Vulnerability index

Browse CVEs

732 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Signature VerificationCWE-347 × clear
Net\ CRITICAL 9.8
CVE-2026-18108

Net::SAML2 versions before 0.86 for Perl allow authentication bypass because _verify_encrypted_assertion accepts an EncryptedAssertion whose decrypte…

Fix: 0.86+
Fix from $2,300 2026-08-03
Net\ HIGH 7.5
CVE-2026-18089

Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass by verifying responses against the response-embedded certificate in verify_…

Fix: 0.86+
Fix from $1,950 2026-08-03
Unclassified HIGH 7.3
CVE-2026-0392

eParakstītājs 3.0 for Windows before version 1.10.0 retrieves and executes its automatic updates over a channel that is not authenticated or integrit…

No fix yet
Fix from $1,950 2026-08-03
Unclassified HIGH 8.7
CVE-2026-12860

In Bouncy Castle for Java before 1.85, RSA PKCS#1 verification skips last two hash bytes in NULL-omitted path. This issue also affects Bouncy Castle …

Mitigation only
Fix from $1,950 2026-08-03
Unclassified HIGH 8.7
CVE-2026-59643

In Bouncy Castle for Java before 1.85, OpenPGP inline-signature policy failures silently ignored. This issue also affects Bouncy Castle for Java FIPS…

No fix yet
Fix from $1,950 2026-08-03
Unclassified HIGH 8.7
CVE-2026-59639

In Bouncy Castle for Java before 1.85, CMS verifySignatures returns true for SignedData with zero signers. This issue also affects Bouncy Castle for …

No fix yet
Fix from $1,950 2026-08-03
Guardian HIGH 7.5
CVE-2026-55735

Improper Verification of Cryptographic Signature in ueberauth guardian allows an unauthenticated attacker to revoke a victim's session with a forged …

Fix: 2.4.1+
Fix from $1,950 2026-08-01
Unclassified HIGH 8.2
CVE-2026-53501

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor’s HMAC validation can be bypassed due to the use of Python’s …

No fix yet
Fix from $1,950 2026-07-31
Unclassified CRITICAL 9.8
CVE-2026-44104

The firmware update process for the basemodule of the charging controller only validates the CRC32 checksum without cryptographic signature verificat…

No fix yet
Fix from $2,300 2026-07-30
Chrome MEDIUM 6.1
CVE-2026-17872

Cryptographic Flaw in WebAppInstalls in Google Chrome on Android prior to 151.0.7922.72 allowed a local attacker to potentially perform a sandbox esc…

Fix: 151.0.7922.72+
Fix from $1,600 2026-07-30
Unclassified MEDIUM 6.4
CVE-2026-13305

Autel MaxiCharger AC Elite Home Software Update Improper Verification of Cryptographic Signature Arbitrary Code Execution Vulnerability. This vulnera…

No fix yet
Fix from $1,600 2026-07-29
Apache Airflow Providers Fab CRITICAL 9.8
CVE-2026-59243

The FAB auth manager's Azure AD OAuth login defaulted `verify_signature=False` when decoding the ID token, so an attacker able to present a forged or…

Fix: 3.7.3+
Fix from $2,300 2026-07-29
Artifactory HIGH 8.8
CVE-2026-65616

Incorrect authorization validation in refresh token signature allows non-admin users to obtain a signed JFrog administrator token.

Fix: 7.146.27+
Fix from $1,950 2026-07-27
Unclassified HIGH 7.8
CVE-2026-14837

Multiple Lenze products are affected by an improper signature verification vulnerability in the SSH enablement mechanism. A low-privileged local atta…

No fix yet
Fix from $1,950 2026-07-27
Unclassified CRITICAL 9.1
CVE-2026-48021

In epa4all, prior to version 2026-05-20, an attacker who can intercept the TLS connection between epa4all and the ePA backend can complete the VAU ha…

No fix yet
Fix from $2,300 2026-07-24
Unclassified HIGH 7.5
CVE-2026-13089

OIDC::Lite versions through 0.12.1 for Perl allow ID Token signature verification bypass via a token-controlled algorithm allowlist in verify. When …

No fix yet
Fix from $1,950 2026-07-22
Unclassified MEDIUM 6.8
CVE-2026-10723

BIND may accept incorrect child-zone NSEC3 records as valid, which could allow an attacker to forge authenticated NXDOMAIN responses. This issue affe…

No fix yet
Fix from $1,600 2026-07-22
Unclassified HIGH 8.6
CVE-2026-64623

Network-AI before 5.13.4 contains an improper cryptographic signature verification vulnerability in APSAdapter where the default local verifier accep…

No fix yet
Fix from $1,950 2026-07-20
Sigstore Go HIGH 7.5
CVE-2026-49834

sigstore-go is a Go library for Sigstore signing and verification. Prior to 1.2.0, a verifier configured with WithTransparencyLog(N>1) or WithSignedC…

Fix: 1.2.0+
Fix from $1,950 2026-07-17
Unclassified HIGH 8.2
CVE-2026-49998

Centrifugo is an open-source scalable real-time messaging server. Prior to 6.8.1, Centrifugo dynamic JWKS endpoint verification could reuse a key for…

No fix yet
Fix from $1,950 2026-07-16
Unclassified MEDIUM 5.3
CVE-2026-45795

The Janssen Project is an open-source identity and access management (IAM) platform. Prior to 2.0.0, jans-auth-server accepts unsigned JWE request ob…

No fix yet
Fix from $1,600 2026-07-16
Unclassified CRITICAL 9.3
CVE-2026-54733

The Microsoft 365 and Microsoft Entra ID Plugins for Moodle provide Office 365 and Azure Active Directory integration for Moodle. Prior to 4.5.6, 5.0…

No fix yet
Fix from $2,300 2026-07-16
Unclassified CRITICAL 9.8
CVE-2026-15013

The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass via SAML Signature Algorithm Confusion in all version…

No fix yet
Fix from $2,300 2026-07-16
Unclassified CRITICAL 9.5
CVE-2026-46684

DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase enterprise token handling can let TokenFilter#doFilter() …

Mitigation only
Fix from $2,300 2026-07-15
Unclassified MEDIUM 5.4
CVE-2026-48758

sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 3.2.1, the preAuthEncoding function in @sigstore/core uses…

Mitigation only
Fix from $1,600 2026-07-14
Unclassified HIGH 7.5
CVE-2026-48815

sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 4.1.1, the documented certificateOIDs option in sigstore.v…

Mitigation only
Fix from $1,950 2026-07-14
Symfony MEDIUM 5.3
CVE-2026-48747

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 7.4.13 and 8.0.13, MailomatRequestParser::…

Fix: 7.4.13 / 8.0.13+
Fix from $1,600 2026-07-14
Symfony MEDIUM 5.3
CVE-2026-47212

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.12, and 8.0.12, TwilioRequestP…

Fix: 6.4.40 / 7.4.12+
Fix from $1,600 2026-07-14
.net Framework CRITICAL 9.8
CVE-2026-47304

Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.

Fix: 8.0.29 / 9.0.18+
Fix from $2,300 2026-07-14
Symfony MEDIUM 5.3
CVE-2026-45755

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 7.4.12 and 8.0.12, MailtrapRequestParser::…

Fix: 7.4.12 / 8.0.12+
Fix from $1,600 2026-07-14