Vulnerability index

Browse CVEs

732 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Signature VerificationCWE-347 × clear
Unclassified HIGH 8.1
CVE-2025-55278

Improper authentication in the API authentication middleware of HCL DevOps Loop allows authentication tokens to be accepted without proper validation…

Mitigation only
Fix from $1,950 2025-11-05
macOS MEDIUM 5.5
CVE-2025-43468

A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions. This issue is fixed in macOS Sequoia 1…

Fix: 14.8.2 / 15.7.2+
Fix from $1,600 2025-11-04
macOS MEDIUM 5.5
CVE-2025-43390

A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions. This issue is fixed in macOS Sequoia 1…

Fix: 15.7.2+
Fix from $1,600 2025-11-04
Unclassified MEDIUM 5.9
CVE-2025-54549

Cryptographic validation of upgrade images could be circumventing by dropping a specifically crafted file into the upgrade ISO

No fix yet
Fix from $1,600 2025-10-29
Unclassified HIGH 8.3
CVE-2025-58356

Constellation is the first Confidential Kubernetes. The Constellation CVM image uses LUKS2-encrypted volumes for persistent storage. When opening an …

Patch available
Fix from $1,950 2025-10-27
Dap 2695 Firmware HIGH 8.1
CVE-2025-12295

A weakness has been identified in D-Link DAP-2695 2.00RC13. The affected element is the function sub_40C6B8 of the component Firmware Update Handler.…

No fix yet
Fix from $1,950 2025-10-27
Unclassified HIGH 7.0
CVE-2025-34503

Deck Mate 1 executes firmware directly from an external EEPROM without verifying authenticity or integrity. An attacker with physical access can repl…

Mitigation only
Fix from $1,950 2025-10-24
Unclassified HIGH 7.0
CVE-2025-34500

Deck Mate 2's firmware update mechanism accepts packages without cryptographic signature verification, encrypts them with a single hard-coded AES key…

Mitigation only
Fix from $1,950 2025-10-24
Spark MEDIUM 6.5
CVE-2025-55039

This issue affects Apache Spark versions before 3.4.4, 3.5.2 and 4.0.0. Apache Spark versions before 4.0.0, 3.5.2 and 3.4.4 use an insecure defau…

Fix: 3.4.4 / 3.5.2+
Fix from $1,600 2025-10-15
Playwright MEDIUM 5.3
CVE-2025-59288

Improper verification of cryptographic signature in Github: Playwright allows an unauthorized attacker to perform spoofing over an adjacent network.

Fix: 1.55.1+
Fix from $1,600 2025-10-14
Forticlient HIGH 7.8
CVE-2025-46774

An Improper Verification of Cryptographic Signature vulnerability [CWE-347] in FortiClient MacOS installer version 7.4.2 and below, version 7.2.9 and…

Fix: 7.2.10 / 7.4.4+
Fix from $1,950 2025-10-14
Unclassified CRITICAL 9.8
CVE-2025-9485

The OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress is vulnerable to Improper Verification of Cryptographic Signature in versions up t…

Mitigation only
Fix from $2,300 2025-10-04
Unclassified CRITICAL 9.4
CVE-2025-59934EPSS 8%

Formbricks is an open source qualtrics alternative. Prior to version 4.0.1, Formbricks is missing JWT signature verification. This vulnerability stem…

Patch available
Fix from $2,300 2025-09-26
Unclassified CRITICAL 9.3
CVE-2024-13990

MicroWorld eScan AV's update mechanism failed to ensure authenticity and integrity of updates: update packages were delivered and accepted without ro…

Mitigation only
Fix from $2,300 2025-09-19
Unclassified HIGH 7.2
CVE-2025-7937

There is a vulnerability in the Supermicro BMC firmware validation logic at Supermicro MBD-X12STW . An attacker can update the system firmware with a…

