This issue affects Zscaler Client Connector on MacOS prior to…

Fix: 4.2+
Fix from $2,300 2024-05-01
Zoom MEDIUM 6.7
CVE-2024-27247

Improper privilege management in the installer for Zoom Desktop Client for macOS before version 5.17.10 may allow a privileged user to conduct an esc…

Fix: 5.17.10+
Fix from $1,600 2024-04-09
Zoom HIGH 7.8
CVE-2024-24694

Improper privilege management in the installer for Zoom Desktop Client for Windows before version 5.17.10 may allow an authenticated user to conduct …

Fix: 5.7.10+
Fix from $1,950 2024-04-09
Windows 10 1507 HIGH 7.8
CVE-2024-26228

Windows Cryptographic Services Security Feature Bypass Vulnerability

Fix: 10.0.10240.20596 / 10.0.14393.6897+
Fix from $1,950 2024-04-09
Windows 10 1507 HIGH 7.4
CVE-2024-26194

Secure Boot Security Feature Bypass Vulnerability

Fix: 10.0.10240.20596 / 10.0.14393.6897+
Fix from $1,950 2024-04-09
Emui CRITICAL 9.1
CVE-2023-52538

Vulnerability of package name verification being bypassed in the HwIms module. Impact: Successful exploitation of this vulnerability will affect avai…

No fix yet
Fix from $2,300 2024-04-08
Unclassified HIGH 8.1
CVE-2023-52043

An issue in D-Link COVR 1100, 1102, 1103 AC1200 Dual-Band Whole-Home Mesh Wi-Fi System (Hardware Rev B1) truncates Wireless Access Point Passwords (W…

Mitigation only
Fix from $1,950 2024-04-03
Unclassified MEDIUM 6.1
CVE-2024-2307

A flaw was found in osbuild-composer. A condition can be triggered that disables GPG verification for package repositories, which can expose the buil…

Mitigation only
Fix from $1,600 2024-03-19
Unclassified CRITICAL 9.8
CVE-2018-25099

In the CryptX module before 0.062 for Perl, gcm_decrypt_verify() and chacha20poly1305_decrypt_verify() do not verify the tag.

Patch available
Fix from $2,300 2024-03-18
Svix Webhooks MEDIUM 6.5
CVE-2024-21491

Versions of the package svix before 1.17.0 are vulnerable to Authentication Bypass due to an issue in the verify function where signatures of differe…

Fix: 1.17.0+
Fix from $1,600 2024-02-13
Snow Inventory Agent MEDIUM 5.5
CVE-2024-1149

Improper Verification of Cryptographic Signature vulnerability in Snow Software Inventory Agent on MacOS, Snow Software Inventory Agent on Windows, S…

Fix: 6.7.2 / 6.14.5+
Fix from $1,600 2024-02-08
Snow Inventory Agent MEDIUM 5.5
CVE-2024-1150

Improper Verification of Cryptographic Signature vulnerability in Snow Software Inventory Agent on Unix allows File Manipulation through Snow Update …

Fix: 7.3.1+
Fix from $1,600 2024-02-08
Factorytalk Services Platform CRITICAL 9.1
CVE-2024-21917

A vulnerability exists in Rockwell Automation FactoryTalk® Service Platform that allows a malicious user to obtain the service token and use it for a…

Fix: after 6.31.00
Fix from $2,300 2024-01-31
Aws Encryption Sdk MEDIUM 5.3
CVE-2024-23680

AWS Encryption SDK for Java versions 2.0.0 to 2.2.0 and less than 1.9.0 incorrectly validates some invalid ECDSA signatures.

Fix: 1.9.0 / 2.2.0+
Fix from $1,600 2024-01-19
Sharebrowser CRITICAL 9.8
CVE-2023-44077

Studio Network Solutions ShareBrowser before 7.0 on macOS mishandles signature verification, aka PMP-2636.

Fix: 7.0+
Fix from $2,300 2024-01-17
Fedora HIGH 7.5
CVE-2024-0567

A vulnerability was found in GnuTLS, where a cockpit (which uses gnuTLS) rejects a certificate chain with distributed trust. This issue occurs when v…

Fix: 3.8.3+
Fix from $1,950 2024-01-16
GitLab MEDIUM 5.3
CVE-2023-2030

An issue has been discovered in GitLab CE/EE affecting all versions from 12.2 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in whic…

Fix: 16.5.6 / 16.6.4+
Fix from $1,600 2024-01-12
Portage CRITICAL 9.8
CVE-2016-20021

In Gentoo Portage before 3.0.47, there is missing PGP validation of executed code: the standalone emerge-webrsync downloads a .gpgsig file but does n…

Fix: 3.0.47+
Fix from $2,300 2024-01-12
Aries Cloud Agent HIGH 8.8
CVE-2024-21669

Hyperledger Aries Cloud Agent Python (ACA-Py) is a foundation for building decentralized identity applications and services running in non-mobile env…

Fix: 0.10.5+
Fix from $1,950 2024-01-11