Vulnerability index

Browse CVEs

732 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Signature VerificationCWE-347 × clear
Tough MEDIUM 6.5
CVE-2026-6966

Improper verification of cryptographic signature uniqueness in delegated role validation in awslabs/tough before tough-v0.22.0 allows remote authenti…

Fix: 0.15.0 / 0.22.0+
Fix from $1,600 2026-04-24
Unclassified CRITICAL 9.8
CVE-2026-6911

Missing JWT signature verification in AWS Ops Wheel allows unauthenticated attackers to forge JWT tokens and gain unintended administrative access to…

Patch available
Fix from $2,300 2026-04-24
Nimiq Proof Of Stake MEDIUM 6.8
CVE-2026-34068

nimiq-transaction provides the transaction primitive to be used in Nimiq's Rust implementation. Prior to version 1.3.0, the staking contract accepts …

Fix: 1.3.0+
Fix from $1,600 2026-04-22
Asp.net Core CRITICAL 9.1
CVE-2026-40372EPSS 11%

Improper verification of cryptographic signature in ASP.NET Core allows an unauthorized attacker to elevate privileges over a network.

Fix: 10.0.7+
Fix from $2,300 2026-04-21
Openclaw MEDIUM 5.3
CVE-2026-41301

OpenClaw versions 2026.3.22 before 2026.3.31 contain a signature verification bypass vulnerability in the Nostr DM ingress path that allows pairing c…

Fix: 2026.3.31+
Fix from $1,600 2026-04-21
Unclassified HIGH 7.5
CVE-2026-5050

The Payment Gateway for Redsys & WooCommerce Lite plugin for WordPress is vulnerable to Improper Verification of Cryptographic Signature in versions …

Mitigation only
Fix from $1,950 2026-04-16
Unclassified HIGH 7.5
CVE-2026-5588

Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcpkix on all (pkix modules), Legion of th…

Patch available
Fix from $1,950 2026-04-15
Unclassified HIGH 8.3
CVE-2026-6328

Improper input validation, Improper verification of cryptographic signature vulnerability in XQUIC Project XQUIC xquic on Linux (QUIC protocol implem…

Patch available
Fix from $1,950 2026-04-15
Unclassified HIGH 7.3
CVE-2026-24032

A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP3 with UMC). The affected application contains an authentication weakness due…

Mitigation only
Fix from $1,950 2026-04-14
Cortex Xsiam CRITICAL 9.1
CVE-2026-0234

An improper verification of cryptographic signature vulnerability exists in Cortex XSOAR and Cortex XSIAM platforms during integration of Microsoft T…

Fix: 1.5.52+
Fix from $2,300 2026-04-13
Wolfssl HIGH 8.1
CVE-2026-5466

wolfSSL's ECCSI signature verifier `wc_VerifyEccsiHash` decodes the `r` and `s` scalars from the signature blob via `mp_read_unsigned_bin` with no ch…

Fix: 5.9.1+
Fix from $1,950 2026-04-10
Bsv Wallet HIGH 8.1
CVE-2026-40070

BSV Ruby SDK is the Ruby SDK for the BSV blockchain. From 0.3.1 to before 0.8.2, BSV::Wallet::WalletClient#acquire_certificate persists certificate r…

Fix: 0.3.4 / 0.8.2+
Fix from $1,950 2026-04-09
Helm HIGH 7.8
CVE-2026-35205

Helm is a package manager for Charts for Kubernetes. From 4.0.0 to 4.1.3, Helm will install plugins missing provenance (.prov file) when signature ve…

Fix: 4.1.4+
Fix from $1,950 2026-04-09
Lightrag MEDIUM 6.5
CVE-2026-39413

LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.4.14, the LightRAG API is vulnerable to a JWT algorithm confusion attack…

Fix: 1.4.14+
Fix from $1,600 2026-04-08
Erlang\/otp HIGH 7.4
CVE-2026-32144

Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_ocsp module) allows OCSP designated-responder authorization bypass via…

