Vulnerability index

Browse CVEs

732 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Signature VerificationCWE-347 × clear
Jsrsasign CRITICAL 9.1
CVE-2026-4600

Versions of the package jsrsasign before 11.1.1 are vulnerable to Improper Verification of Cryptographic Signature via the DSA domain-parameter valid…

Fix: 11.1.1+
Fix from $2,300 2026-03-23
Unclassified HIGH 8.1
CVE-2026-4478

A vulnerability was identified in Yi Technology YI Home Camera 2 2.1.1_20171024151200. This impacts an unknown function of the file home/web/ipc of t…

Mitigation only
Fix from $1,950 2026-03-20
Unclassified CRITICAL 9.0
CVE-2026-3564

A condition in the ScreenConnect server component may allow an actor with access to server-level cryptographic material used for authentication to ob…

Mitigation only
Fix from $2,300 2026-03-17
Stanford Javascript Crypto Library HIGH 7.5
CVE-2026-4258

Versions of the package sjcl before 1.0.9 are vulnerable to Improper Verification of Cryptographic Signature due to missing point-on-curve validation…

Fix: after 1.0.8
Fix from $1,950 2026-03-17
Authlib CRITICAL 9.1
CVE-2026-27962

Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a JWK Header Injection vulnerability in authlib's …

Fix: 1.6.9+
Fix from $2,300 2026-03-16
Hue Bridge V2 Firmware HIGH 8.8
CVE-2026-3562

Philips Hue Bridge hk_hap Ed25519 Signature Verification Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to…

Fix: 1975170000+
Fix from $1,950 2026-03-16
Unclassified HIGH 7.5
CVE-2026-32614

Go ShangMi (Commercial Cryptography) Library (GMSM) is a cryptographic library that covers the Chinese commercial cryptographic public algorithms SM2…

No fix yet
Fix from $1,950 2026-03-16
Galaxy Store MEDIUM 5.5
CVE-2026-21002

Improper verification of cryptographic signature in Galaxy Store prior to version 4.6.03.8 allows local attacker to install arbitrary application.

Fix: 4.6.03.8+
Fix from $1,600 2026-03-16
Smart Switch CRITICAL 9.8
CVE-2026-20997

Improper verification of cryptographic signature in Smart Switch prior to version 3.7.69.15 allows remote attackers to potentially bypass authenticat…

Fix: 3.7.69.15+
Fix from $2,300 2026-03-16
Aion CRITICAL 9.8
CVE-2025-52648

HCL AION is affected by a vulnerability where offering images are not digitally signed. Lack of image signing may allow the use of unverified or tamp…

Fix: 2.1.2+
Fix from $2,300 2026-03-16
Pyjwt HIGH 7.5
CVE-2026-32597

PyJWT is a JSON Web Token implementation in Python. Prior to 2.12.0, PyJWT does not validate the crit (Critical) Header Parameter defined in RFC 7515…

Fix: 2.12.0+
Fix from $1,950 2026-03-13
Misskey HIGH 7.5
CVE-2026-28432

Misskey is an open source, federated social media platform. All Misskey servers prior to 2026.3.1 contain a vulnerability that allows bypassing HTTP …

Fix: 2026.3.1+
Fix from $1,950 2026-03-10
Universal Bacnet Router Firmware HIGH 7.2
CVE-2025-41767

A high-privileged remote attacker can fully compromise the device by abusing an update signature bypass vulnerability in the wwwupdate.cgi method in …

Fix: 6.0.1.0+
Fix from $1,950 2026-03-09
Authlib CRITICAL 9.8
CVE-2026-28802

Authlib is a Python library which builds OAuth and OpenID Connect servers. From version 1.6.5 to before version 1.6.7, previous tests involving passi…

Fix: 1.6.7+
Fix from $2,300 2026-03-06
Unclassified CRITICAL 9.1
CVE-2026-29000EPSS 6%

pac4j-jwt versions prior to 4.5.9, 5.7.9, and 6.3.3 contain an authentication bypass vulnerability in JwtAuthenticator when processing encrypted JWTs…

