Vulnerability index

Browse CVEs

732 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Signature VerificationCWE-347 × clear
MEDIUM 6.5 CVE-2024-49393 In neomutt and mutt, the To and Cc email headers are not validated by cryptographic signing which allows an attacker that intercepts a message to cha… Enterprise Linux Patch available Fix from $1,6002024-11-12 CRITICAL 9.1 CVE-2024-47073 DataEase is an open source data visualization analysis tool that helps users quickly analyze data and gain insights into business trends. In affected… Dataease 2.10.2+ Fix from $2,3002024-11-07 MEDIUM 5.5 CVE-2024-51526 Permission control vulnerability in the hidebug module Impact: Successful exploitation of this vulnerability may affect service confidentiality. Harmonyos No fix yet Fix from $1,6002024-11-05 MEDIUM 6.3 CVE-2024-50347 Laravel Reverb provides a real-time WebSocket communication backend for Laravel applications. Prior to 1.4.0, there is an issue where verification si… Patch available Fix from $1,6002024-10-31 MEDIUM 5.9 CVE-2024-8036 ABB is aware of privately reported vulnerabilities in the product versions referenced in this CVE. An attacker could exploit these vulnerabilities by… No fix yet Fix from $1,6002024-10-25 CRITICAL 9.8 CVE-2024-47943 The firmware upgrade function in the admin web interface of the Rittal IoT Interface & CMC III Processing Unit devices checks if the patch files are… Mitigation only Fix from $2,3002024-10-15 HIGH 7.2 CVE-2024-8531 CWE-347: Improper Verification of Cryptographic Signature vulnerability exists that could compromise the Data Center Expert software when an upgrade … Mitigation only Fix from $1,9502024-10-11 CRITICAL 9.1 CVE-2024-9487EPSS 25% An improper verification of cryptographic signature vulnerability was identified in GitHub Enterprise Server that allowed SAML SSO authentication to … Enterprise Server 3.11.16 / 3.12.10+ Fix from $2,3002024-10-10 CRITICAL 9.1 CVE-2024-48949 The verify function in lib/elliptic/eddsa/index.js in the Elliptic package before 6.5.6 for Node.js omits "sig.S().gte(sig.eddsa.curve.n) || sig.S().… Elliptic 6.5.6+ Fix from $2,3002024-10-10 CRITICAL 9.8 CVE-2024-47832 ssoready is a single sign on provider implemented via docker. Affected versions are vulnerable to XML signature bypass attacks. An attacker can carry… Ssoready 2024-10-09+ Fix from $2,3002024-10-09 HIGH 8.8 CVE-2024-7479 Improper verification of cryptographic signature during installation of a VPN driver via the TeamViewer_service.exe component of TeamViewer Remote Cl… Mitigation only Fix from $1,9502024-09-25 HIGH 8.8 CVE-2024-7481 Improper verification of cryptographic signature during installation of a Printer driver via the TeamViewer_service.exe component of TeamViewer Remot… Mitigation only Fix from $1,9502024-09-25 HIGH 7.7 CVE-2024-8698 A flaw exists in the SAML signature validation method within the Keycloak XMLSignatureUtil class. The method incorrectly determines whether a SAML si… Mitigation only Fix from $1,9502024-09-19 HIGH 7.8 CVE-2024-7788 Improper Digital Signature Invalidation  vulnerability in Zip Repair Mode of The Document Foundation LibreOffice allows Signature forgery vulnerabili… Libreoffice 24.2.5+ Fix from $1,9502024-09-17 MEDIUM 5.3 CVE-2024-45607EPSS 14% whatsapp-api-js is a TypeScript server agnostic Whatsapp's Official API framework. It's possible to check the payload validation using the WhatsAppAP… Whatsapp Api Js 4.0.3+ Fix from $1,6002024-09-12 CRITICAL 9.8 CVE-2024-45409EPSS 11% The Ruby SAML library is for implementing the client side of a SAML authorization. Ruby-SAML in <= 12.2 and 1.13.0 <= 1.16.0 does not properly verify… Omniauth Saml 1.12.3 / 1.17.0+ Fix from $2,3002024-09-10 MEDIUM 6.3 CVE-2024-38807 Applications that use spring-boot-loader or spring-boot-loader-classic and contain custom code that performs signature verification of nested jar fil… Mitigation only Fix from $1,6002024-08-23 CRITICAL 9.8 CVE-2024-6800 An XML signature wrapping vulnerability was present in GitHub Enterprise Server (GHES) when using SAML authentication with specific identity provider… Enterprise Server 3.10.16 / 3.11.14+ Fix from $2,3002024-08-20 HIGH 7.5 CVE-2024-23456 Anti-tampering can be disabled under certain conditions without signature validation. This affects Zscaler Client Connector <4.2.0.190 with anti-tamp… Client Connector 4.2.0.190+ Fix from $1,9502024-08-06 HIGH 7.8 CVE-2024-23460 The Zscaler Updater process does not validate the digital signature of the installer before execution, allowing arbitrary code to be locally executed… Client Connector 4.2+ Fix from $1,9502024-08-06 MEDIUM 6.5 CVE-2023-28806 An Improper Validation of signature in Zscaler Client Connector on Windows allows an authenticated user to disable anti-tampering. This issue affects… Client Connector 4.2.0.190+ Fix from $1,6002024-08-06 MEDIUM 5.3 CVE-2024-42459 In the Elliptic package 6.5.6 for Node.js, EDDSA signature malleability occurs because there is a missing signature length check, and thus zero-value… Elliptic Patch available Fix from $1,6002024-08-02 CRITICAL 9.1 CVE-2024-42461 In the Elliptic package 6.5.6 for Node.js, ECDSA signature malleability occurs because BER-encoded signatures are allowed. Elliptic Patch available Fix from $2,3002024-08-02 MEDIUM 5.3 CVE-2024-41258 An issue was discovered in filestash v0.4. The usage of the ssh.InsecureIgnoreHostKey() disables host key verification, possibly allowing attackers t… Filestash after 0.4 Fix from $1,6002024-07-31 MEDIUM 5.3 CVE-2024-41254 An issue was discovered in litestream v0.3.13. The usage of the ssh.InsecureIgnoreHostKey() disables host key verification, possibly allowing attacke… Litestream after 0.3.13 Fix from $1,6002024-07-31 MEDIUM 6.8 CVE-2024-5912 An improper file signature check in Palo Alto Networks Cortex XDR agent may allow an attacker to bypass the Cortex XDR agent's executable blocking ca… Mitigation only Fix from $1,6002024-07-10 HIGH 7.0 CVE-2024-38069 Windows Enroll Engine Security Feature Bypass Vulnerability Windows 10 1507 10.0.10240.20710 / 10.0.14393.7159+ Fix from $1,9502024-07-09 MEDIUM 6.5 CVE-2024-6580 The /n software IPWorks SSH library SFTPServer component can be induced to make unintended filesystem or network path requests when loading a SSH pub… Ipworks Ssh Mitigation only Fix from $1,6002024-07-08 HIGH 7.2 CVE-2023-34435 A firmware update vulnerability exists in the boa formUpload functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted network packets… Rtl819x Jungle Software Development Kit Mitigation only Fix from $1,9502024-07-08 HIGH 7.8 CVE-2024-20892 Improper verification of signature in FilterProvider prior to SMR Jul-2024 Release 1 allows local attackers to execute privileged behaviors. User int… Android Mitigation only Fix from $1,9502024-07-02