Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
CRITICAL 9.8
CVE-2026-18108
Net::SAML2 versions before 0.86 for Perl allow authentication bypass because _verify_encrypted_assertion accepts an EncryptedAssertion whose decrypte…
Net\
0.86+
HIGH 7.5
CVE-2026-18089
Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass by verifying responses against the response-embedded certificate in verify_…
Net\
0.86+
HIGH 7.3
CVE-2026-0392
eParakstītājs 3.0 for Windows before version
1.10.0 retrieves and executes its automatic updates over a channel that is not
authenticated or integrit…
No fix yet
HIGH 8.7
CVE-2026-12860
In Bouncy Castle for Java before 1.85, RSA PKCS#1 verification skips last two hash bytes in NULL-omitted path. This issue also affects Bouncy Castle …
Mitigation only
HIGH 8.7
CVE-2026-59643
In Bouncy Castle for Java before 1.85, OpenPGP inline-signature policy failures silently ignored. This issue also affects Bouncy Castle for Java FIPS…
No fix yet
HIGH 8.7
CVE-2026-59639
In Bouncy Castle for Java before 1.85, CMS verifySignatures returns true for SignedData with zero signers. This issue also affects Bouncy Castle for …
No fix yet
HIGH 7.5
CVE-2026-55735
Improper Verification of Cryptographic Signature in ueberauth guardian allows an unauthenticated attacker to revoke a victim's session with a forged …
Guardian
2.4.1+
HIGH 8.2
CVE-2026-53501
Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor’s HMAC validation can be bypassed due to the use of Python’s …
No fix yet
CRITICAL 9.8
CVE-2026-44104
The firmware update process for the basemodule of the charging controller only validates the
CRC32 checksum without cryptographic signature verificat…
No fix yet
MEDIUM 6.1
CVE-2026-17872
Cryptographic Flaw in WebAppInstalls in Google Chrome on Android prior to 151.0.7922.72 allowed a local attacker to potentially perform a sandbox esc…
Chrome
151.0.7922.72+
MEDIUM 6.4
CVE-2026-13305
Autel MaxiCharger AC Elite Home Software Update Improper Verification of Cryptographic Signature Arbitrary Code Execution Vulnerability. This vulnera…
No fix yet
CRITICAL 9.8
CVE-2026-59243
The FAB auth manager's Azure AD OAuth login defaulted `verify_signature=False` when decoding the ID token, so an attacker able to present a forged or…
Apache Airflow Providers Fab
3.7.3+
HIGH 8.8
CVE-2026-65616
Incorrect authorization validation in refresh token signature allows non-admin users to obtain a signed JFrog administrator token.
Artifactory
7.146.27+
HIGH 7.8
CVE-2026-14837
Multiple Lenze products are affected by an improper signature verification vulnerability in the SSH enablement mechanism. A low-privileged local atta…
No fix yet
CRITICAL 9.1
CVE-2026-48021
In epa4all, prior to version 2026-05-20, an attacker who can intercept the TLS connection between epa4all and the ePA backend can complete the VAU ha…
No fix yet
HIGH 7.5
CVE-2026-13089
OIDC::Lite versions through 0.12.1 for Perl allow ID Token signature verification bypass via a token-controlled algorithm allowlist in verify.
When …
No fix yet
MEDIUM 6.8
CVE-2026-10723
BIND may accept incorrect child-zone NSEC3 records as valid, which could allow an attacker to forge authenticated NXDOMAIN responses.
This issue affe…
No fix yet
HIGH 8.6
CVE-2026-64623
Network-AI before 5.13.4 contains an improper cryptographic signature verification vulnerability in APSAdapter where the default local verifier accep…
No fix yet
HIGH 7.5
CVE-2026-49834
sigstore-go is a Go library for Sigstore signing and verification. Prior to 1.2.0, a verifier configured with WithTransparencyLog(N>1) or WithSignedC…
Sigstore Go
1.2.0+
HIGH 8.2
CVE-2026-49998
Centrifugo is an open-source scalable real-time messaging server. Prior to 6.8.1, Centrifugo dynamic JWKS endpoint verification could reuse a key for…
No fix yet
MEDIUM 5.3
CVE-2026-45795
The Janssen Project is an open-source identity and access management (IAM) platform. Prior to 2.0.0, jans-auth-server accepts unsigned JWE request ob…
No fix yet
CRITICAL 9.3
CVE-2026-54733
The Microsoft 365 and Microsoft Entra ID Plugins for Moodle provide Office 365 and Azure Active Directory integration for Moodle. Prior to 4.5.6, 5.0…
No fix yet
CRITICAL 9.8
CVE-2026-15013
The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass via SAML Signature Algorithm Confusion in all version…
No fix yet
CRITICAL 9.5
CVE-2026-46684
DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase enterprise token handling can let TokenFilter#doFilter() …
Mitigation only
MEDIUM 5.4
CVE-2026-48758
sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 3.2.1, the preAuthEncoding function in @sigstore/core uses…
Mitigation only
HIGH 7.5
CVE-2026-48815
sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 4.1.1, the documented certificateOIDs option in sigstore.v…
Mitigation only
MEDIUM 5.3
CVE-2026-48747
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 7.4.13 and 8.0.13, MailomatRequestParser::…
Symfony
7.4.13 / 8.0.13+
MEDIUM 5.3
CVE-2026-47212
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.12, and 8.0.12, TwilioRequestP…
Symfony
6.4.40 / 7.4.12+
CRITICAL 9.8
CVE-2026-47304
Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.
.net Framework
8.0.29 / 9.0.18+
MEDIUM 5.3
CVE-2026-45755
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 7.4.12 and 8.0.12, MailtrapRequestParser::…
Symfony
7.4.12 / 8.0.12+