Vulnerability index

Browse CVEs

732 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Signature VerificationCWE-347 × clear
CRITICAL 9.0 CVE-2026-41005 Cloud Foundry UAA incorrectly treated XML encryption to the Service Provider (confidentiality) as a substitute for XML signatures from the Identity P… Mitigation only Fix from $2,3002026-06-11 HIGH 8.1 CVE-2026-10795 The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.26.… Mitigation only Fix from $1,9502026-06-11 HIGH 7.0 CVE-2026-42462 Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Prior to versions 1.9.11, 1.10.10, 2.0.18, 2.1.14, and 2.2.… Mitigation only Fix from $1,9502026-06-10 HIGH 8.8 CVE-2026-52754 Ghidra before 12.1 contains an authentication bypass vulnerability in PKIAuthenticationModule.authenticate() that allows any user with a valid CA-sig… Ghidra 12.1+ Fix from $1,9502026-06-10 MEDIUM 5.3 CVE-2026-41694 Since Spring Security SAML decrypts SAML Responses as well as elements of SAML LogoutRequests and LogoutResponses without requiring a valid signature… Spring Security 5.7.24 / 5.8.26+ Fix from $1,6002026-06-10 CRITICAL 9.8 CVE-2026-36721 A lack of cryptographic signature verification in the validateAccessToken function of bookcars v8.3 allows attackers to bypass authentication via a f… Mitigation only Fix from $2,3002026-06-09 CRITICAL 9.9 CVE-2026-44748 SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated attacker with normal privileges to obtain a valid signed message and … Mitigation only Fix from $2,3002026-06-09 HIGH 8.5 CVE-2026-47201 authentik is an open-source identity provider. Prior to versions 2025.12.5, 2026.2.3, and 2026.5.1, authentik's SAML Source ACS endpoint is vulnerabl… Authentik 2025.12.6 / 2026.2.4+ Fix from $1,9502026-06-02 MEDIUM 5.4 CVE-2026-48523 PyJWT is a JSON Web Token implementation in Python. From 2.9.0 to 2.12.1, there is a verifier-side algorithm allow-list bypass when jwt.decode() or j… Pyjwt 2.12.1+ Fix from $1,6002026-05-28 HIGH 7.4 CVE-2026-48526 PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, when the verifier is decoding JSON Web Tokens, while supporting both asymmetric … Pyjwt 2.13.0+ Fix from $1,9502026-05-28 HIGH 7.5 CVE-2026-9793 A flaw was found in Keycloak. When a JSON Web Encryption (JWE) encrypted request object is submitted, Keycloak may incorrectly process unsigned claim… Build Of Keycloak Mitigation only Fix from $1,9502026-05-28 MEDIUM 6.9 CVE-2026-44720 OpenLearnX is an open-source, decentralized learning and assessment platform. Prior to 2.0.4, a critical authentication vulnerability was identified … Mitigation only Fix from $1,6002026-05-27 MEDIUM 5.3 CVE-2025-67903 Northern.tech Mender Client 5 before 5.0.4 allows a Cryptographic signature verification bypass. Mitigation only Fix from $1,6002026-05-27 HIGH 8.8 CVE-2025-41669 The Web-based Management allows a remote low privileged Engineer user to install additional APPs on the device downloaded from the PLCnext Store with… Mitigation only Fix from $1,9502026-05-27 HIGH 7.4 CVE-2026-45575 epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. Prior to 1.2.2, an attacker who can MITM the TLS connection b… Patch available Fix from $1,9502026-05-26 HIGH 7.5 CVE-2026-39829 The RSA and DSA public key parsers did not enforce size limits on key parameters. A crafted public key with an excessively large modulus or DSA param… Crypto 0.52.0+ Fix from $1,9502026-05-22 MEDIUM 5.3 CVE-2026-44309 Gitsign is a keyless Sigstore to signing tool for Git commits with your a GitHub / OIDC identity. Prior to 0.16.0, gitsign verify and gitsign verify-… Mitigation only Fix from $1,6002026-05-15 CRITICAL 9.1 CVE-2026-44699 LibJWT is a C JSON Web Token Library. From 3.0.0 to 3.3.2, libjwt accepts an RSA JWK that does not contain an alg parameter as the verification key f… Mitigation only Fix from $2,3002026-05-15 HIGH 7.5 CVE-2026-44714 The bitcoinj library is a Java implementation of the Bitcoin protocol. Prior to 0.17.1, ScriptExecution.correctlySpends() contains two fast-path veri… Patch available Fix from $1,9502026-05-15 HIGH 7.0 CVE-2024-36334 Improper verification of cryptographic signature in the Radeon RGB tool could allow a malicious file placed in the installation directory to be run w… Mitigation only Fix from $1,9502026-05-15 HIGH 8.1 CVE-2026-42602 azureauthextension is the Azure Authenticator Extension. From 0.124.0 to 0.150.0, a server-side authentication bypass in azureauthextension allows an… Opentelemetry Collector Contrib after 0.150.0 Fix from $1,9502026-05-13 HIGH 8.1 CVE-2026-0265 An authentication bypass vulnerability in Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to bypass authe… Pan Os 10.2.7 / 10.2.10+ Fix from $1,9502026-05-13 CRITICAL 9.1 CVE-2026-33117 The Java Key Vault Keys library in the Azure SDK for Java contains an issue in the local cryptographic verification path where authentication tag com… Azure Sdk For Java 4.10.6+ Fix from $2,3002026-05-12 HIGH 8.0 CVE-2026-41431 Zen is a firefox-based browser. Prior to 1.19.9b, Zen Browser ships a Mozilla Application Resource (MAR) updater (org.mozilla.updater) that has had a… Patch available Fix from $1,9502026-05-11 CRITICAL 9.1 CVE-2026-42193 Plunk is an open-source email platform built on top of AWS SES. Prior to version 0.9.0, the /webhooks/sns endpoint accepts Amazon SNS notification pa… Mitigation only Fix from $2,3002026-05-08 CRITICAL 9.1 CVE-2026-44497 ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.4.0 and prior to zebra-script version 6.0.0, the fix for CVE-2026-41583 int… Zebra Script 4.4.0 / 6.0.0+ Fix from $2,3002026-05-08 HIGH 7.5 CVE-2026-42501 A malicious module proxy can exploit a flaw in the go command's validation of module checksums to bypass checksum database validation. This vulnerabi… Go 1.25.10 / 1.26.3+ Fix from $1,9502026-05-07 HIGH 8.2 CVE-2026-41669 Admidio is an open-source user management solution. Prior to version 5.0.9, the Admidio SAML Identity Provider implementation discards the return val… Mitigation only Fix from $1,9502026-05-07 MEDIUM 5.9 CVE-2026-33467 Improper Verification of Cryptographic Signature (CWE-347) in Elastic Package Registry could allow an attacker positioned to intercept network traffi… Elastic Package Registry 1.38.0+ Fix from $1,6002026-04-28 HIGH 8.2 CVE-2026-38651 Authentication Bypass vulnerability exists in Netmaker versions prior to 1.5.0. The VerifyHostToken function in logic/jwts.go fails to validate the J… Netmaker 1.5.0+ Fix from $1,9502026-04-28