Vulnerability index

Browse CVEs

733 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Signature VerificationCWE-347 × clear
Union Pay HIGH 7.5
CVE-2020-23533

Union Pay up to 1.2.0, for web based versions contains a CWE-347: Improper Verification of Cryptographic Signature vulnerability, allows attackers to…

Fix: after 1.2.0
Fix from $1,950 2021-04-06
Debian Linux HIGH 7.5
CVE-2021-30130

phpseclib before 2.0.31 and 3.x before 3.0.7 mishandles RSA PKCS#1 v1.5 signature verification.

Fix: 2.0.31 / 3.0.7+
Fix from $1,950 2021-04-06
Ios Xe MEDIUM 6.7
CVE-2021-1375

Multiple vulnerabilities in the fast reload feature of Cisco IOS XE Software running on Cisco Catalyst 3850, Cisco Catalyst 9300, and Cisco Catalyst …

Mitigation only
Fix from $1,600 2021-03-24
Ios Xe MEDIUM 6.7
CVE-2021-1376

Multiple vulnerabilities in the fast reload feature of Cisco IOS XE Software running on Cisco Catalyst 3850, Cisco Catalyst 9300, and Cisco Catalyst …

Mitigation only
Fix from $1,600 2021-03-24
Ios Xe MEDIUM 6.8
CVE-2021-1453

A vulnerability in the software image verification functionality of Cisco IOS XE Software for the Cisco Catalyst 9000 Family of switches could allow …

Mitigation only
Fix from $1,600 2021-03-24
Security Space HIGH 7.8
CVE-2020-23967

Dr.Web Security Space versions 11 and 12 allow elevation of privilege for local users without administrative privileges to NT AUTHORITY\SYSTEM due to…

No fix yet
Fix from $1,950 2021-03-08
Fedora CRITICAL 9.8
CVE-2021-3406

A flaw was found in keylime 5.8.1 and older. The issue in the Keylime agent and registrar code invalidates the cryptographic chain of trust from the …

Fix: after 5.8.1
Fix from $2,300 2021-02-25
Anyconnect Secure Mobility Client HIGH 7.8
CVE-2021-1366

A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, …

Fix: 4.9.05042+
Fix from $1,950 2021-02-17
Prisma Cloud CRITICAL 9.8
CVE-2021-3033

An improper verification of cryptographic signature vulnerability exists in the Palo Alto Networks Prisma Cloud Compute console. This vulnerability e…

Mitigation only
Fix from $2,300 2021-02-10
Ios Xr MEDIUM 6.7
CVE-2021-1136

Multiple vulnerabilities in Cisco Network Convergence System (NCS) 540 Series Routers, only when running Cisco IOS XR NCS540L software images, and Ci…

Fix: 7.0.12 / 7.2.1+
Fix from $1,600 2021-02-04
Ios Xr MEDIUM 6.7
CVE-2021-1244

Multiple vulnerabilities in Cisco Network Convergence System (NCS) 540 Series Routers, only when running Cisco IOS XR NCS540L software images, and Ci…

Fix: 7.0.12 / 7.2.1+
Fix from $1,600 2021-02-04
Cs C2shw Firmware CRITICAL 9.8
CVE-2020-27540

Bash injection vulnerability and bypass of signature verification in Rostelecom CS-C2SHW 5.0.082.1. The camera reads firmware update configuration fr…

No fix yet
Fix from $2,300 2021-01-26
Pysaml2 MEDIUM 6.5
CVE-2021-21238

PySAML2 is a pure python implementation of SAML Version 2 Standard. PySAML2 before 6.5.0 has an improper verification of cryptographic signature vuln…

Fix: 6.5.0+
Fix from $1,600 2021-01-21
Debian Linux MEDIUM 6.5
CVE-2021-21239

PySAML2 is a pure python implementation of SAML Version 2 Standard. PySAML2 before 6.5.0 has an improper verification of cryptographic signature vuln…

Fix: 6.5.0+
Fix from $1,600 2021-01-21
Master Pdf Editor MEDIUM 5.3
CVE-2018-18688

The Portable Document Format (PDF) specification does not provide any information regarding the concrete procedure of how to validate signatures. Con…