Mitigation only
Fix from $1,950 2025-09-19
Unclassified HIGH 7.2
CVE-2025-6198

There is a vulnerability in the Supermicro BMC firmware validation logic at Supermicro MBD-X13SEM-F . An attacker can update the system firmware with…

Mitigation only
Fix from $1,950 2025-09-19
Linkr HIGH 8.8
CVE-2025-59334

Linkr is a lightweight file delivery system that downloads files from a webserver. Linkr versions through 2.0.0 do not verify the integrity or authen…

Fix: 2.0.1+
Fix from $1,950 2025-09-16
Unclassified MEDIUM 6.0
CVE-2025-20248

A vulnerability in the installation process of Cisco IOS XR Software could allow an authenticated, local attacker to bypass Cisco IOS XR Software ima…

Mitigation only
Fix from $1,600 2025-09-10
E3 Supervisory Controller Firmware HIGH 7.2
CVE-2025-52550

E3 Site Supervisor Control (firmware version < 2.31F01) firmware upgrade packages are unsigned. An attacker can forge malicious firmware upgrade pack…

Fix: 2.31f01+
Fix from $1,950 2025-09-02
Unclassified HIGH 8.8
CVE-2025-30064

An insufficiently secured internal function allows session generation for arbitrary users. The decodeParam function checks the JWT but does not verif…

Mitigation only
Fix from $1,950 2025-08-27
Gnark CRITICAL 9.1
CVE-2025-57801

gnark is a zero-knowledge proof system framework. In versions prior to 0.14.0, the Verify function in eddsa.go and ecdsa.go used the S value from a s…

Fix: 0.14.0+
Fix from $2,300 2025-08-22
Windows 10 1507 MEDIUM 5.3
CVE-2025-55229

Improper verification of cryptographic signature in Windows Certificates allows an unauthorized attacker to perform spoofing over a network.

Fix: 10.0.10240.21014 / 10.0.14393.8066+
Fix from $1,600 2025-08-21
Unclassified MEDIUM 6.8
CVE-2025-4371

A potential vulnerability was reported in the Lenovo 510 FHD and Performance FHD web cameras that could allow an attacker with physical access to wri…

Mitigation only
Fix from $1,600 2025-08-18
Unclassified HIGH 8.7
CVE-2025-40758

A vulnerability has been identified in Mendix SAML (Mendix 10.12 compatible) (All versions < V4.0.3), Mendix SAML (Mendix 10.21 compatible) (All vers…

Mitigation only
Fix from $1,950 2025-08-14
Unclassified CRITICAL 9.6
CVE-2025-54982

An improper verification of cryptographic signature in Zscaler's SAML authentication mechanism on the server-side allowed an authentication abuse.

Mitigation only
Fix from $2,300 2025-08-05
Devscripts CRITICAL 9.8
CVE-2025-8454

It was discovered that uscan, a tool to scan/watch upstream sources for new releases of software, included in devscripts (a collection of scripts to …

Mitigation only
Fix from $2,300 2025-08-01
macOS MEDIUM 5.5
CVE-2025-43185

A downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in macOS Sequoia 15.6. An app may be able to access pr…

Fix: 15.6+
Fix from $1,600 2025-07-30
Unclassified CRITICAL 10.0
CVE-2025-54419

A SAML library not dependent on any frameworks that runs in Node. In version 5.0.1, Node-SAML loads the assertion from the (unsigned) original respon…

Patch available
Fix from $2,300 2025-07-28
Linux Imaging And Printing CRITICAL 9.1
CVE-2025-43023

A potential security vulnerability has been identified in the HP Linux Imaging and Printing Software documentation. This potential vulnerability is d…

Fix: 3.25.2+
Fix from $2,300 2025-07-28
Unclassified CRITICAL 9.3
CVE-2025-54369

Node-SAML is a SAML library not dependent on any frameworks that runs in Node. In versions 5.0.1 and below, Node-SAML loads the assertion from the (u…

Patch available
Fix from $2,300 2025-07-24