Vulnerability index

Browse CVEs

732 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Signature VerificationCWE-347 × clear
Unclassified CRITICAL 9.0
CVE-2026-41005

Cloud Foundry UAA incorrectly treated XML encryption to the Service Provider (confidentiality) as a substitute for XML signatures from the Identity P…

Mitigation only
Fix from $2,300 2026-06-11
Unclassified HIGH 8.1
CVE-2026-10795

The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.26.…

Mitigation only
Fix from $1,950 2026-06-11
Unclassified HIGH 7.0
CVE-2026-42462

Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Prior to versions 1.9.11, 1.10.10, 2.0.18, 2.1.14, and 2.2.…

Mitigation only
Fix from $1,950 2026-06-10
Ghidra HIGH 8.8
CVE-2026-52754

Ghidra before 12.1 contains an authentication bypass vulnerability in PKIAuthenticationModule.authenticate() that allows any user with a valid CA-sig…

Fix: 12.1+
Fix from $1,950 2026-06-10
Spring Security MEDIUM 5.3
CVE-2026-41694

Since Spring Security SAML decrypts SAML Responses as well as elements of SAML LogoutRequests and LogoutResponses without requiring a valid signature…

Fix: 5.7.24 / 5.8.26+
Fix from $1,600 2026-06-10
Unclassified CRITICAL 9.8
CVE-2026-36721

A lack of cryptographic signature verification in the validateAccessToken function of bookcars v8.3 allows attackers to bypass authentication via a f…

Mitigation only
Fix from $2,300 2026-06-09
Unclassified CRITICAL 9.9
CVE-2026-44748

SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated attacker with normal privileges to obtain a valid signed message and …

Mitigation only
Fix from $2,300 2026-06-09
Authentik HIGH 8.5
CVE-2026-47201

authentik is an open-source identity provider. Prior to versions 2025.12.5, 2026.2.3, and 2026.5.1, authentik's SAML Source ACS endpoint is vulnerabl…

Fix: 2025.12.6 / 2026.2.4+
Fix from $1,950 2026-06-02
Pyjwt MEDIUM 5.4
CVE-2026-48523

PyJWT is a JSON Web Token implementation in Python. From 2.9.0 to 2.12.1, there is a verifier-side algorithm allow-list bypass when jwt.decode() or j…

Fix: 2.12.1+
Fix from $1,600 2026-05-28
Pyjwt HIGH 7.4
CVE-2026-48526

PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, when the verifier is decoding JSON Web Tokens, while supporting both asymmetric …

Fix: 2.13.0+
Fix from $1,950 2026-05-28
Build Of Keycloak HIGH 7.5
CVE-2026-9793

A flaw was found in Keycloak. When a JSON Web Encryption (JWE) encrypted request object is submitted, Keycloak may incorrectly process unsigned claim…

Mitigation only
Fix from $1,950 2026-05-28
Unclassified MEDIUM 6.9
CVE-2026-44720

OpenLearnX is an open-source, decentralized learning and assessment platform. Prior to 2.0.4, a critical authentication vulnerability was identified …

Mitigation only
Fix from $1,600 2026-05-27
Unclassified MEDIUM 5.3
CVE-2025-67903

Northern.tech Mender Client 5 before 5.0.4 allows a Cryptographic signature verification bypass.

Mitigation only
Fix from $1,600 2026-05-27
Unclassified HIGH 8.8
CVE-2025-41669

The Web-based Management allows a remote low privileged Engineer user to install additional APPs on the device downloaded from the PLCnext Store with…

Mitigation only
Fix from $1,950 2026-05-27
Unclassified HIGH 7.4
CVE-2026-45575

epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. Prior to 1.2.2, an attacker who can MITM the TLS connection b…

Patch available
Fix from $1,950 2026-05-26
Crypto HIGH 7.5
CVE-2026-39829

The RSA and DSA public key parsers did not enforce size limits on key parameters. A crafted public key with an excessively large modulus or DSA param…

