Vulnerability index

Browse CVEs

733 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Signature VerificationCWE-347 × clear
Aqt1000 Firmware MEDIUM 6.8
CVE-2021-35097

Possible authentication bypass due to improper order of signature verification and hashing in the signature verification call in Snapdragon Auto, Sna…

Mitigation only
Fix from $1,600 2022-09-02
Aqt1000 Firmware MEDIUM 6.8
CVE-2021-35113

Possible authentication bypass due to improper order of signature verification and hashing in the signature verification call in Snapdragon Auto, Sna…

Mitigation only
Fix from $1,600 2022-09-02
Pdf Editor MEDIUM 5.5
CVE-2021-40326

Foxit PDF Reader before 11.1 and PDF Editor before 11.1, and PhantomPDF before 10.1.6, mishandle hidden and incremental data in signed documents. An …

Fix: 10.1.6 / 11.1+
Fix from $1,600 2022-08-29
Electric\'s Proficy MEDIUM 5.9
CVE-2022-2790

Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulenrable to CWE-347 Improper Verification of Cryptographic Signature, and does…

Fix: after 9.0.0
Fix from $1,600 2022-08-19
Meetings HIGH 7.8
CVE-2022-28751

The Zoom Client for Meetings for MacOS (Standard and for IT Admin) before version 5.11.3 contains a vulnerability in the package signature validation…

Fix: 5.11.3+
Fix from $1,950 2022-08-17
Rooms HIGH 7.8
CVE-2022-28752

Zoom Rooms for Conference Rooms for Windows versions before 5.11.0 are susceptible to a Local Privilege Escalation vulnerability. A local low-privile…

Fix: 5.11.0+
Fix from $1,950 2022-08-17
Meetings HIGH 7.8
CVE-2022-28756

The Zoom Client for Meetings for macOS (Standard and for IT Admin) starting with version 5.7.3 and before 5.11.5 contains a vulnerability in the auto…

Fix: 5.11.5+
Fix from $1,950 2022-08-15
Policy Controller HIGH 8.8
CVE-2022-35930

PolicyController is a utility used to enforce supply chain policy in Kubernetes clusters. In versions prior to 0.2.1 PolicyController will report a f…

Fix: 0.2.1+
Fix from $1,950 2022-08-04
Cosign CRITICAL 9.8
CVE-2022-35929

cosign is a container signing and verification utility. In versions prior to 1.10.1 cosign can report a false positive if any attestation exists. `co…

Fix: 1.10.1+
Fix from $2,300 2022-08-04
Nx701 1600 Firmware CRITICAL 9.8
CVE-2022-31206

The Omron SYSMAC Nx product family PLCs (NJ series, NY series, NX series, and PMAC series) through 2022-005-18 lack cryptographic authentication. The…

Fix: 1.29 / 1.49+
Fix from $2,300 2022-07-26
Sysmac Cs1 Firmware CRITICAL 9.8
CVE-2022-31207

The Omron SYSMAC Cx product family PLCs (CS series, CJ series, and CP series) through 2022-05-18 lack cryptographic authentication. They utilize the …

Fix: 1.5 / 1.10+
Fix from $2,300 2022-07-26
Contracts HIGH 7.5
CVE-2022-31172

OpenZeppelin Contracts is a library for smart contract development. Versions 4.1.0 until 4.7.1 are vulnerable to the SignatureChecker reverting. `Sig…

Fix: 4.7.1+
Fix from $1,950 2022-07-22
HTTP Server CRITICAL 9.8
CVE-2020-35169

Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.5.2, contain an Improper Input Valida…

Fix: 4.1.5 / 4.5.2+
Fix from $2,300 2022-07-11
Jsrsasign CRITICAL 9.8
CVE-2022-25898

The package jsrsasign before 10.5.25 are vulnerable to Improper Verification of Cryptographic Signature when JWS or JWT signature with non Base64URL …

