Vulnerability index

Browse CVEs

732 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Signature VerificationCWE-347 × clear
CRITICAL 9.1 CVE-2023-5347 An Improper Verification of Cryptographic Signature vulnerability in the update process of Korenix JetNet Series allows replacing the whole operating… Jetnet 5310g Firmware No fix yet Fix from $2,3002024-01-09 HIGH 7.1 CVE-2023-23432 Some Honor products are affected by signature management vulnerability, successful exploitation could cause the forged system file overwrite the corr… Nth An00 Firmware 7.0.0.157+ Fix from $1,9502023-12-29 HIGH 7.1 CVE-2023-23433 Some Honor products are affected by signature management vulnerability, successful exploitation could cause the forged system file overwrite the corr… Nth An00 Firmware 7.0.0.157+ Fix from $1,9502023-12-29 HIGH 7.1 CVE-2023-23435 Some Honor products are affected by signature management vulnerability, successful exploitation could cause the forged system file overwrite the corr… Magicos 7.1.0.137+ Fix from $1,9502023-12-29 HIGH 7.1 CVE-2023-23436 Some Honor products are affected by signature management vulnerability, successful exploitation could cause the forged system file overwrite the corr… Magicos 7.1.0.100+ Fix from $1,9502023-12-29 HIGH 7.1 CVE-2023-23431 Some Honor products are affected by signature management vulnerability, successful exploitation could cause the forged system file overwrite the corr… Nth An00 Firmware 7.0.0.157+ Fix from $1,9502023-12-29 HIGH 8.8 CVE-2023-50714 yii2-authclient is an extension that adds OpenID, OAuth, OAuth2 and OpenId Connect consumers for the Yii framework 2.0. In yii2-authclient prior to v… Yii2 Authclient 2.2.15+ Fix from $1,9502023-12-22 MEDIUM 6.5 CVE-2023-49646 Improper authentication in some Zoom clients before version 5.16.5 may allow an authenticated user to conduct a denial of service via network access. Meeting Software Development Kit 5.14.14 / 5.15.12+ Fix from $1,6002023-12-13 MEDIUM 6.7 CVE-2023-41337 h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. In version 2.3.0-beta2 and prior, when h2o is configured to listen to multiple ad… H2o after 2.2.6 Fix from $1,6002023-12-12 HIGH 7.5 CVE-2023-49079 Misskey is an open source, decentralized social media platform. Misskey's missing signature validation allows arbitrary users to impersonate any remo… Misskey 2023.11.1+ Fix from $1,9502023-11-29 MEDIUM 6.7 CVE-2023-20567 Improper signature verification of RadeonTM RX Vega M Graphics driver for Windows may allow an attacker with admin privileges to launch AMDSoftwareIn… Radeon Rx Vega M Firmware 23.q3 / 23.7.1+ Fix from $1,6002023-11-14 MEDIUM 6.7 CVE-2023-20568 Improper signature verification of RadeonTM RX Vega M Graphics driver for Windows may allow an attacker with admin privileges to launch RadeonInstall… Radeon Rx Vega M Firmware 23.q3 / 23.7.1+ Fix from $1,6002023-11-14 HIGH 8.8 CVE-2023-5747 Bashis, a Security Researcher at IPVM has found a flaw that allows for a remote code execution during the installation of Wave on the camera device. … Wave Server Software 5.1.1.37647+ Fix from $1,9502023-11-13 MEDIUM 5.3 CVE-2023-47122 Gitsign is software for keyless Git signing using Sigstore. In versions of gitsign starting with 0.6.0 and prior to 0.8.0, Rekor public keys were fet… Gitsign 0.8.0+ Fix from $1,6002023-11-10 HIGH 7.5 CVE-2023-34058 VMware Tools contains a SAML token signature bypass