Vulnerability index

Browse CVEs

732 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Signature VerificationCWE-347 × clear
Unclassified CRITICAL 9.3
CVE-2026-22696

dcap-qvl implements the quote verification logic for DCAP (Data Center Attestation Primitives). A vulnerability present in versions prior to 0.3.9 in…

Mitigation only
Fix from $2,300 2026-01-26
Sm Crypto HIGH 7.5
CVE-2026-23967

sm-crypto provides JavaScript implementations of the Chinese cryptographic algorithms SM2, SM3, and SM4. A signature malleability vulnerability exist…

Fix: 0.3.14+
Fix from $1,950 2026-01-22
Go Tuf HIGH 7.5
CVE-2026-23992

go-tuf is a Go implementation of The Update Framework (TUF). Starting in version 2.0.0 and prior to version 2.3.1, a compromised or misconfigured TUF…

Fix: 2.3.1+
Fix from $1,950 2026-01-22
Sm Crypto HIGH 7.5
CVE-2026-23965

sm-crypto provides JavaScript implementations of the Chinese cryptographic algorithms SM2, SM3, and SM4. A signature forgery vulnerability exists in …

Fix: 0.4.0+
Fix from $1,950 2026-01-22
Fleet CRITICAL 9.8
CVE-2026-23518

Fleet is open source device management software. In versions prior to 4.78.3, 4.77.1, 4.76.2, 4.75.2, and 4.53.3, a vulnerability in Fleet's Windows …

Fix: 4.53.3 / 4.75.2+
Fix from $2,300 2026-01-21
Applinx CRITICAL 9.8
CVE-2025-36418

IBM ApplinX 11.1 is vulnerable due to a privilege escalation vulnerability due to improper verification of JWT tokens. An attacker may be able to cra…

Mitigation only
Fix from $2,300 2026-01-20
Unclassified HIGH 8.4
CVE-2025-12007

There is a vulnerability in the Supermicro BMC firmware validation logic at Supermicro MBD-X13SEM-F . An attacker can update the system firmware with…

Mitigation only
Fix from $1,950 2026-01-16
Unclassified HIGH 7.2
CVE-2025-12006

There is a vulnerability in the Supermicro BMC firmware validation logic at Supermicro MBD-X12STW-F . An attacker can update the system firmware with…

Mitigation only
Fix from $1,950 2026-01-16
Hono MEDIUM 6.5
CVE-2026-22817

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.11.4, there is a flaw in Hono’s JWK/JWKS JWT verific…

Fix: 4.11.4+
Fix from $1,600 2026-01-13
Hono MEDIUM 6.5
CVE-2026-22818

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.11.4, there is a flaw in Hono’s JWK/JWKS JWT verific…

Fix: 4.11.4+
Fix from $1,600 2026-01-13
Jervis MEDIUM 5.3
CVE-2025-68925

Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, the code doesn't validate that the JWT header spe…

Fix: 2.2+
Fix from $1,600 2026-01-13
Windows Admin Center HIGH 7.5
CVE-2026-20965

Improper verification of cryptographic signature in Windows Admin Center allows an authorized attacker to elevate privileges locally.

Fix: 0.70.0.0+
Fix from $1,950 2026-01-13
Crypt\ CRITICAL 9.8
CVE-2025-15444

Crypt::Sodium::XS module versions prior to 0.000042, for Perl, include a vulnerable version of libsodium libsodium <= 1.0.20 or a version of libsodi…

Fix: 0.000042+
Fix from $2,300 2026-01-06
Unclassified CRITICAL 9.8
CVE-2023-53951

Ever Gauzy v0.281.9 contains a JWT authentication vulnerability that allows attackers to exploit weak HMAC secret key implementation. Attackers can l…

Mitigation only
Fix from $2,300 2025-12-19
Unclassified MEDIUM 6.5
CVE-2025-68113

ALTCHA is privacy-first software for captcha and bot protection. A cryptographic semantic binding flaw in ALTCHA libraries allows challenge payload s…

