Vulnerability index

Browse CVEs

732 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Signature VerificationCWE-347 × clear
Jetnet 5310g Firmware CRITICAL 9.1
CVE-2023-5347

An Improper Verification of Cryptographic Signature vulnerability in the update process of Korenix JetNet Series allows replacing the whole operating…

No fix yet
Fix from $2,300 2024-01-09
Nth An00 Firmware HIGH 7.1
CVE-2023-23432

Some Honor products are affected by signature management vulnerability, successful exploitation could cause the forged system file overwrite the corr…

Fix: 7.0.0.157+
Fix from $1,950 2023-12-29
Nth An00 Firmware HIGH 7.1
CVE-2023-23433

Some Honor products are affected by signature management vulnerability, successful exploitation could cause the forged system file overwrite the corr…

Fix: 7.0.0.157+
Fix from $1,950 2023-12-29
Magicos HIGH 7.1
CVE-2023-23435

Some Honor products are affected by signature management vulnerability, successful exploitation could cause the forged system file overwrite the corr…

Fix: 7.1.0.137+
Fix from $1,950 2023-12-29
Magicos HIGH 7.1
CVE-2023-23436

Some Honor products are affected by signature management vulnerability, successful exploitation could cause the forged system file overwrite the corr…

Fix: 7.1.0.100+
Fix from $1,950 2023-12-29
Nth An00 Firmware HIGH 7.1
CVE-2023-23431

Some Honor products are affected by signature management vulnerability, successful exploitation could cause the forged system file overwrite the corr…

Fix: 7.0.0.157+
Fix from $1,950 2023-12-29
Yii2 Authclient HIGH 8.8
CVE-2023-50714

yii2-authclient is an extension that adds OpenID, OAuth, OAuth2 and OpenId Connect consumers for the Yii framework 2.0. In yii2-authclient prior to v…

Fix: 2.2.15+
Fix from $1,950 2023-12-22
Meeting Software Development Kit MEDIUM 6.5
CVE-2023-49646

Improper authentication in some Zoom clients before version 5.16.5 may allow an authenticated user to conduct a denial of service via network access.

Fix: 5.14.14 / 5.15.12+
Fix from $1,600 2023-12-13
H2o MEDIUM 6.7
CVE-2023-41337

h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. In version 2.3.0-beta2 and prior, when h2o is configured to listen to multiple ad…

Fix: after 2.2.6
Fix from $1,600 2023-12-12
Misskey HIGH 7.5
CVE-2023-49079

Misskey is an open source, decentralized social media platform. Misskey's missing signature validation allows arbitrary users to impersonate any remo…

Fix: 2023.11.1+
Fix from $1,950 2023-11-29
Radeon Rx Vega M Firmware MEDIUM 6.7
CVE-2023-20567

Improper signature verification of RadeonTM RX Vega M Graphics driver for Windows may allow an attacker with admin privileges to launch AMDSoftwareIn…

Fix: 23.q3 / 23.7.1+
Fix from $1,600 2023-11-14
Radeon Rx Vega M Firmware MEDIUM 6.7
CVE-2023-20568

Improper signature verification of RadeonTM RX Vega M Graphics driver for Windows may allow an attacker with admin privileges to launch RadeonInstall…

Fix: 23.q3 / 23.7.1+
Fix from $1,600 2023-11-14
Wave Server Software HIGH 8.8
CVE-2023-5747

Bashis, a Security Researcher at IPVM has found a flaw that allows for a remote code execution during the installation of Wave on the camera device. …

Fix: 5.1.1.37647+
Fix from $1,950 2023-11-13
Gitsign MEDIUM 5.3
CVE-2023-47122

Gitsign is software for keyless Git signing using Sigstore. In versions of gitsign starting with 0.6.0 and prior to 0.8.0, Rekor public keys were fet…

Fix: 0.8.0+
Fix from $1,600 2023-11-10
Open Vm Tools HIGH 7.5
CVE-2023-34058

VMware Tools contains a SAML token signature bypass vulnerability. A malicious actor that has been granted Guest Operation Privileges https://docs.v…