vulnerability. A malicious actor that has been granted Guest Operation Privileges https://docs.v… Open Vm Tools 12.3.5+ Fix from $1,9502023-10-27 HIGH 7.5 CVE-2023-46234 browserify-sign is a package to duplicate the functionality of node's crypto public key functions, much of this is based on Fedor Indutny's work on i… Debian Linux 4.2.2+ Fix from $1,9502023-10-26 HIGH 7.8 CVE-2023-28796 Improper Verification of Cryptographic Signature vulnerability in Zscaler Client Connector on Linux allows Code Injection. This issue affects Zscaler… Client Connector 1.3.1.6+ Fix from $1,9502023-10-23 MEDIUM 5.3 CVE-2023-28804 An Improper Verification of Cryptographic Signature vulnerability in Zscaler Client Connector on Linux allows replacing binaries.This issue affects L… Client Connector 1.4.0.105+ Fix from $1,6002023-10-23 HIGH 7.5 CVE-2023-46324 pkg/suci/suci.go in free5GC udm before 1.2.0, when Go before 1.19 is used, allows an Invalid Curve Attack because it may compute a shared secret via … Udm 1.2.0+ Fix from $1,9502023-10-23 HIGH 8.8 CVE-2022-25333 The Texas Instruments OMAP L138 (secure variants) trusted execution environment (TEE) performs an RSA check implemented in mask ROM when loading a mo… Omap L138 Firmware Mitigation only Fix from $1,9502023-10-19 HIGH 7.8 CVE-2023-43611 The BIG-IP Edge Client Installer on macOS does not follow best practices for elevating privileges during the installation process.  This vulnerabilit… Big Ip Access Policy Manager 7.2.4.4 / 15.1.9+ Fix from $1,9502023-10-10 HIGH 8.1 CVE-2023-43660 Warpgate is a smart SSH, HTTPS and MySQL bastion host for Linux that doesn't need special client apps. The SSH key verification for a user can be byp… Warpgate 0.8.1+ Fix from $1,9502023-09-27 MEDIUM 5.5 CVE-2023-42811 aes-gcm is a pure Rust implementation of the AES-GCM. Starting in version 0.10.0 and prior to version 0.10.3, in the AES GCM implementation of decryp… Aes Gcm 0.10.3+ Fix from $1,6002023-09-22 MEDIUM 6.5 CVE-2023-42806 Hydra is the layer-two scalability solution for Cardano. Prior to version 0.13.0, not signing and verifying `$\mathsf{cid}$` allows an attacker (whic… Hydra 0.13.0+ Fix from $1,6002023-09-21 HIGH 7.0 CVE-2023-20135 A vulnerability in Cisco IOS XR Software image verification checks could allow an authenticated, local attacker to execute arbitrary code on the unde… Ios Xr 7.6 / 7.10.1+ Fix from $1,9502023-09-13 HIGH 7.8 CVE-2023-20236 A vulnerability in the iPXE boot function of Cisco IOS XR software could allow an authenticated, local attacker to install an unverified software ima… Ios Xr 7.10.1+ Fix from $1,9502023-09-13 MEDIUM 5.5 CVE-2023-41764 Microsoft Office Spoofing Vulnerability 365 Apps Patch available Fix from $1,6002023-09-12 HIGH 7.8 CVE-2023-40727 A vulnerability has been identified in QMS Automotive (All versions < V12.39). The QMS.Mobile module of the affected application uses weak outdated a… Qms Automotive 12.39+ Fix from $1,9502023-09-12 HIGH 7.8 CVE-2023-41744 Local privilege escalation due to unrestricted loading of unsigned libraries. The following products are affected: Acronis Agent (macOS) before build… Agent Patch available Fix from $1,9502023-08-31 CRITICAL 9.8 CVE-2023-28801 An Improper Verification of Cryptographic Signature in the SAML authentication of the Zscaler Admin UI allows a Privilege Escalation.This issue affec… Zscaler Internet Access Admin Portal 6.2r+ Fix from $2,3002023-08-31