Vulnerability index

Browse CVEs

732 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Signature VerificationCWE-347 × clear
Tia Administrator HIGH 8.4
CVE-2025-23364

A vulnerability has been identified in TIA Administrator (All versions < V3.0.6). The affected application improperly validates code signing certific…

Fix: 3.0.6+
Fix from $1,950 2025-07-08
Wear Os MEDIUM 5.5
CVE-2025-21004

Improper verification of intent by broadcast receiver in System UI for Galaxy Watch prior to SMR Jul-2025 Release 1 allows local attackers to power o…

Mitigation only
Fix from $1,600 2025-07-08
Unclassified HIGH 8.1
CVE-2024-49365

tiny-secp256k1 is a tiny secp256k1 native/JS wrapper. Prior to version 1.1.7, a malicious JSON-stringifyable message can be made passing on verify(),…

Patch available
Fix from $1,950 2025-07-01
Unclassified MEDIUM 6.4
CVE-2024-36347

Improper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator privilege to load malicious micr…

Mitigation only
Fix from $1,600 2025-06-27
Unclassified CRITICAL 9.6
CVE-2025-32977

Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 (Patch 5)…

Mitigation only
Fix from $2,300 2025-06-24
Unclassified CRITICAL 9.3
CVE-2025-52556

rfc3161-client is a Python library implementing the Time-Stamp Protocol (TSP) described in RFC 3161. Prior to version 1.0.3, there is a flaw in the t…

Patch available
Fix from $2,300 2025-06-21
Windows 11 24h2 MEDIUM 5.1
CVE-2025-33069

Improper verification of cryptographic signature in App Control for Business (WDAC) allows an unauthorized attacker to bypass a security feature loca…

Fix: 10.0.26100.4270+
Fix from $1,600 2025-06-10
Deno MEDIUM 5.3
CVE-2025-24015

Deno is a JavaScript, TypeScript, and WebAssembly runtime. Versions 1.46.0 through 2.1.6 have an issue that affects AES-256-GCM and AES-128-GCM in De…

Fix: 2.1.7+
Fix from $1,600 2025-06-03
Sipass Integrated Ac5102 \(acc G2\) Firmware MEDIUM 5.5
CVE-2022-31807

A vulnerability has been identified in Building X - Security Manager Edge Controller (ACC-AP) (All versions). Affected devices do not properly check …

Mitigation only
Fix from $1,600 2025-05-23
Samlify HIGH 7.5
CVE-2025-47949

samlify is a Node.js library for SAML single sign-on. A Signature Wrapping attack has been found in samlify prior to version 2.10.0, allowing an atta…

Fix: 2.10.0+
Fix from $1,950 2025-05-19
Unclassified HIGH 8.7
CVE-2025-47934

OpenPGP.js is a JavaScript implementation of the OpenPGP protocol. Startinf in version 5.0.1 and prior to versions 5.11.3 and 6.1.1, a maliciously mo…

Patch available
Fix from $1,950 2025-05-19
Openpubkey CRITICAL 9.8
CVE-2025-3757

Versions of OpenPubkey library prior to 0.10.0 contained a vulnerability that would allow a specially crafted JWS to bypass signature verification.

Fix: 0.10.0+
Fix from $2,300 2025-05-13
Openpubkey CRITICAL 9.8
CVE-2025-4658

Versions of OpenPubkey library prior to 0.10.0 contained a vulnerability that would allow a specially crafted JWS to bypass signature verification. …

Fix: 0.5.0 / 0.10.0+
Fix from $2,300 2025-05-13
iOS MEDIUM 6.8
CVE-2025-20181

A vulnerability in Cisco IOS Software for Cisco Catalyst 2960X, 2960XR, 2960CX, and 3560CX Series Switches could allow an authenticated, local attack…

Mitigation only
Fix from $1,600 2025-05-07
Azure Functions HIGH 8.8
CVE-2025-33074

Improper verification of cryptographic signature in Microsoft Azure Functions allows an authorized attacker to execute code over a network.

Mitigation only
Fix from $1,950 2025-04-30
Libreoffice MEDIUM 5.5
CVE-2025-2866

Improper Verification of Cryptographic Signature vulnerability in LibreOffice allows PDF Signature Spoofing by Improper Validation. In the affect…

Fix: 24.8.6.0 / 25.2.2+
Fix from $1,600 2025-04-27
Autokit MEDIUM 6.8
CVE-2025-2763

CarlinKit CPC200-CCPA Improper Verification of Cryptographic Signature Code Execution Vulnerability. This vulnerability allows physically present att…

Mitigation only
Fix from $1,600 2025-04-23
Autokit HIGH 8.0
CVE-2025-2764

CarlinKit CPC200-CCPA update.cgi Improper Verification of Cryptographic Signature Code Execution Vulnerability. This vulnerability allows network-adj…

Mitigation only
Fix from $1,950 2025-04-23
Secure Network Analytics HIGH 7.2
CVE-2025-20178

A vulnerability in the web-based management interface of Cisco Secure Network Analytics could allow an authenticated, remote attacker with valid admi…

Mitigation only
Fix from $1,950 2025-04-16
Suricata HIGH 7.5
CVE-2025-29915

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. The AF_PACKET defrag option is …

Fix: 7.0.9+
Fix from $1,950 2025-04-10
Unclassified HIGH 8.1
CVE-2025-27813

MSI Center before 2.0.52.0 has Missing PE Signature Validation.

Mitigation only
Fix from $1,950 2025-04-10
Unclassified HIGH 8.7
CVE-2025-31489

MinIO is a High Performance Object Storage released under GNU Affero General Public License v3.0. The signature component of the authorization may be…

Patch available
Fix from $1,950 2025-04-03
Unclassified CRITICAL 9.3
CVE-2025-29775EPSS 9%

xml-crypto is an XML digital signature and encryption library for Node.js. An attacker may be able to exploit a vulnerability in versions prior to 6.…

Patch available
Fix from $2,300 2025-03-14
Unclassified CRITICAL 9.3
CVE-2025-29774EPSS 9%

xml-crypto is an XML digital signature and encryption library for Node.js. An attacker may be able to exploit a vulnerability in versions prior to 6.…

Patch available
Fix from $2,300 2025-03-14
Omniauth Saml CRITICAL 9.8
CVE-2025-25291EPSS 20%

ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. An authentication bypass vulnerability was found in ruby-…

Fix: 1.10.6 / 1.12.4+
Fix from $2,300 2025-03-12
Omniauth Saml CRITICAL 9.8
CVE-2025-25292EPSS 65%

ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. An authentication bypass vulnerability was found in ruby-…

Fix: 1.10.6 / 1.12.4+
Fix from $2,300 2025-03-12
Ios Xr MEDIUM 6.7
CVE-2025-20143

A vulnerability in the boot process of Cisco IOS XR Software could allow an authenticated, local attacker with high privileges to bypass the Secure B…

Fix: 7.9.1+
Fix from $1,600 2025-03-12
Smartthings HIGH 8.8
CVE-2025-2233

Samsung SmartThings Improper Verification of Cryptographic Signature Authentication Bypass Vulnerability. This vulnerability allows network-adjacent …

Fix: 0.55.5+
Fix from $1,950 2025-03-11
Unclassified HIGH 8.6
CVE-2025-27773

The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. Prior to versions 4.17.0 and 5.0.0-alpha.20, there is a signature c…

Patch available
Fix from $1,950 2025-03-11
Windbg HIGH 7.5
CVE-2025-24043

Improper verification of cryptographic signature in .NET allows an authorized attacker to execute code over a network.

Fix: 1.2502.25002.0+
Fix from $1,950 2025-03-11