Vulnerability index

Browse CVEs

732 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Signature VerificationCWE-347 × clear
HIGH 8.8 CVE-2024-37532 IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to identity spoofing by an authenticated user due to improper signature validation. IBM X… Websphere Application Server Mitigation only Fix from $1,9502024-06-20 MEDIUM 5.3 CVE-2024-36277 Improper verification of cryptographic signature issue exists in "FreeFrom - the nostr client" App versions prior to 1.3.5 for Android and iOS. The a… Mitigation only Fix from $1,6002024-06-17 MEDIUM 5.3 CVE-2024-21988 StorageGRID (formerly StorageGRID Webscale) versions prior to 11.7.0.9 and 11.8.0.5 are susceptible to disclosure of sensitive information via comp… Storagegrid 11.7.0.9 / 11.8.0.5+ Fix from $1,6002024-06-14 CRITICAL 9.8 CVE-2024-32911 There is a possible escalation of privilege due to improperly used crypto. This could lead to remote escalation of privilege with no additional execu… Android No fix yet Fix from $2,3002024-06-13 HIGH 7.5 CVE-2024-37568 lepture Authlib before 1.3.1 has algorithm confusion with asymmetric public keys. Unless an algorithm is specified in a jwt.decode call, HMAC verific… Authlib 1.3.1+ Fix from $1,9502024-06-09 MEDIUM 6.4 CVE-2024-2451 Improper fingerprint validation in the TeamViewer Client (Full & Host) prior Version 15.54 for Windows and macOS allows an attacker with administrati… Mitigation only Fix from $1,6002024-05-28 MEDIUM 5.6 CVE-2024-1721 Improper Verification of Cryptographic Signature vulnerability in HYPR Passwordless on Windows allows Malicious Software Update.This issue affects HY… Mitigation only Fix from $1,6002024-05-21 HIGH 7.8 CVE-2024-27244 Insufficient verification of data authenticity in the installer for Zoom Workplace VDI App for Windows may allow an authenticated user to conduct an… Workplace Virtual Desktop Infrastructure 5.15.0 / 5.17.10+ Fix from $1,9502024-05-15 MEDIUM 5.3 CVE-2024-34358 TYPO3 is an enterprise content management system. Starting in version 9.0.0 and prior to versions 9.5.48 ELTS, 10.4.45 ELTS, 11.5.37 LTS, 12.4.15 LTS… TYPO3 9.5.48 / 10.4.45+ Fix from $1,6002024-05-14 HIGH 7.8 CVE-2023-50228 Parallels Desktop Updater Improper Verification of Cryptographic Signature Local Privilege Escalation Vulnerability. This vulnerability allows local … Parallels Desktop 19.1.0_+ Fix from $1,9502024-05-03 CRITICAL 10.0 CVE-2024-32962 xml-crypto is an xml digital signature and encryption library for Node.js. In affected versions the default configuration does not check authorizatio… Patch available Fix from $2,3002024-05-02 CRITICAL 9.8 CVE-2024-23480 A fallback mechanism in code sign checking on macOS may allow arbitrary code execution. This issue affects Zscaler Client Connector on MacOS prior to… Client Connector 4.2+ Fix from $2,3002024-05-01 MEDIUM 6.7 CVE-2024-27247 Improper privilege management in the installer for Zoom Desktop Client for macOS before version 5.17.10 may allow a privileged user to conduct an esc… Zoom 5.17.10+ Fix from $1,6002024-04-09 HIGH 7.8 CVE-2024-24694 Improper privilege management in the installer for Zoom Desktop Client for Windows before version 5.17.10 may allow an authenticated user to conduct … Zoom 5.7.10+ Fix from $1,9502024-04-09 HIGH 7.8 CVE-2024-26228 Windows Cryptographic