Vulnerability index

Browse CVEs

732 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Signature VerificationCWE-347 × clear
Emergency Responder HIGH 7.2
CVE-2023-20266

A vulnerability in Cisco Emergency Responder, Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Managem…

Mitigation only
Fix from $1,950 2023-08-30
Mbts Site Controller Firmware HIGH 8.8
CVE-2023-23772

Motorola MBTS Site Controller fails to check firmware update authenticity. The Motorola MBTS Site Controller lacks cryptographic signature validation…

Mitigation only
Fix from $1,950 2023-08-29
Ebts Base Radio Firmware HIGH 8.8
CVE-2023-23773

Motorola EBTS/MBTS Base Radio fails to check firmware authenticity. The Motorola MBTS Base Radio lacks cryptographic signature validation for firmwar…

Mitigation only
Fix from $1,950 2023-08-29
Node Saml MEDIUM 5.3
CVE-2023-40178

Node-SAML is a SAML library not dependent on any frameworks that runs in Node. The lack of checking of current timestamp allows a LogoutRequest XML t…

Fix: 4.0.5+
Fix from $1,600 2023-08-23
App Lounge MEDIUM 6.5
CVE-2021-43171

Improper verification of applications' cryptographic signatures in the /e/OS app store client App Lounge before 0.19q allows attackers in control of …

Fix: 0.19q+
Fix from $1,600 2023-08-22
Emui HIGH 7.5
CVE-2023-39392

Vulnerability of insecure signatures in the OsuLogin module. Successful exploitation of this vulnerability may cause OsuLogin to be maliciously modif…

Mitigation only
Fix from $1,950 2023-08-13
Emui HIGH 7.5
CVE-2023-39393

Vulnerability of insecure signatures in the ServiceWifiResources module. Successful exploitation of this vulnerability may cause ServiceWifiResources…

Mitigation only
Fix from $1,950 2023-08-13
Uthenticode HIGH 7.5
CVE-2023-40012

uthenticode is a small cross-platform library for partially verifying Authenticode digital signatures. Versions of uthenticode prior to the 2.x serie…

Fix: 2.0.0+
Fix from $1,950 2023-08-09
Uthenticode CRITICAL 9.8
CVE-2023-39969

uthenticode is a small cross-platform library for partially verifying Authenticode digital signatures. Version 1.0.9 of uthenticode hashed the entire…

Fix: 1.0.9+
Fix from $2,300 2023-08-09
Rooms HIGH 7.8
CVE-2023-39211

Improper privilege management in Zoom Desktop Client for Windows and Zoom Rooms for Windows before 5.15.5 may allow an authenticated user to enable a…

Fix: 5.15.5+
Fix from $1,950 2023-08-08
Access Policy Manager Clients HIGH 7.8
CVE-2023-38418

The BIG-IP Edge Client Installer on macOS does not follow best practices for elevating privileges during the installation process.  Note: Software ve…

Fix: 7.2.4.3+
Fix from $1,950 2023-08-02
Storage MEDIUM 5.9
CVE-2023-3347

A vulnerability was found in Samba's SMB2 packet signing mechanism. The SMB2 packet signing is not enforced if an admin configured "server signing = …

Fix: 4.17.10 / 4.18.5+
Fix from $1,600 2023-07-20
Wemo Smart Plug Wsp080 Firmware MEDIUM 6.5
CVE-2023-33768

Incorrect signature verification of the firmware during the Device Firmware Update process of Belkin Wemo Smart Plug WSP080 v1.2 allows attackers to …

No fix yet
Fix from $1,600 2023-07-13
Mono MEDIUM 5.3
CVE-2023-35373

Mono Authenticode Validation Spoofing Vulnerability

Fix: 6.12.0.200+
Fix from $1,600 2023-07-11
Powerstoret Os HIGH 7.8
CVE-2023-32449

Dell PowerStore versions prior to 3.5 contain an improper verification of cryptographic signature vulnerability. An attacker can trick a high privile…