Fix: 9.4+
Fix from $1,600 2021-01-07
Expert Pdf Ultimate MEDIUM 5.3
CVE-2018-18689

The Portable Document Format (PDF) specification does not provide any information regarding the concrete procedure of how to validate signatures. Con…

Mitigation only
Fix from $1,600 2021-01-07
Dex CRITICAL 9.6
CVE-2020-26290

Dex is a federated OpenID Connect provider written in Go. In Dex before version 2.27.0 there is a critical set of vulnerabilities which impacts users…

Fix: 2.27.0+
Fix from $2,300 2020-12-28
Indy Node HIGH 7.5
CVE-2020-11093

Hyperledger Indy Node is the server portion of a distributed ledger purpose-built for decentralized identity. In Hyperledger Indy before version 1.12…

Fix: 1.12.4+
Fix from $1,950 2020-12-24
Password Store HIGH 7.5
CVE-2020-28086

pass through 1.7.3 has a possibility of using a password for an unintended resource. For exploitation to occur, the user must do a git pull, decrypt …

Fix: after 1.7.3
Fix from $1,950 2020-12-09
Nf8480m5 Firmware HIGH 7.2
CVE-2020-26122

Inspur NF5266M5 through 3.21.2 and other server M5 devices allow remote code execution via administrator privileges. The Baseboard Management Control…

Fix: 1.18.51 / 1.19.33+
Fix from $1,950 2020-12-07
Python Openid Connect MEDIUM 6.8
CVE-2020-26244

Python oic is a Python OpenID Connect implementation. In Python oic before version 1.2.1, there are several related cryptographic issues affecting cl…

Fix: 1.2.1+
Fix from $1,600 2020-12-02
Model X Firmware MEDIUM 6.5
CVE-2020-29438

Tesla Model X vehicles before 2020-11-23 have key fobs that accept firmware updates without signature verification. This allows attackers to construc…

Fix: 2020-11-23+
Fix from $1,600 2020-11-30
Nextcloud Server MEDIUM 5.3
CVE-2020-8133

A wrong generation of the passphrase for the encrypted block in Nextcloud Server 19.0.1 allowed an attacker to overwrite blocks in a file.

No fix yet
Fix from $1,600 2020-11-09
Acrobat HIGH 7.8
CVE-2020-24429

Acrobat Reader DC versions 2020.012.20048 (and earlier), 2020.001.30005 (and earlier) and 2017.011.30175 (and earlier) for macOS are affected by a si…

Fix: after 20.012.20048
Fix from $1,950 2020-11-05
Servicestack MEDIUM 5.3
CVE-2020-28042

ServiceStack before 5.9.2 mishandles JWT signature verification unless an application has a custom ValidateToken function that establishes a valid mi…

Fix: 5.9.2+
Fix from $1,600 2020-11-02
Prolinos HIGH 7.8
CVE-2020-28045

An unsigned-library issue was discovered in ProlinOS through 2.4.161.8859R. This OS requires installed applications and all system binaries to be sig…

Fix: after 2.4.161.8859r
Fix from $1,950 2020-11-02
Bmc Firmware MEDIUM 6.7
CVE-2020-11488

NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30 and all DGX-2 with BMC firmware versions prior to 1.06.06, contains a vulne…

Fix: 1.06.06 / 3.38.30+
Fix from $1,600 2020-10-29
Ipados MEDIUM 6.5
CVE-2019-8901

This issue was addressed by verifying host keys when connecting to a previously-known SSH server. This issue is fixed in iOS 13.1 and iPadOS 13.1. An…

Fix: 13.1+
Fix from $1,600 2020-10-27
Omniauth Auth0 CRITICAL 9.1
CVE-2020-15240

omniauth-auth0 (rubygems) versions >= 2.3.0 and < 2.4.1 improperly validate the JWT token signature when using the `jwt_validator.verify` method. Imp…

Fix: 2.4.1+
Fix from $2,300 2020-10-21
Windows 10 MEDIUM 5.3
CVE-2020-16922

<p>A spoofing vulnerability exists when Windows incorrectly validates file signatures. An attacker who successfully exploited this vulnerability coul…

Patch available
Fix from $1,600 2020-10-16