Services Security Feature Bypass Vulnerability Windows 10 1507 10.0.10240.20596 / 10.0.14393.6897+ Fix from $1,9502024-04-09 HIGH 7.4 CVE-2024-26194 Secure Boot Security Feature Bypass Vulnerability Windows 10 1507 10.0.10240.20596 / 10.0.14393.6897+ Fix from $1,9502024-04-09 CRITICAL 9.1 CVE-2023-52538 Vulnerability of package name verification being bypassed in the HwIms module. Impact: Successful exploitation of this vulnerability will affect avai… Emui No fix yet Fix from $2,3002024-04-08 HIGH 8.1 CVE-2023-52043 An issue in D-Link COVR 1100, 1102, 1103 AC1200 Dual-Band Whole-Home Mesh Wi-Fi System (Hardware Rev B1) truncates Wireless Access Point Passwords (W… Mitigation only Fix from $1,9502024-04-03 MEDIUM 6.1 CVE-2024-2307 A flaw was found in osbuild-composer. A condition can be triggered that disables GPG verification for package repositories, which can expose the buil… Mitigation only Fix from $1,6002024-03-19 CRITICAL 9.8 CVE-2018-25099 In the CryptX module before 0.062 for Perl, gcm_decrypt_verify() and chacha20poly1305_decrypt_verify() do not verify the tag. Patch available Fix from $2,3002024-03-18 MEDIUM 6.5 CVE-2024-21491 Versions of the package svix before 1.17.0 are vulnerable to Authentication Bypass due to an issue in the verify function where signatures of differe… Svix Webhooks 1.17.0+ Fix from $1,6002024-02-13 MEDIUM 5.5 CVE-2024-1149 Improper Verification of Cryptographic Signature vulnerability in Snow Software Inventory Agent on MacOS, Snow Software Inventory Agent on Windows, S… Snow Inventory Agent 6.7.2 / 6.14.5+ Fix from $1,6002024-02-08 MEDIUM 5.5 CVE-2024-1150 Improper Verification of Cryptographic Signature vulnerability in Snow Software Inventory Agent on Unix allows File Manipulation through Snow Update … Snow Inventory Agent 7.3.1+ Fix from $1,6002024-02-08 CRITICAL 9.1 CVE-2024-21917 A vulnerability exists in Rockwell Automation FactoryTalk® Service Platform that allows a malicious user to obtain the service token and use it for a… Factorytalk Services Platform after 6.31.00 Fix from $2,3002024-01-31 MEDIUM 5.3 CVE-2024-23680 AWS Encryption SDK for Java versions 2.0.0 to 2.2.0 and less than 1.9.0 incorrectly validates some invalid ECDSA signatures. Aws Encryption Sdk 1.9.0 / 2.2.0+ Fix from $1,6002024-01-19 CRITICAL 9.8 CVE-2023-44077 Studio Network Solutions ShareBrowser before 7.0 on macOS mishandles signature verification, aka PMP-2636. Sharebrowser 7.0+ Fix from $2,3002024-01-17 HIGH 7.5 CVE-2024-0567 A vulnerability was found in GnuTLS, where a cockpit (which uses gnuTLS) rejects a certificate chain with distributed trust. This issue occurs when v… Fedora 3.8.3+ Fix from $1,9502024-01-16 MEDIUM 5.3 CVE-2023-2030 An issue has been discovered in GitLab CE/EE affecting all versions from 12.2 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in whic… GitLab 16.5.6 / 16.6.4+ Fix from $1,6002024-01-12 CRITICAL 9.8 CVE-2016-20021 In Gentoo Portage before 3.0.47, there is missing PGP validation of executed code: the standalone emerge-webrsync downloads a .gpgsig file but does n… Portage 3.0.47+ Fix from $2,3002024-01-12 HIGH 8.8 CVE-2024-21669 Hyperledger Aries Cloud Agent Python (ACA-Py) is a foundation for building decentralized identity applications and services running in non-mobile env… Aries Cloud Agent 0.10.5+ Fix from $1,9502024-01-11