Vulnerability index

Browse CVEs

732 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Signature VerificationCWE-347 × clear
HIGH 8.1 CVE-2025-9210 Missing signature validation in JSON Web Tokens in Otalio Ship Property Management System versions before 2.22.0 allows authenticated attackers to es… Fix unknown Fix from $4,9002026-08-18 CRITICAL 9.8 CVE-2026-74901 openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerability in pqc.py where AES-GCM decryption failures trigger fallback to … Fix unknown Fix from $5,7502026-08-17 CRITICAL 9.8 CVE-2026-74876 openssl_encrypt versions before 1.4.0 contain a vulnerability in PublicKeyBundle.from_dict() that creates key bundles from untrusted data without ver… Fix unknown Fix from $5,7502026-08-17 HIGH 8.1 CVE-2026-18500 @fastify/jwt is a JSON Web Token plugin for Fastify. In versions before 10.2.2, a per-request verification key passed to request.jwtVerify({ key }) i… No fix yet Fix from $4,9002026-08-15 MEDIUM 5.9 CVE-2026-74244 A flaw was found in Red Hat Quay's Stripe billing webhook handler. This vulnerability allows an unauthenticated attacker to forge billing events by s… No fix yet Fix from $4,0002026-08-14 HIGH 7.5 CVE-2026-19910 PAX Technology Q80 Application Installer Signature Verification Bypass Remote Code Execution Vulnerability. This vulnerability allows network-adjacen… No fix yet Fix from $4,9002026-08-14 HIGH 7.5 CVE-2026-56864 A malicious GOSUMDB was capable of serving arbitrary module content not contained within the transparency log. This attack allows for a coordinating … No fix yet Fix from $4,9002026-08-13 HIGH 8.4 CVE-2026-56865 A malicious GOPROXY was previously capable of forging up to two sumdb tiles that allow for a requested module to bypass the GOSUMDB check and persist… No fix yet Fix from $4,9002026-08-13 CRITICAL 9.8 CVE-2026-28148 Unauthenticated Bypass Vulnerability in Headless Single Sign On <= 1.6 versions. No fix yet Fix from $5,7502026-08-13 HIGH 8.8 CVE-2026-12263 Zohocorp ManageEngine Password Manager Pro versions before 13232 and PAM360 versions before 8551 are vulnerable to an authentication bypass vulnerabi… No fix yet Fix from $4,9002026-08-13 HIGH 7.2 CVE-2026-68759 A holder of a valid integration credential may impersonate other users under specific conditions. No fix yet Fix from $4,9002026-08-12 HIGH 7.5 CVE-2026-68757 A user with access to a valid SAML response may impersonate another user under specific conditions. No fix yet Fix from $4,9002026-08-12 CRITICAL 9.1 CVE-2025-59324 CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to properly validate LUKS encryption and, if encryption is present, all CryptoPro file i… No fix yet Fix from $5,7502026-08-12 HIGH 7.5 CVE-2025-59327 In CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4, bootxsa.efi fails to properly validate LUKS encryption and, if encryption is present, all … No fix yet Fix from $4,9002026-08-12 MEDIUM 5.9 CVE-2026-62757 Improper verification of cryptographic signature in Windows Schannel allows an unauthorized attacker to bypass a security feature over a network. Windows 10 1607 10.0.14393.9418 / 10.0.17763.9115+ Fix from $4,0002026-08-11 CRITICAL 9.8 CVE-2026-10579 A flaw was found in Picketlink Federation SAML; the unsolcited response handler would accept forged assertions with no verification or validation, pe… No fix yet Fix from $5,7502026-08-11 HIGH 8.1 CVE-2026-15556 A flaw was found in Picketlink's SP signature validation; a SAML response containing zero assertion elements matching the signature check can allow a… No fix yet Fix from $4,9002026-08-11 MEDIUM 5.9 CVE-2026-66776 SAP Approuter does not consistently enforce integrity verification on certain session-related request headers under specific conditions. An attacker … No fix yet Fix from $4,0002026-08-11 HIGH 8.6 CVE-2026-10754 Pega Platform versions 8.5.0 through 25.1.2 are affected by an improper validation of cryptographic signatures that may allow an attacker to bypass s… No fix yet Fix from $4,9002026-08-10 MEDIUM 6.7 CVE-2026-16742 systemd-homed contains a local privilege escalation bug via arbitrary system group addition to a local, logged in, homed-managed user No fix yet Fix from $4,0002026-08-10 HIGH 7.1 CVE-2026-58262 Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, header signature verification counts the unused padding bits o… No fix yet Fix from $1,9502026-08-07 CRITICAL 9.8 CVE-2026-62873 Improper verification of cryptographic signature in Microsoft 365 Admin Center allows an unauthorized attacker to elevate privileges over a network. Windows Admin Center No fix yet Fix from $2,3002026-08-07 HIGH 7.5 CVE-2026-62918 Improper verification of cryptographic signature in Microsoft Teams allows an unauthorized attacker to perform spoofing over a network. Teams No fix yet Fix from $1,9502026-08-07 CRITICAL 10.0 CVE-2026-5430 The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker t… Api Control Plane 4.1.0.257 / 4.2.0.197+ Fix from $2,3002026-08-06 CRITICAL 9.1 CVE-2026-7557 An improper verification of cryptographic signature vulnerability in the SAML authentication module of Progress MarkLogic Server before 11.3.6 and 12… No fix yet Fix from $2,3002026-08-05 CRITICAL 9.1 CVE-2026-16443 A flaw was found in the SAML metadata import functionality of the keycloak-services component, which is the core engine for identity brokering in Red… Build Of Keycloak 26.4.14 / 26.6.5+ Fix from $2,3002026-08-05 CRITICAL 9.2 CVE-2026-46713 Misskey is an open source, federated social media platform. Versions 12.37.0 and later, but prior to 2026.5.4, contain a vulnerability in the JSON-LD… Mitigation only Fix from $2,3002026-08-03 HIGH 7.5 CVE-2026-18568 XML::Sig versions from 0.29 before 0.72 for Perl allow signature verification bypass because verify returns true when every signature was skipped bef… \ 0.72+ Fix from $1,9502026-08-03 CRITICAL 9.1 CVE-2026-9487 XML::Sig versions before 0.71 for Perl allow signature wrapping via duplicate ID. _get_signed_xml() in lib/XML/Sig.pm, called from verify(), resolve… \ 0.71+ Fix from $2,3002026-08-03 HIGH 8.1 CVE-2026-18092 Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass via XML signature wrapping because new_from_xml reads assertion identity wi… Net\ 0.86+ Fix from $1,9502026-08-03