Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.8
CVE-2025-20206
A vulnerability in the interprocess communication (IPC) channel of Cisco Secure Client for Windows could allow an authenticated, local attacker to pe…
Secure Client
5.1.8.105+
CRITICAL 9.8
CVE-2025-27670
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Insufficient Signature Validation OVE-202305…
Vasion Print
20.0.1923 / 22.0.843+
CRITICAL 9.3
CVE-2024-11957
Improper verification of the digital signature in ksojscore.dll in Kingsoft WPS Office in versions equal or less than 12.1.0.18276
on Windows allow…
Mitigation only
MEDIUM 5.6
CVE-2025-27498
aes-gcm is a pure Rust implementation of the AES-GCM. In decrypt_in_place_detached, the decrypted ciphertext (which is the correct ciphertext) is exp…
Patch available
CRITICAL 9.8
CVE-2023-25574
`jupyterhub-ltiauthenticator` is a JupyterHub authenticator for learning tools interoperability (LTI). LTI13Authenticator that was introduced in `jup…
Lti Jupyterhub Authenticator
Mitigation only
HIGH 7.2
CVE-2024-10237
There is a vulnerability in the BMC firmware image authentication design
at Supermicro MBD-X12DPG-OA6
. An attacker can modify the firmware to by…
Mitigation only
HIGH 7.2
CVE-2024-56161
Improper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator privilege to load malicious CPU …
Mitigation only
CRITICAL 9.3
CVE-2025-24800
Hyperbridge is a hyper-scalable coprocessor for verifiable, cross-chain interoperability. A critical vulnerability was discovered in the ismp-grandpa…
Patch available
HIGH 8.8
CVE-2025-23369
An improper verification of cryptographic signature vulnerability was identified in GitHub Enterprise Server that allowed signature spoofing for unau…
Enterprise Server
3.12.14 / 3.13.10+
HIGH 8.1
CVE-2025-23206
The AWS Cloud Development Kit (AWS CDK) is an open-source software development framework to define cloud infrastructure in code and provision it thro…
Aws Cloud Development Kit
2.177.0+
HIGH 7.8
CVE-2024-13172
Improper signature verification in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote …
Endpoint Manager
2022+
HIGH 8.2
CVE-2024-7344
Howyar UEFI Application "Reloader" (32-bit and 64-bit) is vulnerable to execution of unsigned software in a hardcoded path.
Neo Impact
8.4.022-20241127 / 10.1.024-20241127+
CRITICAL 9.1
CVE-2024-54150
cjwt is a C JSON Web Token (JWT) Implementation. Algorithm confusion occurs when a system improperly verifies the type of signature used, allowing at…
Patch available
HIGH 7.1
CVE-2024-41159
A library injection vulnerability exists in Microsoft OneNote 16.83 for macOS. A specially crafted library can leverage OneNote's access privileges, …
Onenote
No fix yet
CRITICAL 9.1
CVE-2024-41165
A library injection vulnerability exists in Microsoft Word 16.83 for macOS. A specially crafted library can leverage Word's access privileges, leadin…
Word
No fix yet
CRITICAL 9.8
CVE-2024-42004
A library injection vulnerability exists in Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially crafted library can leverage…
Teams
No fix yet
CRITICAL 9.1
CVE-2024-42220
A library injection vulnerability exists in Microsoft Outlook 16.83.3 for macOS. A specially crafted library can leverage Outlook's access privileges…
Outlook
No fix yet
CRITICAL 9.1
CVE-2024-43106
A library injection vulnerability exists in Microsoft Excel 16.83 for macOS. A specially crafted library can leverage Excel's access privileges, lead…
Excel
No fix yet
CRITICAL 9.1
CVE-2024-39804
A library injection vulnerability exists in Microsoft PowerPoint 16.83 for macOS. A specially crafted library can leverage PowerPoint's access privil…
Powerpoint
No fix yet
CRITICAL 9.8
CVE-2024-41138
A library injection vulnerability exists in the com.microsoft.teams2.modulehost.app helper app of Microsoft Teams (work or school) 24046.2813.2770.10…
Teams
No fix yet
CRITICAL 9.8
CVE-2024-41145
A library injection vulnerability exists in the WebView.app helper app of Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A speciall…
Teams
No fix yet
HIGH 8.8
CVE-2024-22461
Dell RecoverPoint for Virtual Machines 6.0.x contains an OS Command injection vulnerability. A low privileged remote attacker could potentially explo…
Recoverpoint For Virtual Machines
Mitigation only
HIGH 8.5
CVE-2024-54126
This vulnerability exists in the TP-Link Archer C50 due to improper signature verification mechanism in the firmware upgrade process at its web inter…
Mitigation only
HIGH 7.8
CVE-2024-47476
Dell NetWorker Management Console, version(s) 19.11, contain(s) an Improper Verification of Cryptographic Signature vulnerability. An unauthenticated…
Networker Management Console
Mitigation only
HIGH 7.8
CVE-2024-49413
Improper Verification of Cryptographic Signature in SmartSwitch prior to SMR Dec-2024 Release 1 allows local attackers to install malicious applicati…
Android
Mitigation only
HIGH 7.2
CVE-2024-52958
A improper verification of cryptographic signature vulnerability in plugin management in iota C.ai Conversational Platform from 1.0.0 through 2.1.3 a…
Iota C.ai
after 2.1.3
MEDIUM 5.5
CVE-2024-53267
sigstore-java is a sigstore java client for interacting with sigstore infrastructure. sigstore-java has insufficient verification for a situation whe…
Patch available
MEDIUM 5.4
CVE-2024-11696
The application failed to account for exceptions thrown by the `loadManifestFromFile` method during add-on signature verification. This flaw, trigger…
Firefox
128.5.0 / 133.0+
MEDIUM 6.7
CVE-2024-40592
An improper verification of cryptographic signature vulnerability [CWE-347] in FortiClient MacOS version 7.4.0, version 7.2.4 and below, version 7.0.…
Forticlient
7.2.5+
MEDIUM 5.3
CVE-2024-49394
In mutt and neomutt the In-Reply-To email header field is not protected by cryptographic signing which allows an attacker to reuse an unencrypted but…
Enterprise Linux
Patch available