Fix: 10.5.25+
Fix from $2,300 2022-07-01
Imagecast X MEDIUM 6.8
CVE-2022-1739

The tested version of Dominion Voting Systems ImageCast X does not validate application signatures to a trusted root certificate. Use of a trusted ro…

Mitigation only
Fix from $1,600 2022-06-24
Biscuit Auth CRITICAL 9.8
CVE-2022-31053

Biscuit is an authentication and authorization token for microservices architectures. The Biscuit specification version 1 contains a vulnerable algor…

Fix: 2.0.0+
Fix from $2,300 2022-06-13
Ir302 Firmware MEDIUM 6.5
CVE-2022-26510

A firmware update vulnerability exists in the iburn firmware checks functionality of InHand Networks InRouter302 V3.5.37. A specially-crafted HTTP re…

No fix yet
Fix from $1,600 2022-05-12
Fedora HIGH 7.5
CVE-2022-24884

ecdsautils is a tiny collection of programs used for ECDSA (keygen, sign, verify). `ecdsa_verify_[prepare_]legacy()` does not check whether the signa…

Fix: 0.4.1+
Fix from $1,950 2022-05-06
Oauth Client Library For Java HIGH 7.3
CVE-2021-22573

The vulnerability is that IDToken verifier does not verify if token is properly signed. Signature verification makes sure that the token's payload co…

Fix: 1.33.3+
Fix from $1,950 2022-05-03
Datamodule Compactplus HIGH 7.1
CVE-2020-25166

An improper verification of the cryptographic signature of firmware updates of the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and th…

Mitigation only
Fix from $1,950 2022-04-14
System Platform HIGH 7.2
CVE-2021-32977

AVEVA System Platform versions 2017 through 2020 R2 P01 does not verify, or incorrectly verifies, the cryptographic signature for data.

Fix: 2020+
Fix from $1,950 2022-04-04
Tofino Xenon Security Appliance Firmware MEDIUM 6.8
CVE-2021-30066

On Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and Belden Tofino Xenon Security Appliance, an arbitr…

Fix: 03.2.03+
Fix from $1,600 2022-04-03
Ykneo Openpgp HIGH 8.8
CVE-2015-3298

Yubico ykneo-openpgp before 1.0.10 has a typo in which an invalid PIN can be used. When first powered up, a signature will be issued even though the …

Fix: 1.0.10+
Fix from $1,950 2022-03-30
Forge HIGH 7.5
CVE-2022-24771

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.3.0, RSA PKCS#1 v1.5 signat…

Fix: 1.3.0+
Fix from $1,950 2022-03-18
Forge HIGH 7.5
CVE-2022-24772

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.3.0, RSA PKCS#1 v1.5 signat…

Fix: 1.3.0+
Fix from $1,950 2022-03-18
Forge MEDIUM 5.3
CVE-2022-24773

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.3.0, RSA PKCS#1 v1.5 signat…

Fix: 1.3.0+
Fix from $1,600 2022-03-18
Js Libp2p Noise HIGH 7.4
CVE-2022-24759

`@chainsafe/libp2p-noise` contains TypeScript implementation of noise protocol, an encryption protocol used in libp2p. `@chainsafe/libp2p-noise` befo…

Fix: 4.1.2 / 5.0.3+
Fix from $1,950 2022-03-17
Wire Server HIGH 8.1
CVE-2022-23610

wire-server provides back end services for Wire, an open source messenger. In versions of wire-server prior to the 2022-01-27 release, it was possibl…

Fix: 2.123.0+
Fix from $1,950 2022-03-16
Coreos Installer HIGH 7.8
CVE-2021-20319

An improper signature verification vulnerability was found in coreos-installer. A specially crafted gzip installation image can bypass the image sign…

Fix: 0.10.1+
Fix from $1,950 2022-03-04
J Safe3 Firmware MEDIUM 6.2
CVE-2021-43392

STMicroelectronics STSAFE-J 1.1.4, J-SAFE3 1.2.5, and J-SIGN sometimes allow attackers to obtain information on cryptographic secrets. This is associ…

Mitigation only
Fix from $1,600 2022-03-04