Vulnerability index

Browse CVEs

733 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Signature VerificationCWE-347 × clear
Control CRITICAL 9.8
CVE-2023-25718

In ConnectWise Control through 22.9.10032 (formerly known as ScreenConnect), after an executable file is signed, additional instructions can be added…

Fix: after 22.9.10032
Fix from $2,300 2023-02-13
My Cloud Os CRITICAL 9.8
CVE-2021-36226

Western Digital My Cloud devices before OS5 do not use cryptographically signed Firmware upgrade files.

Fix: 5.02.104+
Fix from $2,300 2023-02-06
Contracts MEDIUM 5.3
CVE-2023-23940

OpenZeppelin Contracts for Cairo is a library for secure smart contract development written in Cairo for StarkNet, a decentralized ZK Rollup. `is_val…

Fix: 0.6.1+
Fix from $1,600 2023-02-03
Alienware Update HIGH 7.8
CVE-2022-34459

Dell Command | Update, Dell Update, and Alienware Update versions prior to 4.7 contain a improper verification of cryptographic signature in get appl…

Fix: 4.7.1+
Fix from $1,950 2023-02-01
Reason Jose CRITICAL 9.8
CVE-2023-23928

reason-jose is a JOSE implementation in ReasonML and OCaml.`Jose.Jws.validate` does not check HS256 signatures. This allows tampering of JWS header a…

Fix: 0.8.2+
Fix from $2,300 2023-02-01
Newtest CRITICAL 9.8
CVE-2022-23334

The Robot application in Ip-label Newtest before v8.5R0 was discovered to use weak signature checks on executed binaries, allowing attackers to have …

Fix: 8.5r0+
Fix from $2,300 2023-01-30
Libgit2 MEDIUM 5.9
CVE-2023-22742

libgit2 is a cross-platform, linkable library implementation of Git. When using an SSH remote with the optional libssh2 backend, libgit2 does not per…

Fix: 1.4.5+
Fix from $1,600 2023-01-20
Pqclean HIGH 7.5
CVE-2023-24025

CRYSTALS-DILITHIUM (in Post-Quantum Cryptography Selected Algorithms 2022) in PQClean d03da30 may allow universal forgeries of digital signatures via…

Mitigation only
Fix from $1,950 2023-01-20
R310 Firmware CRITICAL 9.8
CVE-2020-22653

In Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n 10.5.1.0.199, Ruckus T301s 10…

Fix: 3.6.2.0.795+
Fix from $2,300 2023-01-20
R310 Firmware HIGH 7.5
CVE-2020-22659

In Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n 10.5.1.0.199, Ruckus T301s 10…

Fix: 3.6.2.0.795+
Fix from $1,950 2023-01-20
Cargo MEDIUM 5.9
CVE-2022-46176

Cargo is a Rust package manager. The Rust Security Response WG was notified that Cargo did not perform SSH host key verification when cloning indexes…

Fix: after 0.67.0
Fix from $1,600 2023-01-11
Go Saml MEDIUM 5.3
CVE-2020-36563

XML Digital Signatures generated and validated using this package use SHA-1, which may allow an attacker to craft inputs which cause hash collisions …

Patch available
Fix from $1,600 2022-12-28
Jsonwebtoken HIGH 7.6
CVE-2022-23540

In versions `<=8.5.1` of `jsonwebtoken` library, lack of algorithm definition in the `jwt.verify()` function can lead to signature validation bypass …

Fix: after 8.5.1
Fix from $1,950 2022-12-22
Op Tee MEDIUM 6.4
CVE-2022-47549

An unprotected memory-access operation in optee_os in TrustedFirmware Open Portable Trusted Execution Environment (OP-TEE) before 3.20 allows a physi…

Fix: 3.20+
Fix from $1,600 2022-12-19
Tendermint Light Client Verifier MEDIUM 6.5
CVE-2022-23507

Tendermint is a high-performance blockchain consensus engine for Byzantine fault tolerant applications. Versions prior to 0.28.0 contain a potential …

Fix: 0.28.0+
Fix from $1,600 2022-12-15
Enterprise Driver HIGH 7.8
CVE-2021-26391

