Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 8.1
CVE-2025-9210
Missing signature validation in JSON Web Tokens in Otalio Ship Property Management System versions before 2.22.0 allows authenticated attackers to es…
Fix unknown
CRITICAL 9.8
CVE-2026-74901
openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerability in pqc.py where AES-GCM decryption failures trigger fallback to …
Fix unknown
CRITICAL 9.8
CVE-2026-74876
openssl_encrypt versions before 1.4.0 contain a vulnerability in PublicKeyBundle.from_dict() that creates key bundles from untrusted data without ver…
Fix unknown
HIGH 8.1
CVE-2026-18500
@fastify/jwt is a JSON Web Token plugin for Fastify. In versions before 10.2.2, a per-request verification key passed to request.jwtVerify({ key }) i…
No fix yet
MEDIUM 5.9
CVE-2026-74244
A flaw was found in Red Hat Quay's Stripe billing webhook handler. This vulnerability allows an unauthenticated attacker to forge billing events by s…
No fix yet
HIGH 7.5
CVE-2026-19910
PAX Technology Q80 Application Installer Signature Verification Bypass Remote Code Execution Vulnerability. This vulnerability allows network-adjacen…
No fix yet
HIGH 7.5
CVE-2026-56864
A malicious GOSUMDB was capable of serving arbitrary module content not contained within the transparency log. This attack allows for a coordinating …
No fix yet
HIGH 8.4
CVE-2026-56865
A malicious GOPROXY was previously capable of forging up to two sumdb tiles that allow for a requested module to bypass the GOSUMDB check and persist…
No fix yet
CRITICAL 9.8
CVE-2026-28148
Unauthenticated Bypass Vulnerability in Headless Single Sign On <= 1.6 versions.
No fix yet
HIGH 8.8
CVE-2026-12263
Zohocorp ManageEngine Password Manager Pro versions before 13232 and PAM360 versions before 8551 are vulnerable to an authentication bypass vulnerabi…
No fix yet
HIGH 7.2
CVE-2026-68759
A holder of a valid integration credential may impersonate other users under specific conditions.
No fix yet
HIGH 7.5
CVE-2026-68757
A user with access to a valid SAML response may impersonate another user under specific conditions.
No fix yet
CRITICAL 9.1
CVE-2025-59324
CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to properly validate LUKS encryption and, if encryption is present, all CryptoPro file i…
No fix yet
HIGH 7.5
CVE-2025-59327
In CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4, bootxsa.efi fails to properly validate LUKS encryption and, if encryption is present, all …
No fix yet
MEDIUM 5.9
CVE-2026-62757
Improper verification of cryptographic signature in Windows Schannel allows an unauthorized attacker to bypass a security feature over a network.
Windows 10 1607
10.0.14393.9418 / 10.0.17763.9115+
CRITICAL 9.8
CVE-2026-10579
A flaw was found in Picketlink Federation SAML; the unsolcited response handler would accept forged assertions with no verification or validation, pe…
No fix yet
HIGH 8.1
CVE-2026-15556
A flaw was found in Picketlink's SP signature validation; a SAML response containing zero assertion elements matching the signature check can allow a…
No fix yet
MEDIUM 5.9
CVE-2026-66776
SAP Approuter does not consistently enforce integrity verification on certain session-related request headers under specific conditions. An attacker …
No fix yet
HIGH 8.6
CVE-2026-10754
Pega Platform versions 8.5.0 through 25.1.2 are affected by an improper validation of cryptographic signatures that may allow an attacker to bypass s…
No fix yet
MEDIUM 6.7
CVE-2026-16742
systemd-homed contains a local privilege escalation bug via arbitrary system group addition to a local, logged in, homed-managed user
No fix yet
HIGH 7.1
CVE-2026-58262
Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, header signature verification counts the unused padding bits o…
No fix yet
CRITICAL 9.8
CVE-2026-62873
Improper verification of cryptographic signature in Microsoft 365 Admin Center allows an unauthorized attacker to elevate privileges over a network.
Windows Admin Center
No fix yet
HIGH 7.5
CVE-2026-62918
Improper verification of cryptographic signature in Microsoft Teams allows an unauthorized attacker to perform spoofing over a network.
Teams
No fix yet
CRITICAL 10.0
CVE-2026-5430
The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker t…
Api Control Plane
4.1.0.257 / 4.2.0.197+
CRITICAL 9.1
CVE-2026-7557
An improper verification of cryptographic signature vulnerability in the SAML authentication module of Progress MarkLogic Server before 11.3.6 and 12…
No fix yet
CRITICAL 9.1
CVE-2026-16443
A flaw was found in the SAML metadata import functionality of the keycloak-services component, which is the core engine for identity brokering in Red…
Build Of Keycloak
26.4.14 / 26.6.5+
CRITICAL 9.2
CVE-2026-46713
Misskey is an open source, federated social media platform. Versions 12.37.0 and later, but prior to 2026.5.4, contain a vulnerability in the JSON-LD…
Mitigation only
HIGH 7.5
CVE-2026-18568
XML::Sig versions from 0.29 before 0.72 for Perl allow signature verification bypass because verify returns true when every signature was skipped bef…
\
0.72+
CRITICAL 9.1
CVE-2026-9487
XML::Sig versions before 0.71 for Perl allow signature wrapping via duplicate ID.
_get_signed_xml() in lib/XML/Sig.pm, called from verify(), resolve…
\
0.71+
HIGH 8.1
CVE-2026-18092
Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass via XML signature wrapping because new_from_xml reads assertion identity wi…
Net\
0.86+