Mitigation only
Fix from $2,300 2026-03-04
Seppmail MEDIUM 5.3
CVE-2026-2746

SEPPmail Secure Email Gateway before version 15.0.1 does not properly communicate PGP signature verification results, leaving users unable to detect …

Fix: 15.0.1+
Fix from $1,600 2026-03-04
Seppmail MEDIUM 5.3
CVE-2026-27445

SEPPmail Secure Email Gateway before version 15.0.1 does not properly verify that a PGP signature was generated by the expected key, allowing signatu…

Fix: 15.0.1+
Fix from $1,600 2026-03-04
Sqlbot MEDIUM 5.9
CVE-2025-15598

A vulnerability was found in Dataease SQLBot up to 1.5.1. This impacts the function validateEmbedded of the file backend/apps/system/middleware/auth.…

Fix: after 1.5.1
Fix from $1,600 2026-03-03
Aws Lc Sys HIGH 7.5
CVE-2026-3338

Improper signature validation in PKCS7_verify() in AWS-LC allows an unauthenticated user to bypass signature verification when processing PKCS7 objec…

Fix: 0.38.0 / 1.69.0+
Fix from $1,950 2026-03-02
Ethereum Name Service HIGH 7.5
CVE-2026-22866

Ethereum Name Service (ENS) is a distributed, open, and extensible naming system based on the Ethereum blockchain. In versions 1.6.2 and prior, the `…

Fix: after 1.6.2
Fix from $1,950 2026-02-25
Unclassified MEDIUM 6.7
CVE-2025-32060

The system suffers from the absence of a kernel module signature verification. If an attacker can execute commands on behalf of root user (due to add…

Mitigation only
Fix from $1,600 2026-02-15
Authentik HIGH 8.8
CVE-2026-25922

authentik is an open-source identity provider. Prior to 2025.8.6, 2025.10.4, and 2025.12.4, when using a SAML Source that has the option Verify Asser…

Fix: 2025.8.6 / 2025.10.4+
Fix from $1,950 2026-02-12
Sap Basis HIGH 8.8
CVE-2026-23687

SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated attacker with normal privileges to obtain a valid signed message and …

Mitigation only
Fix from $1,950 2026-02-10
Unclassified HIGH 8.1
CVE-2026-1529

A flaw was found in Keycloak. An attacker can exploit this vulnerability by modifying the organization ID and target email within a legitimate invita…

Mitigation only
Fix from $1,950 2026-02-09
Nebula HIGH 8.1
CVE-2026-25793

Nebula is a scalable overlay networking tool. In versions from 1.7.0 to 1.10.2, when using P256 certificates (which is not the default configuration)…

Fix: 1.10.3+
Fix from $1,950 2026-02-06
Unclassified CRITICAL 9.6
CVE-2026-1568

Rapid7 InsightVM versions before 8.34.0 contain a signature verification issue on the Assertion Consumer Service (ACS) cloud endpoint that could allo…

Mitigation only
Fix from $2,300 2026-02-03
Commerce Paybox HIGH 7.5
CVE-2026-0750

Improper Verification of Cryptographic Signature vulnerability in Drupal Drupal Commerce Paybox Commerce Paybox on Drupal 7.X allows Authentication B…

Fix: after 7.x-1.5
Fix from $1,950 2026-01-28
Unclassified MEDIUM 5.3
CVE-2026-24850

The ML-DSA crate is a Rust implementation of the Module-Lattice-Based Digital Signature Standard (ML-DSA). Starting in version 0.0.4 and prior to ver…

Patch available
Fix from $1,600 2026-01-28
OpenSSL MEDIUM 5.5
CVE-2025-15469

Issue summary: The 'openssl dgst' command-line tool silently truncates input data to 16MB when using one-shot signing algorithms and reports success …

Fix: 3.5.5 / 3.6.1+
Fix from $1,600 2026-01-27
Unclassified MEDIUM 5.3
CVE-2026-24807

Improper Verification of Cryptographic Signature vulnerability in liuyueyi quick-media (plugins/svg-plugin/batik-codec-fix/src/main/java/org/apache/b…

Patch available
Fix from $1,600 2026-01-27