Vulnerability index

Browse CVEs

732 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Signature VerificationCWE-347 × clear
CRITICAL 9.8 CVE-2026-18108 Net::SAML2 versions before 0.86 for Perl allow authentication bypass because _verify_encrypted_assertion accepts an EncryptedAssertion whose decrypte… Net\ 0.86+ Fix from $2,3002026-08-03 HIGH 7.5 CVE-2026-18089 Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass by verifying responses against the response-embedded certificate in verify_… Net\ 0.86+ Fix from $1,9502026-08-03 HIGH 7.3 CVE-2026-0392 eParakstītājs 3.0 for Windows before version 1.10.0 retrieves and executes its automatic updates over a channel that is not authenticated or integrit… No fix yet Fix from $1,9502026-08-03 HIGH 8.7 CVE-2026-12860 In Bouncy Castle for Java before 1.85, RSA PKCS#1 verification skips last two hash bytes in NULL-omitted path. This issue also affects Bouncy Castle … Mitigation only Fix from $1,9502026-08-03 HIGH 8.7 CVE-2026-59643 In Bouncy Castle for Java before 1.85, OpenPGP inline-signature policy failures silently ignored. This issue also affects Bouncy Castle for Java FIPS… No fix yet Fix from $1,9502026-08-03 HIGH 8.7 CVE-2026-59639 In Bouncy Castle for Java before 1.85, CMS verifySignatures returns true for SignedData with zero signers. This issue also affects Bouncy Castle for … No fix yet Fix from $1,9502026-08-03 HIGH 7.5 CVE-2026-55735 Improper Verification of Cryptographic Signature in ueberauth guardian allows an unauthenticated attacker to revoke a victim's session with a forged … Guardian 2.4.1+ Fix from $1,9502026-08-01 HIGH 8.2 CVE-2026-53501 Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor’s HMAC validation can be bypassed due to the use of Python’s … No fix yet Fix from $1,9502026-07-31 CRITICAL 9.8 CVE-2026-44104 The firmware update process for the basemodule of the charging controller only validates the CRC32 checksum without cryptographic signature verificat… No fix yet Fix from $2,3002026-07-30 MEDIUM 6.1 CVE-2026-17872 Cryptographic Flaw in WebAppInstalls in Google Chrome on Android prior to 151.0.7922.72 allowed a local attacker to potentially perform a sandbox esc… Chrome 151.0.7922.72+ Fix from $1,6002026-07-30 MEDIUM 6.4 CVE-2026-13305 Autel MaxiCharger AC Elite Home Software Update Improper Verification of Cryptographic Signature Arbitrary Code Execution Vulnerability. This vulnera… No fix yet Fix from $1,6002026-07-29 CRITICAL 9.8 CVE-2026-59243 The FAB auth manager's Azure AD OAuth login defaulted `verify_signature=False` when decoding the ID token, so an attacker able to present a forged or… Apache Airflow Providers Fab 3.7.3+ Fix from $2,3002026-07-29 HIGH 8.8 CVE-2026-65616 Incorrect authorization validation in refresh token signature allows non-admin users to obtain a signed JFrog administrator token. Artifactory 7.146.27+ Fix from $1,9502026-07-27 HIGH 7.8 CVE-2026-14837 Multiple Lenze products are affected by an improper signature verification vulnerability in the SSH enablement mechanism. A low-privileged local atta… No fix yet Fix from $1,9502026-07-27 CRITICAL 9.1 CVE-2026-48021 In epa4all, prior to version 2026-05-20, an attacker who can intercept the TLS connection between epa4all and the ePA backend can complete the VAU ha… No fix yet Fix from $2,3002026-07-24 HIGH 7.5 CVE-2026-13089 OIDC::Lite versions through 0.12.1 for Perl allow ID Token signature verification bypass via a token-controlled algorithm allowlist in verify. When … No fix yet Fix from $1,9502026-07-22 MEDIUM 6.8 CVE-2026-10723 BIND may accept incorrect child-zone NSEC3 records as valid, which could allow an attacker to forge authenticated NXDOMAIN responses. This issue affe… No fix yet Fix from $1,6002026-07-22 HIGH 8.6 CVE-2026-64623 Network-AI before 5.13.4 contains an improper cryptographic signature verification vulnerability in APSAdapter where the default local verifier accep… No fix yet Fix from $1,9502026-07-20 HIGH 7.5 CVE-2026-49834 sigstore-go is a Go library for Sigstore signing and verification. Prior to 1.2.0, a verifier configured with WithTransparencyLog(N>1) or WithSignedC… Sigstore Go 1.2.0+ Fix from $1,9502026-07-17 HIGH 8.2 CVE-2026-49998 Centrifugo is an open-source scalable real-time messaging server. Prior to 6.8.1, Centrifugo dynamic JWKS endpoint verification could reuse a key for… No fix yet Fix from $1,9502026-07-16 MEDIUM 5.3 CVE-2026-45795 The Janssen Project is an open-source identity and access management (IAM) platform. Prior to 2.0.0, jans-auth-server accepts unsigned JWE request ob… No fix yet Fix from $1,6002026-07-16 CRITICAL 9.3 CVE-2026-54733 The Microsoft 365 and Microsoft Entra ID Plugins for Moodle provide Office 365 and Azure Active Directory integration for Moodle. Prior to 4.5.6, 5.0… No fix yet Fix from $2,3002026-07-16 CRITICAL 9.8 CVE-2026-15013 The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass via SAML Signature Algorithm Confusion in all version… No fix yet Fix from $2,3002026-07-16 CRITICAL 9.5 CVE-2026-46684 DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase enterprise token handling can let TokenFilter#doFilter() … Mitigation only Fix from $2,3002026-07-15 MEDIUM 5.4 CVE-2026-48758 sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 3.2.1, the preAuthEncoding function in @sigstore/core uses… Mitigation only Fix from $1,6002026-07-14 HIGH 7.5 CVE-2026-48815 sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 4.1.1, the documented certificateOIDs option in sigstore.v… Mitigation only Fix from $1,9502026-07-14 MEDIUM 5.3 CVE-2026-48747 Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 7.4.13 and 8.0.13, MailomatRequestParser::… Symfony 7.4.13 / 8.0.13+ Fix from $1,6002026-07-14 MEDIUM 5.3 CVE-2026-47212 Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.12, and 8.0.12, TwilioRequestP… Symfony 6.4.40 / 7.4.12+ Fix from $1,6002026-07-14 CRITICAL 9.8 CVE-2026-47304 Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network. .net Framework 8.0.29 / 9.0.18+ Fix from $2,3002026-07-14 MEDIUM 5.3 CVE-2026-45755 Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 7.4.12 and 8.0.12, MailtrapRequestParser::… Symfony 7.4.12 / 8.0.12+ Fix from $1,6002026-07-14