Fix: 1.17.1.2 / 1.20.3+
Fix from $1,950 2026-04-07
Hardened Images MEDIUM 5.5
CVE-2026-2625

A flaw was found in rust-rpm-sequoia. An attacker can exploit this vulnerability by providing a specially crafted Red Hat Package Manager (RPM) file.…

Mitigation only
Fix from $1,600 2026-04-03
Oneuptime HIGH 8.1
CVE-2026-34840

OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, OneUptime's SAML SSO implementation (App/FeatureSet/Iden…

Fix: 10.0.42+
Fix from $1,950 2026-04-02
Convoy CRITICAL 9.8
CVE-2026-33746

Convoy is a KVM server management panel for hosting businesses. From version 3.9.0-beta to before version 4.5.1, the JWTService::decode() method did …

Fix: 4.5.1+
Fix from $2,300 2026-04-02
Mbed Tls CRITICAL 9.1
CVE-2026-34872

An issue was discovered in Mbed TLS 3.5.x and 3.6.x through 3.6.5 and TF-PSA-Crypto 1.0. There is a lack of contributory behavior in FFDH due to impr…

Fix: 3.6.6+
Fix from $2,300 2026-04-01
Jose HIGH 7.5
CVE-2026-34240

JOSE is a Javascript Object Signing and Encryption (JOSE) library. Prior to version 0.3.5+1, a vulnerability in jose could allow an unauthenticated, …

Fix: 0.3.5+
Fix from $1,950 2026-03-31
Zebra HIGH 8.1
CVE-2026-34377

ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.0 and zebra-consensus version 5.0.1, a logic error in Zebra's transaction…

Fix: 4.3.0 / 5.0.1+
Fix from $1,950 2026-03-31
Rauc MEDIUM 5.3
CVE-2026-34155

RAUC controls the update process on embedded Linux systems. Prior to version 1.15.2, RAUC bundles using the 'plain' format exceeding a payload size o…

Fix: 1.15.2+
Fix from $1,600 2026-03-31
Openolat CRITICAL 9.8
CVE-2026-31946

OpenOlat is an open source web-based e-learning platform for teaching, learning, assessment and communication. From version 10.5.4 to before version …

Fix: 20.2.5+
Fix from $2,300 2026-03-30
Botan MEDIUM 5.9
CVE-2026-32883

Botan is a C++ cryptography library. From version 3.0.0 to before version 3.11.0, during X509 path validation, OCSP responses were checked for an app…

Fix: 3.11.0+
Fix from $1,600 2026-03-30
Nginx Ui CRITICAL 9.1
CVE-2026-33026

Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, the nginx-ui backup restore mechanism allows attackers to tamper w…

Fix: 2.3.4+
Fix from $2,300 2026-03-30
Openclaw CRITICAL 9.8
CVE-2026-32974

OpenClaw before 2026.3.12 contains an authentication bypass vulnerability in Feishu webhook mode when only verificationToken is configured without en…

Fix: 2026.3.12+
Fix from $2,300 2026-03-29
Forge HIGH 7.5
CVE-2026-33895

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, Ed25519 signature veri…

Fix: after 1.3.3
Fix from $1,950 2026-03-27
Forge HIGH 7.5
CVE-2026-33894

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, RSASSA PKCS#1 v1.5 sig…

Fix: 1.4.0+
Fix from $1,950 2026-03-27
Goxmldsig HIGH 7.5
CVE-2026-33487

goxmlsig provides XML Digital Signatures implemented in Go. Prior to version 1.6.0, the `validateSignature` function in `validate.go` goes through th…

Fix: 1.6.0+
Fix from $1,950 2026-03-26
macOS MEDIUM 6.2
CVE-2026-20699

A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions. This issue is fixed in macOS Sequoia 1…

Fix: 14.8.5 / 15.7.5+
Fix from $1,600 2026-03-25