Vulnerability index

Browse CVEs

733 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Signature VerificationCWE-347 × clear
Spacecom2 CRITICAL 9.8
CVE-2021-33885EPSS 6%

An Insufficient Verification of Data Authenticity vulnerability in B. Braun SpaceCom2 prior to 012U000062 allows a remote unauthenticated attacker to…

Fix: 012u000062+
Fix from $2,300 2021-08-25
Californium HIGH 7.5
CVE-2021-34433

In Eclipse Californium version 2.0.0 to 2.6.4 and 3.0.0-M1 to 3.0.0-M3, the certificate based (x509 and RPK) DTLS handshakes accidentally succeeds wi…

Fix: 2.6.5+
Fix from $1,950 2021-08-20
Expressway HIGH 7.2
CVE-2021-34715

A vulnerability in the image verification function of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an …

Patch available
Fix from $1,950 2021-08-18
Drivers Management HIGH 7.8
CVE-2021-3633

A DLL preloading vulnerability was reported in Lenovo Driver Management prior to version 2.9.0719.1104 that could allow privilege escalation.

Fix: 2.9.0719.1104+
Fix from $1,950 2021-08-17
Alienware Command Center Application HIGH 7.8
CVE-2021-36277

Dell Command | Update, Dell Update, and Alienware Update versions before 4.3 contains an Improper Verification of Cryptographic Signature Vulnerabili…

Fix: 4.3.0 / 5.4.35.0+
Fix from $1,950 2021-08-09
Libsecp256k1 CRITICAL 9.8
CVE-2021-38195

An issue was discovered in the libsecp256k1 crate before 0.5.0 for Rust. It can verify an invalid signature because it allows the R or S parameter to…

Fix: 0.5.0+
Fix from $2,300 2021-08-08
Hmi 3 Control Panel Firmware CRITICAL 9.8
CVE-2021-37160EPSS 8%

A firmware validation issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by released versions of software before …

Fix: 7.2.5.7+
Fix from $2,300 2021-08-02
Evlink City Evc1s22p4 Firmware HIGH 7.2
CVE-2021-22708

A CWE-347: Improper Verification of Cryptographic Signature vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0…

Mitigation only
Fix from $1,950 2021-07-21
Fortimail CRITICAL 9.8
CVE-2021-24020

A missing cryptographic step in the implementation of the hash digest algorithm in FortiMail 6.4.0 through 6.4.4, and 6.2.0 through 6.2.7 may allow a…

Fix: 6.4.5+
Fix from $2,300 2021-07-09
Fortimail HIGH 7.5
CVE-2021-26100

A missing cryptographic step in the Identity-Based Encryption service of FortiMail before 7.0.0 may allow an unauthenticated attacker who intercepts …

Fix: 7.0.0+
Fix from $1,950 2021-07-09
Linux Kernel HIGH 7.8
CVE-2021-35039

kernel/module.c in the Linux kernel before 5.12.14 mishandles Signature Verification, aka CID-0c18f29aae7c. Without CONFIG_MODULE_SIG, verification t…

Fix: 4.19.196 / 5.4.129+
Fix from $1,950 2021-07-07
Js Stellar Sdk MEDIUM 6.5
CVE-2021-32738

js-stellar-sdk is a Javascript library for communicating with a Stellar Horizon server. The `Utils.readChallengeTx` function used in SEP-10 Stellar W…

Fix: 8.2.3+
Fix from $1,600 2021-07-02
Thunderbird MEDIUM 6.5
CVE-2021-23993

An attacker may perform a DoS attack to prevent a user from sending encrypted email to a correspondent. If an attacker creates a crafted OpenPGP key …

Fix: 78.9.1+
Fix from $1,600 2021-06-24
Tenvoy CRITICAL 9.8
CVE-2021-32685

tEnvoy contains the PGP, NaCl, and PBKDF2 in node.js and the browser (hashing, random, encryption, decryption, signatures, conversions), used by Toga…

Fix: 7.0.3+
Fix from $2,300 2021-06-16
Id Bravura Security Fabric HIGH 8.8
CVE-2021-3196

An issue was discovered in Hitachi ID Bravura Security Fabric 11.0.0 through 11.1.3, 12.0.0 through 12.0.2, and 12.1.0. When using federated identity…

Fix: after 12.0.2
Fix from $1,950 2021-06-09
Bubble Fireworks HIGH 7.5
CVE-2021-29500

bubble fireworks is an open source java package relating to Spring Framework. In bubble fireworks before version 2021.BUILD-SNAPSHOT there is a vulne…

Fix: 2021.build-snapshot+
Fix from $1,950 2021-06-04
Debian Linux HIGH 7.5
CVE-2021-28091

Lasso all versions prior to 2.7.0 has improper verification of a cryptographic signature.

