Vulnerability index

Browse CVEs

732 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Signature VerificationCWE-347 × clear
Unclassified CRITICAL 9.1
CVE-2026-15265

A path traversal vulnerability in Tenable Agent 11.2.0 and 11.1.3 and lower allows a privileged attacker to write arbitrary files outside the intende…

Mitigation only
Fix from $2,300 2026-07-14
Unclassified CRITICAL 10.0
CVE-2026-56451

A vulnerability has been identified in Opcenter X (All versions < V2604). Affected applications do not properly validate the algorithm specified in t…

Mitigation only
Fix from $2,300 2026-07-14
Unclassified CRITICAL 9.3
CVE-2026-22097

The firmware update mechanism does not include cryptographic signature validation. This allows anyone with access to the firmware update capability t…

Mitigation only
Fix from $2,300 2026-07-13
Unclassified HIGH 8.2
CVE-2026-54736

Phalcon is a high-performance, full-stack PHP framework. Prior to 5.14.1, Phalcon\Encryption\Crypt::decrypt compares the attacker-supplied HMAC tag a…

Patch available
Fix from $1,950 2026-07-10
Unclassified MEDIUM 5.3
CVE-2026-9027

The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulnerable to Payment Bypass via Improper Verification of Cryptographic Signature i…

Mitigation only
Fix from $1,600 2026-07-09
Unclassified CRITICAL 10.0
CVE-2026-54782

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF SAML 1.1 and SAML 2.0…

Patch available
Fix from $2,300 2026-07-08
Unclassified HIGH 7.4
CVE-2026-54783

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF WS-Security endorsing…

Patch available
Fix from $1,950 2026-07-08
Unclassified HIGH 7.4
CVE-2026-54774

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, SamlSerializer skips final Si…

Patch available
Fix from $1,950 2026-07-08
Unclassified MEDIUM 5.9
CVE-2026-54773

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF WS-Security signature…

Patch available
Fix from $1,600 2026-07-08
Coder CRITICAL 9.1
CVE-2026-46354

Coder allows organizations to provision remote development environments via Terraform. In versions prior tp 2.24.5, 2.29.13, 2.30.8, 2.31.12, 2.32.2,…

Fix: 2.24.5 / 2.29.13+
Fix from $2,300 2026-07-07
Unclassified HIGH 8.1
CVE-2026-11348

Improper verification of cryptographic signature vulnerability in HAVELSAN Inc. Liman MYS allows Fake the Source of Data. This issue affects Liman M…

Mitigation only
Fix from $1,950 2026-07-07
Unclassified CRITICAL 9.6
CVE-2026-58426

Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write

Patch available
Fix from $2,300 2026-07-03
Fireware HIGH 7.2
CVE-2026-13722

WatchGuard Fireware OS contains a firmware validation bypass when processing a backup image via the backup/restore feature. An authenticated administ…

Fix: 11.12.4 / 12.12.1+
Fix from $1,950 2026-07-03
Libreswan MEDIUM 5.9
CVE-2026-50721

Libreswan, via the function RSA_authenticate_hash_signature_raw_rsa(), did not correctly verify the length of the authentication hash when the SIG pa…

Fix: 5.3.1+
Fix from $1,600 2026-07-02
Libreswan MEDIUM 5.9
CVE-2026-50722

Libreswan, via the function RSA_authenticate_hash_signature_pkcs1_1_5_rsa(), did not correctly verify the DER encoding of the ASN.1 digest when the I…

Fix: 5.3.1+
Fix from $1,600 2026-07-02
Traveler For Microsoft Outlook HIGH 7.8
CVE-2024-23581

The HCL Traveler for Microsoft Outlook libraries are being flagged as potentially malicious software or an unrecognized application.

Fix: 3.0.9+
Fix from $1,950 2026-06-26
Cacti MEDIUM 6.5
CVE-2026-40941

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have a package import signature validation bypass allow…

Fix: 1.2.31+
Fix from $1,600 2026-06-25
Wolfssl HIGH 7.5
CVE-2026-6331

HMAC zero-length tag forgery in EVP_DigestVerifyFinal, where a zero-length tag could be accepted as valid during HMAC verification. In the OpenSSL-co…

Fix: 5.9.2+
Fix from $1,950 2026-06-25
Wolfssl HIGH 7.5
CVE-2026-7511

PKCS7_verify signer confusion allows forged signatures, where the signer associated with a signature is not correctly bound, permitting a forged sign…

Fix: 5.9.2+
Fix from $1,950 2026-06-25
Wolfssl MEDIUM 6.5
CVE-2026-6329

PKCS#12 MAC verification uses an attacker-controlled comparison length, weakening the integrity check on the MAC and allowing a mismatched MAC to be …

Fix: 5.9.2+
Fix from $1,600 2026-06-25
Build Of Keycloak HIGH 8.1
CVE-2026-11800

A flaw was found in Keycloak. This JWT algorithm confusion vulnerability in the JWT Authorization Grant flow allows an attacker with valid client cre…

Fix: 26.6.4+
Fix from $1,950 2026-06-25
Wolfssl HIGH 7.5
CVE-2026-55961

wolfSSL_PKCS7_verify() returning success for a degenerate (certs-only) PKCS#7 object that contains no signer. Such an object has empty signerInfos, s…

Fix: 5.9.2+
Fix from $1,950 2026-06-25
Unizon HIGH 7.2
CVE-2026-9779

ATEN Unizon doCryptoHugeFileToFile Improper Verification of Cryptographic Signature Remote Code Execution Vulnerability. This vulnerability allows re…

Fix: 2.7.264+
Fix from $1,950 2026-06-24
Unclassified CRITICAL 9.3
CVE-2026-46423

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, 8.1.4, 8.0.5, 7.13.7, and 7.1…

Mitigation only
Fix from $2,300 2026-06-24
Unclassified MEDIUM 5.3
CVE-2026-46349

Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.5.10, 4.4.17, and 4.3.23, Mastodon's normalization of incoming…

Mitigation only
Fix from $1,600 2026-06-24
Unclassified CRITICAL 9.1
CVE-2026-49454

Relyra is a strict-by-default SAML 2.0 Service Provider library for Elixir and Phoenix. Versions 1.0.0 and 1.1.0 accept forged SAML signatures becaus…

Patch available
Fix from $2,300 2026-06-18
Unclassified MEDIUM 6.5
CVE-2026-42743

Unauthenticated Broken Authentication in Masteriyo - LMS <= 2.1.8 versions.

Mitigation only
Fix from $1,600 2026-06-15
Simplehelp CRITICAL 10.0
CVE-2026-48558 KEVEPSS 11%

SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication flow. Whe…

Fix: 5.5.16+
Fix from $2,300 2026-06-12
Netty HIGH 7.5
CVE-2026-50010

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, SimpleTru…

Fix: 4.1.135 / 4.2.15+
Fix from $1,950 2026-06-12
Cxf MEDIUM 6.5
CVE-2026-50634

A vulnerability in Apache CXF's JwsJsonContainerRequestFilter can be exploited to cause CXF to process metadata that was not authenticated by the acc…

Fix: 4.1.7 / 4.2.2+
Fix from $1,600 2026-06-12