Patch available
Fix from $1,600 2025-12-16
macOS MEDIUM 5.5
CVE-2025-43521

A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions. This issue is fixed in macOS Sequoia 1…

Fix: 15.7.3+
Fix from $1,600 2025-12-12
Pdf Editor MEDIUM 5.3
CVE-2025-59803

Foxit PDF Editor and Reader before 2025.2.1 allow signature spoofing via triggers. An attacker can embed triggers (e.g., JavaScript) in a PDF documen…

Fix: after 2025.2.0.68868
Fix from $1,600 2025-12-11
Pdf Editor MEDIUM 6.5
CVE-2025-55311

An issue was discovered in Foxit PDF and Editor for Windows and macOS before 13.2 and 2025 before 2025.2. A crafted PDF can use JavaScript to alter a…

Fix: after 2025.1.0.66692
Fix from $1,600 2025-12-11
Hub M2 Firmware HIGH 8.1
CVE-2025-65295

Multiple vulnerabilities in Aqara Hub firmware update process in the Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 devices, allo…

No fix yet
Fix from $1,950 2025-12-10
Fortiweb CRITICAL 9.8
CVE-2025-59719EPSS 25%

An improper verification of cryptographic signature vulnerability in Fortinet FortiWeb 8.0.0, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.…

Fix: after 7.6.4
Fix from $2,300 2025-12-09
Fortiproxy CRITICAL 9.8
CVE-2025-59718 KEVEPSS 63%

A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 …

Fix: 7.0.6 / 7.0.18+
Fix from $2,300 2025-12-09
Ruby Saml CRITICAL 9.1
CVE-2025-66567

The ruby-saml library is for implementing the client side of a SAML authorization. ruby-saml versions up to and including 1.12.4 contain an authentic…

Fix: 1.18.0+
Fix from $2,300 2025-12-09
Ruby Saml CRITICAL 9.1
CVE-2025-66568

The ruby-saml library implements the client side of an SAML authorization. Versions up to and including 1.12.4, are vulnerable to authentication bypa…

Fix: 1.18.0+
Fix from $2,300 2025-12-09
Endpoint Manager HIGH 7.8
CVE-2025-13662

Improper verification of cryptographic signatures in the patch management component of Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a…

Fix: 2024+
Fix from $1,950 2025-12-09
Node Jws HIGH 7.5
CVE-2025-65945

auth0/node-jws is a JSON Web Signature implementation for Node.js. In versions 3.2.2 and earlier and version 4.0.0, auth0/node-jws has an improper si…

Fix: 3.2.3+
Fix from $1,950 2025-12-04
\ CRITICAL 9.3
CVE-2025-40934

XML-Sig versions 0.27 through 0.67 for Perl incorrectly validates XML files if signatures are omitted. An attacker can remove the signature from the…

Fix: after 0.67
Fix from $2,300 2025-11-26
Gosign HIGH 7.8
CVE-2025-34324

GoSign Desktop versions 2.4.0 and earlier use an unsigned update manifest for distributing application updates. The manifest contains package URLs an…

Fix: 2.4.1+
Fix from $1,950 2025-11-18
Workplace Virtual Desktop Infrastructure HIGH 7.8
CVE-2025-64740

Improper verification of cryptographic signature in the installer for Zoom Workplace VDI Client for Windows may allow an authenticated user to conduc…

Fix: 6.3.14 / 6.4.12+
Fix from $1,950 2025-11-13
Evervault MEDIUM 6.5
CVE-2025-64186

Evervault is a payment security solution. A vulnerability was identified in the `evervault-go` SDK’s attestation verification logic in versions of `e…

Fix: 1.3.2+
Fix from $1,600 2025-11-12
Resharper HIGH 7.8
CVE-2025-64456

In JetBrains ReSharper before 2025.2.4 missing signature verification in DPA Collector allows local privilege escalation

Fix: 2025.2.4+
Fix from $1,950 2025-11-10