Fix: 2.7.0+
Fix from $1,950 2021-06-04
Debian Linux HIGH 7.5
CVE-2021-33054

SOGo 2.x before 2.4.1 and 3.x through 5.x before 5.1.1 does not validate the signatures of any SAML assertions it receives. Any actor with network ac…

Fix: 2.4.1 / 5.1.1+
Fix from $1,950 2021-06-04
Spacelynk Firmware HIGH 7.2
CVE-2021-22734

Improper Verification of Cryptographic Signature vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could cause rem…

Fix: after 2.6.0
Fix from $1,950 2021-05-26
Spacelynk Firmware HIGH 7.2
CVE-2021-22735

Improper Verification of Cryptographic Signature vulnerability exists inhomeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could allow remo…

Fix: after 2.6.0
Fix from $1,950 2021-05-26
Power9 System Firmware CRITICAL 9.1
CVE-2021-20487

IBM Power9 Self Boot Engine(SBE) could allow a privileged user to inject malicious code and compromise the integrity of the host firmware bypassing t…

Mitigation only
Fix from $2,300 2021-05-26
Pulsar CRITICAL 9.8
CVE-2021-22160EPSS 53%

If Apache Pulsar is configured to authenticate clients using tokens based on JSON Web Tokens (JWT), the signature of the token is not validated if th…

Fix: 2.7.1+
Fix from $2,300 2021-05-26
Enterprise Linux MEDIUM 5.5
CVE-2021-3421

A flaw was found in the RPM package in the read functionality. This flaw allows an attacker who can convince a victim to install a seemingly verifiab…

Fix: 4.16.1.3+
Fix from $1,600 2021-05-19
Fedora HIGH 7.5
CVE-2021-3445

A flaw was found in libdnf's signature verification functionality in versions before 0.60.1. This flaw allows an attacker to achieve code execution i…

Fix: 0.60.1+
Fix from $1,950 2021-05-19
Grassroot Platform MEDIUM 5.3
CVE-2021-29455

Grassroot Platform is an application to make it faster, cheaper and easier to persistently organize and mobilize people in low-income communities. Gr…

Fix: 1.3.1+
Fix from $1,600 2021-04-19
Portofino CRITICAL 9.1
CVE-2021-29451

Portofino is an open source web development framework. Portofino before version 5.2.1 did not properly verify the signature of JSON Web Tokens. This …

Fix: 5.2.1+
Fix from $2,300 2021-04-16
Lotus HIGH 7.5
CVE-2021-21405

Lotus is an Implementation of the Filecoin protocol written in Go. BLS signature validation in lotus uses blst library method VerifyCompressed. This …

Fix: 1.5.0+
Fix from $1,950 2021-04-15
Jsrsasign CRITICAL 9.1
CVE-2021-30246

In the jsrsasign package through 10.1.13 for Node.js, some invalid RSA PKCS#1 v1.5 signatures are mistakenly recognized to be valid. NOTE: there is n…

Fix: after 10.1.13
Fix from $2,300 2021-04-07
Union Pay HIGH 7.5
CVE-2020-36284

Union Pay up to 3.4.93.4.9, for android, contains a CWE-347: Improper Verification of Cryptographic Signature vulnerability, allows attackers to shop…

Fix: after 3.4.93.4.9
Fix from $1,950 2021-04-06
Union Pay HIGH 7.5
CVE-2020-36285

Union Pay up to 3.3.12, for iOS mobile apps, contains a CWE-347: Improper Verification of Cryptographic Signature vulnerability, allows attackers to …

Fix: after 3.3.12
Fix from $1,950 2021-04-06