Fix: 12.3.5+
Fix from $1,950 2023-10-27
Debian Linux HIGH 7.5
CVE-2023-46234

browserify-sign is a package to duplicate the functionality of node's crypto public key functions, much of this is based on Fedor Indutny's work on i…

Fix: 4.2.2+
Fix from $1,950 2023-10-26
Client Connector HIGH 7.8
CVE-2023-28796

Improper Verification of Cryptographic Signature vulnerability in Zscaler Client Connector on Linux allows Code Injection. This issue affects Zscaler…

Fix: 1.3.1.6+
Fix from $1,950 2023-10-23
Client Connector MEDIUM 5.3
CVE-2023-28804

An Improper Verification of Cryptographic Signature vulnerability in Zscaler Client Connector on Linux allows replacing binaries.This issue affects L…

Fix: 1.4.0.105+
Fix from $1,600 2023-10-23
Udm HIGH 7.5
CVE-2023-46324

pkg/suci/suci.go in free5GC udm before 1.2.0, when Go before 1.19 is used, allows an Invalid Curve Attack because it may compute a shared secret via …

Fix: 1.2.0+
Fix from $1,950 2023-10-23
Omap L138 Firmware HIGH 8.8
CVE-2022-25333

The Texas Instruments OMAP L138 (secure variants) trusted execution environment (TEE) performs an RSA check implemented in mask ROM when loading a mo…

Mitigation only
Fix from $1,950 2023-10-19
Big Ip Access Policy Manager HIGH 7.8
CVE-2023-43611

The BIG-IP Edge Client Installer on macOS does not follow best practices for elevating privileges during the installation process.  This vulnerabilit…

Fix: 7.2.4.4 / 15.1.9+
Fix from $1,950 2023-10-10
Warpgate HIGH 8.1
CVE-2023-43660

Warpgate is a smart SSH, HTTPS and MySQL bastion host for Linux that doesn't need special client apps. The SSH key verification for a user can be byp…

Fix: 0.8.1+
Fix from $1,950 2023-09-27
Aes Gcm MEDIUM 5.5
CVE-2023-42811

aes-gcm is a pure Rust implementation of the AES-GCM. Starting in version 0.10.0 and prior to version 0.10.3, in the AES GCM implementation of decryp…

Fix: 0.10.3+
Fix from $1,600 2023-09-22
Hydra MEDIUM 6.5
CVE-2023-42806

Hydra is the layer-two scalability solution for Cardano. Prior to version 0.13.0, not signing and verifying `$\mathsf{cid}$` allows an attacker (whic…

Fix: 0.13.0+
Fix from $1,600 2023-09-21
Ios Xr HIGH 7.0
CVE-2023-20135

A vulnerability in Cisco IOS XR Software image verification checks could allow an authenticated, local attacker to execute arbitrary code on the unde…

Fix: 7.6 / 7.10.1+
Fix from $1,950 2023-09-13
Ios Xr HIGH 7.8
CVE-2023-20236

A vulnerability in the iPXE boot function of Cisco IOS XR software could allow an authenticated, local attacker to install an unverified software ima…

Fix: 7.10.1+
Fix from $1,950 2023-09-13
365 Apps MEDIUM 5.5
CVE-2023-41764

Microsoft Office Spoofing Vulnerability

Patch available
Fix from $1,600 2023-09-12
Qms Automotive HIGH 7.8
CVE-2023-40727

A vulnerability has been identified in QMS Automotive (All versions < V12.39). The QMS.Mobile module of the affected application uses weak outdated a…

Fix: 12.39+
Fix from $1,950 2023-09-12
Agent HIGH 7.8
CVE-2023-41744

Local privilege escalation due to unrestricted loading of unsigned libraries. The following products are affected: Acronis Agent (macOS) before build…

Patch available
Fix from $1,950 2023-08-31
Zscaler Internet Access Admin Portal CRITICAL 9.8
CVE-2023-28801

An Improper Verification of Cryptographic Signature in the SAML authentication of the Zscaler Admin UI allows a Privilege Escalation.This issue affec…

Fix: 6.2r+
Fix from $2,300 2023-08-31