Vulnerability index

Browse CVEs

733 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Signature VerificationCWE-347 × clear
CRITICAL 9.8 CVE-2023-28801 An Improper Verification of Cryptographic Signature in the SAML authentication of the Zscaler Admin UI allows a Privilege Escalation.This issue affec… Zscaler Internet Access Admin Portal 6.2r+ Fix from $2,3002023-08-31 HIGH 7.2 CVE-2023-20266 A vulnerability in Cisco Emergency Responder, Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Managem… Emergency Responder Mitigation only Fix from $1,9502023-08-30 HIGH 8.8 CVE-2023-23772 Motorola MBTS Site Controller fails to check firmware update authenticity. The Motorola MBTS Site Controller lacks cryptographic signature validation… Mbts Site Controller Firmware Mitigation only Fix from $1,9502023-08-29 HIGH 8.8 CVE-2023-23773 Motorola EBTS/MBTS Base Radio fails to check firmware authenticity. The Motorola MBTS Base Radio lacks cryptographic signature validation for firmwar… Ebts Base Radio Firmware Mitigation only Fix from $1,9502023-08-29 MEDIUM 5.3 CVE-2023-40178 Node-SAML is a SAML library not dependent on any frameworks that runs in Node. The lack of checking of current timestamp allows a LogoutRequest XML t… Node Saml 4.0.5+ Fix from $1,6002023-08-23 MEDIUM 6.5 CVE-2021-43171 Improper verification of applications' cryptographic signatures in the /e/OS app store client App Lounge before 0.19q allows attackers in control of … App Lounge 0.19q+ Fix from $1,6002023-08-22 HIGH 7.5 CVE-2023-39392 Vulnerability of insecure signatures in the OsuLogin module. Successful exploitation of this vulnerability may cause OsuLogin to be maliciously modif… Emui Mitigation only Fix from $1,9502023-08-13 HIGH 7.5 CVE-2023-39393 Vulnerability of insecure signatures in the ServiceWifiResources module. Successful exploitation of this vulnerability may cause ServiceWifiResources… Emui Mitigation only Fix from $1,9502023-08-13 HIGH 7.5 CVE-2023-40012 uthenticode is a small cross-platform library for partially verifying Authenticode digital signatures. Versions of uthenticode prior to the 2.x serie… Uthenticode 2.0.0+ Fix from $1,9502023-08-09 CRITICAL 9.8 CVE-2023-39969 uthenticode is a small cross-platform library for partially verifying Authenticode digital signatures. Version 1.0.9 of uthenticode hashed the entire… Uthenticode 1.0.9+ Fix from $2,3002023-08-09 HIGH 7.8 CVE-2023-39211 Improper privilege management in Zoom Desktop Client for Windows and Zoom Rooms for Windows before 5.15.5 may allow an authenticated user to enable a… Rooms 5.15.5+ Fix from $1,9502023-08-08 HIGH 7.8 CVE-2023-38418 The BIG-IP Edge Client Installer on macOS does not follow best practices for elevating privileges during the installation process.  Note: Software ve… Access Policy Manager Clients 7.2.4.3+ Fix from $1,9502023-08-02 MEDIUM 5.9 CVE-2023-3347 A vulnerability was found in Samba's SMB2 packet signing mechanism. The SMB2 packet signing is not enforced if an admin configured "server signing = … Storage 4.17.10 / 4.18.5+ Fix from $1,6002023-07-20 MEDIUM 6.5 CVE-2023-33768 Incorrect signature verification of the firmware during the Device Firmware Update process of Belkin Wemo Smart Plug WSP080 v1.2 allows attackers to … Wemo Smart Plug Wsp080 Firmware No fix yet Fix from $1,6002023-07-13 MEDIUM 5.3 CVE-2023-35373 Mono Authenticode Validation Spoofing Vulnerability Mono 6.12.0.200+ Fix from $1,6002023-07-11 HIGH 7.8 CVE-2023-32449 Dell PowerStore versions prior to 3.5 contain an improper verification of cryptographic signature vulnerability. An attacker can trick a high privile… Powerstoret Os 3.5.0.0-2050321+ Fix from $1,9502023-06-22 HIGH 7.7 CVE-2023-28602 Zoom for Windows clients prior to 5.13.5 contain an improper verification of cryptographic signature vulnerability. A malicious user may potentially… Zoom 5.13.5+ Fix from $1,9502023-06-13 HIGH 7.8 CVE-2023-34120 Improper privilege management in Zoom for Windows, Zoom Rooms for Windows, and Zoom VDI for Windows clients before 5.14.0 may allow an authenticated… Virtual Desktop Infrastructure 5.14.0+ Fix from $1,9502023-06-13 HIGH 8.8 CVE-2023-33959 notation is a CLI tool to sign and verify OCI artifacts and container images. An attacker who has compromised a registry can cause users to verify th… Notation Go 1.0.0+ Fix from $1,9502023-06-06 CRITICAL 9.1 CVE-2023-34205 In Moov signedxml through 1.0.0, parsing the raw XML (as received) can result in different output than parsing the canonicalized XML. Thus, signature… Signedxml Mitigation only Fix from $2,3002023-05-30 MEDIUM 5.4 CVE-2023-33185 Django-SES is a drop-in mail backend for Django. The django_ses library implements a mail backend for Django using AWS Simple Email Service. The libr… Django Ses 3.5.0+ Fix from $1,6002023-05-26 HIGH 7.8 CVE-2022-4418 Local privilege escalation due to unrestricted loading of unsigned libraries. The following products are affected: Acronis Cyber Protect Home Office … Cyber Protect Home Office Mitigation only Fix from $1,9502023-05-18 HIGH 7.5 CVE-2023-25934 DELL ECS prior to 3.8.0.2 contains an improper verification of cryptographic signature vulnerability. A network attacker with an ability to intercept… Elastic Cloud Storage 3.8.0.2+ Fix from $1,9502023-05-04 MEDIUM 5.3 CVE-2023-28226 Windows Enroll Engine Security Feature Bypass Vulnerability Windows 10 1507 10.0.10240.19869 / 10.0.14393.5850+ Fix from $1,6002023-04-11 MEDIUM 5.5 CVE-2023-28228 Windows Spoofing Vulnerability Windows 10 1507 10.0.10240.19869 / 10.0.14393.5850+ Fix from $1,6002023-04-11 MEDIUM 5.3 CVE-2023-28818 An issue was discovered in Veritas NetBackup IT Analytics 11 before 11.2.0. The application upgrade process included unsigned files that could be exp… Aptare It Analytics 10.6.00+ Fix from $1,6002023-03-24 CRITICAL 9.8 CVE-2023-28610 The update process in OMICRON StationGuard and OMICRON StationScout before 2.21 can be exploited by providing a modified firmware update image. This … Stationguard after 2.20 Fix from $2,3002023-03-23 MEDIUM 5.9 CVE-2023-28113 russh is a Rust SSH client and server library. Starting in version 0.34.0 and prior to versions 0.36.2 and 0.37.1, Diffie-Hellman key validation is i… Russh 0.36.2+ Fix from $1,6002023-03-16 HIGH 7.8 CVE-2022-20929 A vulnerability in the upgrade signature verification of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, local a… Enterprise Nfv Infrastructure Software 4.9.1+ Fix from $1,9502023-03-10 HIGH 7.8 CVE-2023-20940 In the Android operating system, there is a possible way to replace a boot partition due to improperly used crypto. This could lead to local escalati… Android Patch available Fix from $1,9502023-02-28