Vulnerability index

Browse CVEs

732 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Signature VerificationCWE-347 × clear
CRITICAL 9.1 CVE-2026-15265 A path traversal vulnerability in Tenable Agent 11.2.0 and 11.1.3 and lower allows a privileged attacker to write arbitrary files outside the intende… Mitigation only Fix from $2,3002026-07-14 CRITICAL 10.0 CVE-2026-56451 A vulnerability has been identified in Opcenter X (All versions < V2604). Affected applications do not properly validate the algorithm specified in t… Mitigation only Fix from $2,3002026-07-14 CRITICAL 9.3 CVE-2026-22097 The firmware update mechanism does not include cryptographic signature validation. This allows anyone with access to the firmware update capability t… Mitigation only Fix from $2,3002026-07-13 HIGH 8.2 CVE-2026-54736 Phalcon is a high-performance, full-stack PHP framework. Prior to 5.14.1, Phalcon\Encryption\Crypt::decrypt compares the attacker-supplied HMAC tag a… Patch available Fix from $1,9502026-07-10 MEDIUM 5.3 CVE-2026-9027 The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulnerable to Payment Bypass via Improper Verification of Cryptographic Signature i… Mitigation only Fix from $1,6002026-07-09 CRITICAL 10.0 CVE-2026-54782 CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF SAML 1.1 and SAML 2.0… Patch available Fix from $2,3002026-07-08 HIGH 7.4 CVE-2026-54783 CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF WS-Security endorsing… Patch available Fix from $1,9502026-07-08 HIGH 7.4 CVE-2026-54774 CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, SamlSerializer skips final Si… Patch available Fix from $1,9502026-07-08 MEDIUM 5.9 CVE-2026-54773 CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF WS-Security signature… Patch available Fix from $1,6002026-07-08 CRITICAL 9.1 CVE-2026-46354 Coder allows organizations to provision remote development environments via Terraform. In versions prior tp 2.24.5, 2.29.13, 2.30.8, 2.31.12, 2.32.2,… Coder 2.24.5 / 2.29.13+ Fix from $2,3002026-07-07 HIGH 8.1 CVE-2026-11348 Improper verification of cryptographic signature vulnerability in HAVELSAN Inc. Liman MYS allows Fake the Source of Data. This issue affects Liman M… Mitigation only Fix from $1,9502026-07-07 CRITICAL 9.6 CVE-2026-58426 Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write Patch available Fix from $2,3002026-07-03 HIGH 7.2 CVE-2026-13722 WatchGuard Fireware OS contains a firmware validation bypass when processing a backup image via the backup/restore feature. An authenticated administ… Fireware 11.12.4 / 12.12.1+ Fix from $1,9502026-07-03 MEDIUM 5.9 CVE-2026-50721 Libreswan, via the function RSA_authenticate_hash_signature_raw_rsa(), did not correctly verify the length of the authentication hash when the SIG pa… Libreswan 5.3.1+ Fix from $1,6002026-07-02 MEDIUM 5.9 CVE-2026-50722 Libreswan, via the function RSA_authenticate_hash_signature_pkcs1_1_5_rsa(), did not correctly verify the DER encoding of the ASN.1 digest when the I… Libreswan 5.3.1+ Fix from $1,6002026-07-02 HIGH 7.8 CVE-2024-23581 The HCL Traveler for Microsoft Outlook libraries are being flagged as potentially malicious software or an unrecognized application. Traveler For Microsoft Outlook 3.0.9+ Fix from $1,9502026-06-26 MEDIUM 6.5 CVE-2026-40941 Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have a package import signature validation bypass allow… Cacti 1.2.31+ Fix from $1,6002026-06-25 HIGH 7.5 CVE-2026-6331 HMAC zero-length tag forgery in EVP_DigestVerifyFinal, where a zero-length tag could be accepted as valid during HMAC verification. In the OpenSSL-co… Wolfssl 5.9.2+ Fix from $1,9502026-06-25 HIGH 7.5 CVE-2026-7511 PKCS7_verify signer confusion allows forged signatures, where the signer associated with a signature is not correctly bound, permitting a forged sign… Wolfssl 5.9.2+ Fix from $1,9502026-06-25 MEDIUM 6.5 CVE-2026-6329 PKCS#12 MAC verification uses an attacker-controlled comparison length, weakening the integrity check on the MAC and allowing a mismatched MAC to be … Wolfssl 5.9.2+ Fix from $1,6002026-06-25 HIGH 8.1 CVE-2026-11800 A flaw was found in Keycloak. This JWT algorithm confusion vulnerability in the JWT Authorization Grant flow allows an attacker with valid client cre… Build Of Keycloak 26.6.4+ Fix from $1,9502026-06-25 HIGH 7.5 CVE-2026-55961 wolfSSL_PKCS7_verify() returning success for a degenerate (certs-only) PKCS#7 object that contains no signer. Such an object has empty signerInfos, s… Wolfssl 5.9.2+ Fix from $1,9502026-06-25 HIGH 7.2 CVE-2026-9779 ATEN Unizon doCryptoHugeFileToFile Improper Verification of Cryptographic Signature Remote Code Execution Vulnerability. This vulnerability allows re… Unizon 2.7.264+ Fix from $1,9502026-06-24 CRITICAL 9.3 CVE-2026-46423 Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, 8.1.4, 8.0.5, 7.13.7, and 7.1… Mitigation only Fix from $2,3002026-06-24 MEDIUM 5.3 CVE-2026-46349 Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.5.10, 4.4.17, and 4.3.23, Mastodon's normalization of incoming… Mitigation only Fix from $1,6002026-06-24 CRITICAL 9.1 CVE-2026-49454 Relyra is a strict-by-default SAML 2.0 Service Provider library for Elixir and Phoenix. Versions 1.0.0 and 1.1.0 accept forged SAML signatures becaus… Patch available Fix from $2,3002026-06-18 MEDIUM 6.5 CVE-2026-42743 Unauthenticated Broken Authentication in Masteriyo - LMS <= 2.1.8 versions. Mitigation only Fix from $1,6002026-06-15 CRITICAL 10.0 CVE-2026-48558 KEVEPSS 11% SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication flow. Whe… Simplehelp 5.5.16+ Fix from $2,3002026-06-12 HIGH 7.5 CVE-2026-50010 Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, SimpleTru… Netty 4.1.135 / 4.2.15+ Fix from $1,9502026-06-12 MEDIUM 6.5 CVE-2026-50634 A vulnerability in Apache CXF's JwsJsonContainerRequestFilter can be exploited to cause CXF to process metadata that was not authenticated by the acc… Cxf 4.1.7 / 4.2.2+ Fix from $1,6002026-06-12