Vulnerability index

Browse CVEs

733 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Signature VerificationCWE-347 × clear
CRITICAL 9.8 CVE-2023-25718 In ConnectWise Control through 22.9.10032 (formerly known as ScreenConnect), after an executable file is signed, additional instructions can be added… Control after 22.9.10032 Fix from $2,3002023-02-13 CRITICAL 9.8 CVE-2021-36226 Western Digital My Cloud devices before OS5 do not use cryptographically signed Firmware upgrade files. My Cloud Os 5.02.104+ Fix from $2,3002023-02-06 MEDIUM 5.3 CVE-2023-23940 OpenZeppelin Contracts for Cairo is a library for secure smart contract development written in Cairo for StarkNet, a decentralized ZK Rollup. `is_val… Contracts 0.6.1+ Fix from $1,6002023-02-03 HIGH 7.8 CVE-2022-34459 Dell Command | Update, Dell Update, and Alienware Update versions prior to 4.7 contain a improper verification of cryptographic signature in get appl… Alienware Update 4.7.1+ Fix from $1,9502023-02-01 CRITICAL 9.8 CVE-2023-23928 reason-jose is a JOSE implementation in ReasonML and OCaml.`Jose.Jws.validate` does not check HS256 signatures. This allows tampering of JWS header a… Reason Jose 0.8.2+ Fix from $2,3002023-02-01 CRITICAL 9.8 CVE-2022-23334 The Robot application in Ip-label Newtest before v8.5R0 was discovered to use weak signature checks on executed binaries, allowing attackers to have … Newtest 8.5r0+ Fix from $2,3002023-01-30 MEDIUM 5.9 CVE-2023-22742 libgit2 is a cross-platform, linkable library implementation of Git. When using an SSH remote with the optional libssh2 backend, libgit2 does not per… Libgit2 1.4.5+ Fix from $1,6002023-01-20 HIGH 7.5 CVE-2023-24025 CRYSTALS-DILITHIUM (in Post-Quantum Cryptography Selected Algorithms 2022) in PQClean d03da30 may allow universal forgeries of digital signatures via… Pqclean Mitigation only Fix from $1,9502023-01-20 CRITICAL 9.8 CVE-2020-22653 In Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n 10.5.1.0.199, Ruckus T301s 10… R310 Firmware 3.6.2.0.795+ Fix from $2,3002023-01-20 HIGH 7.5 CVE-2020-22659 In Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n 10.5.1.0.199, Ruckus T301s 10… R310 Firmware 3.6.2.0.795+ Fix from $1,9502023-01-20 MEDIUM 5.9 CVE-2022-46176 Cargo is a Rust package manager. The Rust Security Response WG was notified that Cargo did not perform SSH host key verification when cloning indexes… Cargo after 0.67.0 Fix from $1,6002023-01-11 MEDIUM 5.3 CVE-2020-36563 XML Digital Signatures generated and validated using this package use SHA-1, which may allow an attacker to craft inputs which cause hash collisions … Go Saml Patch available Fix from $1,6002022-12-28 HIGH 7.6 CVE-2022-23540 In versions `<=8.5.1` of `jsonwebtoken` library, lack of algorithm definition in the `jwt.verify()` function can lead to signature validation bypass … Jsonwebtoken after 8.5.1 Fix from $1,9502022-12-22 MEDIUM 6.4 CVE-2022-47549 An unprotected memory-access operation in optee_os in TrustedFirmware Open Portable Trusted Execution Environment (OP-TEE) before 3.20 allows a physi… Op Tee 3.20+ Fix from $1,6002022-12-19 MEDIUM 6.5 CVE-2022-23507 Tendermint is a high-performance blockchain consensus engine for Byzantine fault tolerant applications. Versions prior to 0.28.0 contain a potential … Tendermint Light Client Verifier 0.28.0+ Fix from $1,6002022-12-15 HIGH 7.8 CVE-2021-26391 Insufficient verification of multiple header signatures while loading a Trusted Application (TA) may allow an attacker with privileges to gain code e… Enterprise Driver 22.q2 / 22.5.2+ Fix from $1,9502022-11-09 HIGH 7.8 CVE-2022-41669 A CWE-347: Improper Verification of Cryptographic Signature vulnerability exists in the SGIUtility component that allows adversaries with local user … Ecostruxure Operator Terminal Expert 3.3+ Fix from $1,9502022-11-04 HIGH 7.8 CVE-2022-41666 A CWE-347: Improper Verification of Cryptographic Signature vulnerability exists that allows adversaries with local user privileges to load a malicio… Ecostruxure Operator Terminal Expert 3.3+ Fix from $1,9502022-11-04 MEDIUM 5.5 CVE-2022-42793 An issue in code signature validation was addressed with improved checks. This issue is fixed in macOS Big Sur 11.7, macOS Ventura 13, iOS 16, iOS 15… Ipados 11.7 / 12.6+ Fix from $1,6002022-11-01 CRITICAL 9.8 CVE-2022-39366 DataHub is an open-source metadata platform. Prior to version 0.8.45, the `StatelessTokenService` of the DataHub metadata service (GMS) does not veri… Datahub 0.8.45+ Fix from $2,3002022-10-28 HIGH 7.5 CVE-2022-3322 Lock Warp switch is a feature of Zero Trust platform which, when enabled, prevents users of enrolled devices from disabling WARP client. Due to ins… Warp Mobile Client 6.14+ Fix from $1,9502022-10-28 HIGH 7.8 CVE-2022-31123 Grafana is an open source observability and data visualization platform. Versions prior to 9.1.8 and 8.5.14 are vulnerable to a bypass in the plugin … Grafana 8.5.14 / 9.1.8+ Fix from $1,9502022-10-13 HIGH 8.1 CVE-2022-39300 node SAML is a SAML 2.0 library based on the SAML implementation of passport-saml. A remote attacker may be able to bypass SAML authentication on a w… Node Saml 4.0.0+ Fix from $1,9502022-10-13 HIGH 8.1 CVE-2022-39299 Passport-SAML is a SAML 2.0 authentication provider for Passport, the Node.js authentication library. A remote attacker may be able to bypass SAML au… Passport Saml 3.2.2+ Fix from $1,9502022-10-12 MEDIUM 6.8 CVE-2022-20944 A vulnerability in the software image verification functionality of Cisco IOS XE Software for Cisco Catalyst 9200 Series Switches could allow an unau… Ios Xe Mitigation only Fix from $1,6002022-10-10 MEDIUM 6.5 CVE-2022-42010 An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-… Fedora 1.12.24 / 1.14.4+ Fix from $1,6002022-10-10 CRITICAL 9.8 CVE-2022-39237 syslabs/sif is the Singularity Image Format (SIF) reference implementation. In versions prior to 2.8.1the `github.com/sylabs/sif/v2/pkg/integrity` pa… Singularity Image Format 2.8.1+ Fix from $2,3002022-10-06 HIGH 7.5 CVE-2022-41340 The secp256k1-js package before 1.1.0 for Node.js implements ECDSA without required r and s validation, leading to signature forgery. Secp256k1 Js 1.1.0+ Fix from $1,9502022-09-24 MEDIUM 5.5 CVE-2022-36056 Cosign is a project under the sigstore organization which aims to make signatures invisible infrastructure. In versions prior to 1.12.0 a number of v… Cosign 1.12.0+ Fix from $1,6002022-09-14 MEDIUM 5.3 CVE-2022-39200 Dendrite is a Matrix homeserver written in Go. In affected versions events retrieved from a remote homeserver using the `/get_missing_events` path di… Dendrite 0.9.8+ Fix from $1,6002022-09-12