Vulnerability index

Browse CVEs

732 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Signature VerificationCWE-347 × clear
HIGH 7.8 CVE-2025-20206 A vulnerability in the interprocess communication (IPC) channel of Cisco Secure Client for Windows could allow an authenticated, local attacker to pe… Secure Client 5.1.8.105+ Fix from $1,9502025-03-05 CRITICAL 9.8 CVE-2025-27670 Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Insufficient Signature Validation OVE-202305… Vasion Print 20.0.1923 / 22.0.843+ Fix from $2,3002025-03-05 CRITICAL 9.3 CVE-2024-11957 Improper verification of the digital signature in ksojscore.dll in Kingsoft WPS Office in versions equal or less than 12.1.0.18276 on Windows allow… Mitigation only Fix from $2,3002025-03-04 MEDIUM 5.6 CVE-2025-27498 aes-gcm is a pure Rust implementation of the AES-GCM. In decrypt_in_place_detached, the decrypted ciphertext (which is the correct ciphertext) is exp… Patch available Fix from $1,6002025-03-03 CRITICAL 9.8 CVE-2023-25574 `jupyterhub-ltiauthenticator` is a JupyterHub authenticator for learning tools interoperability (LTI). LTI13Authenticator that was introduced in `jup… Lti Jupyterhub Authenticator Mitigation only Fix from $2,3002025-02-25 HIGH 7.2 CVE-2024-10237 There is a vulnerability in the BMC firmware image authentication design at Supermicro MBD-X12DPG-OA6 . An attacker can modify the firmware to by… Mitigation only Fix from $1,9502025-02-04 HIGH 7.2 CVE-2024-56161 Improper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator privilege to load malicious CPU … Mitigation only Fix from $1,9502025-02-03 CRITICAL 9.3 CVE-2025-24800 Hyperbridge is a hyper-scalable coprocessor for verifiable, cross-chain interoperability. A critical vulnerability was discovered in the ismp-grandpa… Patch available Fix from $2,3002025-01-28 HIGH 8.8 CVE-2025-23369 An improper verification of cryptographic signature vulnerability was identified in GitHub Enterprise Server that allowed signature spoofing for unau… Enterprise Server 3.12.14 / 3.13.10+ Fix from $1,9502025-01-21 HIGH 8.1 CVE-2025-23206 The AWS Cloud Development Kit (AWS CDK) is an open-source software development framework to define cloud infrastructure in code and provision it thro… Aws Cloud Development Kit 2.177.0+ Fix from $1,9502025-01-17 HIGH 7.8 CVE-2024-13172 Improper signature verification in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote … Endpoint Manager 2022+ Fix from $1,9502025-01-14 HIGH 8.2 CVE-2024-7344 Howyar UEFI Application "Reloader" (32-bit and 64-bit) is vulnerable to execution of unsigned software in a hardcoded path. Neo Impact 8.4.022-20241127 / 10.1.024-20241127+ Fix from $1,9502025-01-14 CRITICAL 9.1 CVE-2024-54150 cjwt is a C JSON Web Token (JWT) Implementation. Algorithm confusion occurs when a system improperly verifies the type of signature used, allowing at… Patch available Fix from $2,3002024-12-19 HIGH 7.1 CVE-2024-41159 A library injection vulnerability exists in Microsoft OneNote 16.83 for macOS. A specially crafted library can leverage OneNote's access privileges, … Onenote No fix yet Fix from $1,9502024-12-18 CRITICAL 9.1 CVE-2024-41165 A library injection vulnerability exists in Microsoft Word 16.83 for macOS. A specially crafted library can leverage Word's access privileges, leadin… Word No fix yet Fix from $2,3002024-12-18 CRITICAL 9.8 CVE-2024-42004 A library injection vulnerability exists in Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially crafted library can leverage… Teams No fix yet Fix from $2,3002024-12-18 CRITICAL 9.1 CVE-2024-42220 A library injection vulnerability exists in Microsoft Outlook 16.83.3 for macOS. A specially crafted library can leverage Outlook's access privileges… Outlook No fix yet Fix from $2,3002024-12-18 CRITICAL 9.1 CVE-2024-43106 A library injection vulnerability exists in Microsoft Excel 16.83 for macOS. A specially crafted library can leverage Excel's access privileges, lead… Excel No fix yet Fix from $2,3002024-12-18 CRITICAL 9.1 CVE-2024-39804 A library injection vulnerability exists in Microsoft PowerPoint 16.83 for macOS. A specially crafted library can leverage PowerPoint's access privil… Powerpoint No fix yet Fix from $2,3002024-12-18 CRITICAL 9.8 CVE-2024-41138 A library injection vulnerability exists in the com.microsoft.teams2.modulehost.app helper app of Microsoft Teams (work or school) 24046.2813.2770.10… Teams No fix yet Fix from $2,3002024-12-18 CRITICAL 9.8 CVE-2024-41145 A library injection vulnerability exists in the WebView.app helper app of Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A speciall… Teams No fix yet Fix from $2,3002024-12-18 HIGH 8.8 CVE-2024-22461 Dell RecoverPoint for Virtual Machines 6.0.x contains an OS Command injection vulnerability. A low privileged remote attacker could potentially explo… Recoverpoint For Virtual Machines Mitigation only Fix from $1,9502024-12-13 HIGH 8.5 CVE-2024-54126 This vulnerability exists in the TP-Link Archer C50 due to improper signature verification mechanism in the firmware upgrade process at its web inter… Mitigation only Fix from $1,9502024-12-05 HIGH 7.8 CVE-2024-47476 Dell NetWorker Management Console, version(s) 19.11, contain(s) an Improper Verification of Cryptographic Signature vulnerability. An unauthenticated… Networker Management Console Mitigation only Fix from $1,9502024-12-03 HIGH 7.8 CVE-2024-49413 Improper Verification of Cryptographic Signature in SmartSwitch prior to SMR Dec-2024 Release 1 allows local attackers to install malicious applicati… Android Mitigation only Fix from $1,9502024-12-03 HIGH 7.2 CVE-2024-52958 A improper verification of cryptographic signature vulnerability in plugin management in iota C.ai Conversational Platform from 1.0.0 through 2.1.3 a… Iota C.ai after 2.1.3 Fix from $1,9502024-11-27 MEDIUM 5.5 CVE-2024-53267 sigstore-java is a sigstore java client for interacting with sigstore infrastructure. sigstore-java has insufficient verification for a situation whe… Patch available Fix from $1,6002024-11-26 MEDIUM 5.4 CVE-2024-11696 The application failed to account for exceptions thrown by the `loadManifestFromFile` method during add-on signature verification. This flaw, trigger… Firefox 128.5.0 / 133.0+ Fix from $1,6002024-11-26 MEDIUM 6.7 CVE-2024-40592 An improper verification of cryptographic signature vulnerability [CWE-347] in FortiClient MacOS version 7.4.0, version 7.2.4 and below, version 7.0.… Forticlient 7.2.5+ Fix from $1,6002024-11-12 MEDIUM 5.3 CVE-2024-49394 In mutt and neomutt the In-Reply-To email header field is not protected by cryptographic signing which allows an attacker to reuse an unencrypted but… Enterprise Linux Patch available Fix from $1,6002024-11-12