Insufficient verification of multiple header signatures while loading a Trusted Application (TA) may allow an attacker with privileges to gain code e…

Fix: 22.q2 / 22.5.2+
Fix from $1,950 2022-11-09
Ecostruxure Operator Terminal Expert HIGH 7.8
CVE-2022-41669

A CWE-347: Improper Verification of Cryptographic Signature vulnerability exists in the SGIUtility component that allows adversaries with local user …

Fix: 3.3+
Fix from $1,950 2022-11-04
Ecostruxure Operator Terminal Expert HIGH 7.8
CVE-2022-41666

A CWE-347: Improper Verification of Cryptographic Signature vulnerability exists that allows adversaries with local user privileges to load a malicio…

Fix: 3.3+
Fix from $1,950 2022-11-04
Ipados MEDIUM 5.5
CVE-2022-42793

An issue in code signature validation was addressed with improved checks. This issue is fixed in macOS Big Sur 11.7, macOS Ventura 13, iOS 16, iOS 15…

Fix: 11.7 / 12.6+
Fix from $1,600 2022-11-01
Datahub CRITICAL 9.8
CVE-2022-39366

DataHub is an open-source metadata platform. Prior to version 0.8.45, the `StatelessTokenService` of the DataHub metadata service (GMS) does not veri…

Fix: 0.8.45+
Fix from $2,300 2022-10-28
Warp Mobile Client HIGH 7.5
CVE-2022-3322

Lock Warp switch is a feature of Zero Trust platform which, when enabled, prevents users of enrolled devices from disabling WARP client. Due to ins…

Fix: 6.14+
Fix from $1,950 2022-10-28
Grafana HIGH 7.8
CVE-2022-31123

Grafana is an open source observability and data visualization platform. Versions prior to 9.1.8 and 8.5.14 are vulnerable to a bypass in the plugin …

Fix: 8.5.14 / 9.1.8+
Fix from $1,950 2022-10-13
Node Saml HIGH 8.1
CVE-2022-39300

node SAML is a SAML 2.0 library based on the SAML implementation of passport-saml. A remote attacker may be able to bypass SAML authentication on a w…

Fix: 4.0.0+
Fix from $1,950 2022-10-13
Passport Saml HIGH 8.1
CVE-2022-39299

Passport-SAML is a SAML 2.0 authentication provider for Passport, the Node.js authentication library. A remote attacker may be able to bypass SAML au…

Fix: 3.2.2+
Fix from $1,950 2022-10-12
Ios Xe MEDIUM 6.8
CVE-2022-20944

A vulnerability in the software image verification functionality of Cisco IOS XE Software for Cisco Catalyst 9200 Series Switches could allow an unau…

Mitigation only
Fix from $1,600 2022-10-10
Fedora MEDIUM 6.5
CVE-2022-42010

An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-…

Fix: 1.12.24 / 1.14.4+
Fix from $1,600 2022-10-10
Singularity Image Format CRITICAL 9.8
CVE-2022-39237

syslabs/sif is the Singularity Image Format (SIF) reference implementation. In versions prior to 2.8.1the `github.com/sylabs/sif/v2/pkg/integrity` pa…

Fix: 2.8.1+
Fix from $2,300 2022-10-06
Secp256k1 Js HIGH 7.5
CVE-2022-41340

The secp256k1-js package before 1.1.0 for Node.js implements ECDSA without required r and s validation, leading to signature forgery.

Fix: 1.1.0+
Fix from $1,950 2022-09-24
Cosign MEDIUM 5.5
CVE-2022-36056

Cosign is a project under the sigstore organization which aims to make signatures invisible infrastructure. In versions prior to 1.12.0 a number of v…

Fix: 1.12.0+
Fix from $1,600 2022-09-14
Dendrite MEDIUM 5.3
CVE-2022-39200

Dendrite is a Matrix homeserver written in Go. In affected versions events retrieved from a remote homeserver using the `/get_missing_events` path di…

Fix: 0.9.8+
Fix from $1,600 2022-09-12