Fix: 0.52.0+
Fix from $1,950 2026-05-22
Unclassified MEDIUM 5.3
CVE-2026-44309

Gitsign is a keyless Sigstore to signing tool for Git commits with your a GitHub / OIDC identity. Prior to 0.16.0, gitsign verify and gitsign verify-…

Mitigation only
Fix from $1,600 2026-05-15
Unclassified CRITICAL 9.1
CVE-2026-44699

LibJWT is a C JSON Web Token Library. From 3.0.0 to 3.3.2, libjwt accepts an RSA JWK that does not contain an alg parameter as the verification key f…

Mitigation only
Fix from $2,300 2026-05-15
Unclassified HIGH 7.5
CVE-2026-44714

The bitcoinj library is a Java implementation of the Bitcoin protocol. Prior to 0.17.1, ScriptExecution.correctlySpends() contains two fast-path veri…

Patch available
Fix from $1,950 2026-05-15
Unclassified HIGH 7.0
CVE-2024-36334

Improper verification of cryptographic signature in the Radeon RGB tool could allow a malicious file placed in the installation directory to be run w…

Mitigation only
Fix from $1,950 2026-05-15
Opentelemetry Collector Contrib HIGH 8.1
CVE-2026-42602

azureauthextension is the Azure Authenticator Extension. From 0.124.0 to 0.150.0, a server-side authentication bypass in azureauthextension allows an…

Fix: after 0.150.0
Fix from $1,950 2026-05-13
Pan Os HIGH 8.1
CVE-2026-0265

An authentication bypass vulnerability in Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to bypass authe…

Fix: 10.2.7 / 10.2.10+
Fix from $1,950 2026-05-13
Azure Sdk For Java CRITICAL 9.1
CVE-2026-33117

The Java Key Vault Keys library in the Azure SDK for Java contains an issue in the local cryptographic verification path where authentication tag com…

Fix: 4.10.6+
Fix from $2,300 2026-05-12
Unclassified HIGH 8.0
CVE-2026-41431

Zen is a firefox-based browser. Prior to 1.19.9b, Zen Browser ships a Mozilla Application Resource (MAR) updater (org.mozilla.updater) that has had a…

Patch available
Fix from $1,950 2026-05-11
Unclassified CRITICAL 9.1
CVE-2026-42193

Plunk is an open-source email platform built on top of AWS SES. Prior to version 0.9.0, the /webhooks/sns endpoint accepts Amazon SNS notification pa…

Mitigation only
Fix from $2,300 2026-05-08
Zebra Script CRITICAL 9.1
CVE-2026-44497

ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.4.0 and prior to zebra-script version 6.0.0, the fix for CVE-2026-41583 int…

Fix: 4.4.0 / 6.0.0+
Fix from $2,300 2026-05-08
Go HIGH 7.5
CVE-2026-42501

A malicious module proxy can exploit a flaw in the go command's validation of module checksums to bypass checksum database validation. This vulnerabi…

Fix: 1.25.10 / 1.26.3+
Fix from $1,950 2026-05-07
Unclassified HIGH 8.2
CVE-2026-41669

Admidio is an open-source user management solution. Prior to version 5.0.9, the Admidio SAML Identity Provider implementation discards the return val…

Mitigation only
Fix from $1,950 2026-05-07
Elastic Package Registry MEDIUM 5.9
CVE-2026-33467

Improper Verification of Cryptographic Signature (CWE-347) in Elastic Package Registry could allow an attacker positioned to intercept network traffi…

Fix: 1.38.0+
Fix from $1,600 2026-04-28
Netmaker HIGH 8.2
CVE-2026-38651

Authentication Bypass vulnerability exists in Netmaker versions prior to 1.5.0. The VerifyHostToken function in logic/jwts.go fails to validate the J…

Fix: 1.5.0+
Fix from $1,950 2026-04-28