Fix: 3.5.0.0-2050321+
Fix from $1,950 2023-06-22
Zoom HIGH 7.7
CVE-2023-28602

Zoom for Windows clients prior to 5.13.5 contain an improper verification of cryptographic signature vulnerability. A malicious user may potentially…

Fix: 5.13.5+
Fix from $1,950 2023-06-13
Virtual Desktop Infrastructure HIGH 7.8
CVE-2023-34120

Improper privilege management in Zoom for Windows, Zoom Rooms for Windows, and Zoom VDI for Windows clients before 5.14.0 may allow an authenticated…

Fix: 5.14.0+
Fix from $1,950 2023-06-13
Notation Go HIGH 8.8
CVE-2023-33959

notation is a CLI tool to sign and verify OCI artifacts and container images. An attacker who has compromised a registry can cause users to verify th…

Fix: 1.0.0+
Fix from $1,950 2023-06-06
Signedxml CRITICAL 9.1
CVE-2023-34205

In Moov signedxml through 1.0.0, parsing the raw XML (as received) can result in different output than parsing the canonicalized XML. Thus, signature…

Mitigation only
Fix from $2,300 2023-05-30
Django Ses MEDIUM 5.4
CVE-2023-33185

Django-SES is a drop-in mail backend for Django. The django_ses library implements a mail backend for Django using AWS Simple Email Service. The libr…

Fix: 3.5.0+
Fix from $1,600 2023-05-26
Cyber Protect Home Office HIGH 7.8
CVE-2022-4418

Local privilege escalation due to unrestricted loading of unsigned libraries. The following products are affected: Acronis Cyber Protect Home Office …

Mitigation only
Fix from $1,950 2023-05-18
Elastic Cloud Storage HIGH 7.5
CVE-2023-25934

DELL ECS prior to 3.8.0.2 contains an improper verification of cryptographic signature vulnerability. A network attacker with an ability to intercept…

Fix: 3.8.0.2+
Fix from $1,950 2023-05-04
Windows 10 1507 MEDIUM 5.3
CVE-2023-28226

Windows Enroll Engine Security Feature Bypass Vulnerability

Fix: 10.0.10240.19869 / 10.0.14393.5850+
Fix from $1,600 2023-04-11
Windows 10 1507 MEDIUM 5.5
CVE-2023-28228

Windows Spoofing Vulnerability

Fix: 10.0.10240.19869 / 10.0.14393.5850+
Fix from $1,600 2023-04-11
Aptare It Analytics MEDIUM 5.3
CVE-2023-28818

An issue was discovered in Veritas NetBackup IT Analytics 11 before 11.2.0. The application upgrade process included unsigned files that could be exp…

Fix: 10.6.00+
Fix from $1,600 2023-03-24
Stationguard CRITICAL 9.8
CVE-2023-28610

The update process in OMICRON StationGuard and OMICRON StationScout before 2.21 can be exploited by providing a modified firmware update image. This …

Fix: after 2.20
Fix from $2,300 2023-03-23
Russh MEDIUM 5.9
CVE-2023-28113

russh is a Rust SSH client and server library. Starting in version 0.34.0 and prior to versions 0.36.2 and 0.37.1, Diffie-Hellman key validation is i…

Fix: 0.36.2+
Fix from $1,600 2023-03-16
Enterprise Nfv Infrastructure Software HIGH 7.8
CVE-2022-20929

A vulnerability in the upgrade signature verification of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, local a…

Fix: 4.9.1+
Fix from $1,950 2023-03-10
Android HIGH 7.8
CVE-2023-20940

In the Android operating system, there is a possible way to replace a boot partition due to improperly used crypto. This could lead to local escalati…

Patch available
Fix from $1,950 2023-02-28
Control CRITICAL 9.8
CVE-2023-25718

In ConnectWise Control through 22.9.10032 (formerly known as ScreenConnect), after an executable file is signed, additional instructions can be added…

Fix: after 22.9.10032
Fix from $2,300 2023-02-13