Vulnerability index

Browse CVEs

732 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Signature VerificationCWE-347 × clear
MEDIUM 6.5 CVE-2026-6966 Improper verification of cryptographic signature uniqueness in delegated role validation in awslabs/tough before tough-v0.22.0 allows remote authenti… Tough 0.15.0 / 0.22.0+ Fix from $1,6002026-04-24 CRITICAL 9.8 CVE-2026-6911 Missing JWT signature verification in AWS Ops Wheel allows unauthenticated attackers to forge JWT tokens and gain unintended administrative access to… Patch available Fix from $2,3002026-04-24 MEDIUM 6.8 CVE-2026-34068 nimiq-transaction provides the transaction primitive to be used in Nimiq's Rust implementation. Prior to version 1.3.0, the staking contract accepts … Nimiq Proof Of Stake 1.3.0+ Fix from $1,6002026-04-22 CRITICAL 9.1 CVE-2026-40372EPSS 11% Improper verification of cryptographic signature in ASP.NET Core allows an unauthorized attacker to elevate privileges over a network. Asp.net Core 10.0.7+ Fix from $2,3002026-04-21 MEDIUM 5.3 CVE-2026-41301 OpenClaw versions 2026.3.22 before 2026.3.31 contain a signature verification bypass vulnerability in the Nostr DM ingress path that allows pairing c… Openclaw 2026.3.31+ Fix from $1,6002026-04-21 HIGH 7.5 CVE-2026-5050 The Payment Gateway for Redsys & WooCommerce Lite plugin for WordPress is vulnerable to Improper Verification of Cryptographic Signature in versions … Mitigation only Fix from $1,9502026-04-16 HIGH 7.5 CVE-2026-5588 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcpkix on all (pkix modules), Legion of th… Patch available Fix from $1,9502026-04-15 HIGH 8.3 CVE-2026-6328 Improper input validation, Improper verification of cryptographic signature vulnerability in XQUIC Project XQUIC xquic on Linux (QUIC protocol implem… Patch available Fix from $1,9502026-04-15 HIGH 7.3 CVE-2026-24032 A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP3 with UMC). The affected application contains an authentication weakness due… Mitigation only Fix from $1,9502026-04-14 CRITICAL 9.1 CVE-2026-0234 An improper verification of cryptographic signature vulnerability exists in Cortex XSOAR and Cortex XSIAM platforms during integration of Microsoft T… Cortex Xsiam 1.5.52+ Fix from $2,3002026-04-13 HIGH 8.1 CVE-2026-5466 wolfSSL's ECCSI signature verifier `wc_VerifyEccsiHash` decodes the `r` and `s` scalars from the signature blob via `mp_read_unsigned_bin` with no ch… Wolfssl 5.9.1+ Fix from $1,9502026-04-10 HIGH 8.1 CVE-2026-40070 BSV Ruby SDK is the Ruby SDK for the BSV blockchain. From 0.3.1 to before 0.8.2, BSV::Wallet::WalletClient#acquire_certificate persists certificate r… Bsv Wallet 0.3.4 / 0.8.2+ Fix from $1,9502026-04-09 HIGH 7.8 CVE-2026-35205 Helm is a package manager for Charts for Kubernetes. From 4.0.0 to 4.1.3, Helm will install plugins missing provenance (.prov file) when signature ve… Helm 4.1.4+ Fix from $1,9502026-04-09 MEDIUM 6.5 CVE-2026-39413 LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.4.14, the LightRAG API is vulnerable to a JWT algorithm confusion attack… Lightrag 1.4.14+ Fix from $1,6002026-04-08 HIGH 7.4 CVE-2026-32144 Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_ocsp module) allows OCSP designated-responder authorization bypass via… Erlang\/otp 1.17.1.2 / 1.20.3+ Fix from $1,9502026-04-07 MEDIUM 5.5 CVE-2026-2625 A flaw was found in rust-rpm-sequoia. An attacker can exploit this vulnerability by providing a specially crafted Red Hat Package Manager (RPM) file.… Hardened Images Mitigation only Fix from $1,6002026-04-03 HIGH 8.1 CVE-2026-34840 OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, OneUptime's SAML SSO implementation (App/FeatureSet/Iden… Oneuptime 10.0.42+ Fix from $1,9502026-04-02 CRITICAL 9.8 CVE-2026-33746 Convoy is a KVM server management panel for hosting businesses. From version 3.9.0-beta to before version 4.5.1, the JWTService::decode() method did … Convoy 4.5.1+ Fix from $2,3002026-04-02 CRITICAL 9.1 CVE-2026-34872 An issue was discovered in Mbed TLS 3.5.x and 3.6.x through 3.6.5 and TF-PSA-Crypto 1.0. There is a lack of contributory behavior in FFDH due to impr… Mbed Tls 3.6.6+ Fix from $2,3002026-04-01 HIGH 7.5 CVE-2026-34240 JOSE is a Javascript Object Signing and Encryption (JOSE) library. Prior to version 0.3.5+1, a vulnerability in jose could allow an unauthenticated, … Jose 0.3.5+ Fix from $1,9502026-03-31 HIGH 8.1 CVE-2026-34377 ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.0 and zebra-consensus version 5.0.1, a logic error in Zebra's transaction… Zebra 4.3.0 / 5.0.1+ Fix from $1,9502026-03-31 MEDIUM 5.3 CVE-2026-34155 RAUC controls the update process on embedded Linux systems. Prior to version 1.15.2, RAUC bundles using the 'plain' format exceeding a payload size o… Rauc 1.15.2+ Fix from $1,6002026-03-31 CRITICAL 9.8 CVE-2026-31946 OpenOlat is an open source web-based e-learning platform for teaching, learning, assessment and communication. From version 10.5.4 to before version … Openolat 20.2.5+ Fix from $2,3002026-03-30 MEDIUM 5.9 CVE-2026-32883 Botan is a C++ cryptography library. From version 3.0.0 to before version 3.11.0, during X509 path validation, OCSP responses were checked for an app… Botan 3.11.0+ Fix from $1,6002026-03-30 CRITICAL 9.1 CVE-2026-33026 Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, the nginx-ui backup restore mechanism allows attackers to tamper w… Nginx Ui 2.3.4+ Fix from $2,3002026-03-30 CRITICAL 9.8 CVE-2026-32974 OpenClaw before 2026.3.12 contains an authentication bypass vulnerability in Feishu webhook mode when only verificationToken is configured without en… Openclaw 2026.3.12+ Fix from $2,3002026-03-29 HIGH 7.5 CVE-2026-33895 Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, Ed25519 signature veri… Forge after 1.3.3 Fix from $1,9502026-03-27 HIGH 7.5 CVE-2026-33894 Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, RSASSA PKCS#1 v1.5 sig… Forge 1.4.0+ Fix from $1,9502026-03-27 HIGH 7.5 CVE-2026-33487 goxmlsig provides XML Digital Signatures implemented in Go. Prior to version 1.6.0, the `validateSignature` function in `validate.go` goes through th… Goxmldsig 1.6.0+ Fix from $1,9502026-03-26 MEDIUM 6.2 CVE-2026-20699 A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions. This issue is fixed in macOS Sequoia 1… macOS 14.8.5 / 15.7.5+ Fix from $1,6002026-03-25