Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.5
CVE-2024-49393
In neomutt and mutt, the To and Cc email headers are not validated by cryptographic signing which allows an attacker that intercepts a message to cha…
Enterprise Linux
Patch available
CRITICAL 9.1
CVE-2024-47073
DataEase is an open source data visualization analysis tool that helps users quickly analyze data and gain insights into business trends. In affected…
Dataease
2.10.2+
MEDIUM 5.5
CVE-2024-51526
Permission control vulnerability in the hidebug module
Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Harmonyos
No fix yet
MEDIUM 6.3
CVE-2024-50347
Laravel Reverb provides a real-time WebSocket communication backend for Laravel applications. Prior to 1.4.0, there is an issue where verification si…
Patch available
MEDIUM 5.9
CVE-2024-8036
ABB is aware of privately reported vulnerabilities in the product versions referenced in this CVE. An attacker could exploit these vulnerabilities by…
No fix yet
CRITICAL 9.8
CVE-2024-47943
The firmware upgrade function in the admin web interface of the Rittal IoT Interface & CMC III Processing Unit devices checks if
the patch files are…
Mitigation only
HIGH 7.2
CVE-2024-8531
CWE-347: Improper Verification of Cryptographic Signature vulnerability exists that could
compromise the Data Center Expert software when an upgrade …
Mitigation only
CRITICAL 9.1
CVE-2024-9487EPSS 25%
An improper verification of cryptographic signature vulnerability was identified in GitHub Enterprise Server that allowed SAML SSO authentication to …
Enterprise Server
3.11.16 / 3.12.10+
CRITICAL 9.1
CVE-2024-48949
The verify function in lib/elliptic/eddsa/index.js in the Elliptic package before 6.5.6 for Node.js omits "sig.S().gte(sig.eddsa.curve.n) || sig.S().…
Elliptic
6.5.6+
CRITICAL 9.8
CVE-2024-47832
ssoready is a single sign on provider implemented via docker. Affected versions are vulnerable to XML signature bypass attacks. An attacker can carry…
Ssoready
2024-10-09+
HIGH 8.8
CVE-2024-7479
Improper verification of cryptographic signature during installation of a VPN driver via the TeamViewer_service.exe component of TeamViewer Remote Cl…
Mitigation only
HIGH 8.8
CVE-2024-7481
Improper verification of cryptographic signature during installation of a Printer driver via the TeamViewer_service.exe component of TeamViewer Remot…
Mitigation only
HIGH 7.7
CVE-2024-8698
A flaw exists in the SAML signature validation method within the Keycloak XMLSignatureUtil class. The method incorrectly determines whether a SAML si…
Mitigation only
HIGH 7.8
CVE-2024-7788
Improper Digital Signature Invalidation vulnerability in Zip Repair Mode of The Document Foundation LibreOffice allows Signature forgery vulnerabili…
Libreoffice
24.2.5+
MEDIUM 5.3
CVE-2024-45607EPSS 14%
whatsapp-api-js is a TypeScript server agnostic Whatsapp's Official API framework. It's possible to check the payload validation using the WhatsAppAP…
Whatsapp Api Js
4.0.3+
CRITICAL 9.8
CVE-2024-45409EPSS 11%
The Ruby SAML library is for implementing the client side of a SAML authorization. Ruby-SAML in <= 12.2 and 1.13.0 <= 1.16.0 does not properly verify…
Omniauth Saml
1.12.3 / 1.17.0+
MEDIUM 6.3
CVE-2024-38807
Applications that use spring-boot-loader or spring-boot-loader-classic and contain custom code that performs signature verification of nested jar fil…
Mitigation only
CRITICAL 9.8
CVE-2024-6800
An XML signature wrapping vulnerability was present in GitHub Enterprise Server (GHES) when using SAML authentication with specific identity provider…
Enterprise Server
3.10.16 / 3.11.14+
HIGH 7.5
CVE-2024-23456
Anti-tampering can be disabled under certain conditions without signature validation. This affects Zscaler Client Connector <4.2.0.190 with anti-tamp…
Client Connector
4.2.0.190+
HIGH 7.8
CVE-2024-23460
The Zscaler Updater process does not validate the digital signature of the installer before execution, allowing arbitrary code to be locally executed…
Client Connector
4.2+
MEDIUM 6.5
CVE-2023-28806
An Improper Validation of signature in Zscaler Client Connector on Windows allows an authenticated user to disable anti-tampering. This issue affects…
Client Connector
4.2.0.190+
MEDIUM 5.3
CVE-2024-42459
In the Elliptic package 6.5.6 for Node.js, EDDSA signature malleability occurs because there is a missing signature length check, and thus zero-value…
Elliptic
Patch available
CRITICAL 9.1
CVE-2024-42461
In the Elliptic package 6.5.6 for Node.js, ECDSA signature malleability occurs because BER-encoded signatures are allowed.
Elliptic
Patch available
MEDIUM 5.3
CVE-2024-41258
An issue was discovered in filestash v0.4. The usage of the ssh.InsecureIgnoreHostKey() disables host key verification, possibly allowing attackers t…
Filestash
after 0.4
MEDIUM 5.3
CVE-2024-41254
An issue was discovered in litestream v0.3.13. The usage of the ssh.InsecureIgnoreHostKey() disables host key verification, possibly allowing attacke…
Litestream
after 0.3.13
MEDIUM 6.8
CVE-2024-5912
An improper file signature check in Palo Alto Networks Cortex XDR agent may allow an attacker to bypass the Cortex XDR agent's executable blocking ca…
Mitigation only
HIGH 7.0
CVE-2024-38069
Windows Enroll Engine Security Feature Bypass Vulnerability
Windows 10 1507
10.0.10240.20710 / 10.0.14393.7159+
MEDIUM 6.5
CVE-2024-6580
The /n software IPWorks SSH library SFTPServer component can be induced to make unintended filesystem or network path requests when loading a SSH pub…
Ipworks Ssh
Mitigation only
HIGH 7.2
CVE-2023-34435
A firmware update vulnerability exists in the boa formUpload functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted network packets…
Rtl819x Jungle Software Development Kit
Mitigation only
HIGH 7.8
CVE-2024-20892
Improper verification of signature in FilterProvider prior to SMR Jul-2024 Release 1 allows local attackers to execute privileged behaviors. User int…
Android
Mitigation only