Vulnerability index

Browse CVEs

732 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Signature VerificationCWE-347 × clear
CRITICAL 9.3 CVE-2026-22696 dcap-qvl implements the quote verification logic for DCAP (Data Center Attestation Primitives). A vulnerability present in versions prior to 0.3.9 in… Mitigation only Fix from $2,3002026-01-26 HIGH 7.5 CVE-2026-23967 sm-crypto provides JavaScript implementations of the Chinese cryptographic algorithms SM2, SM3, and SM4. A signature malleability vulnerability exist… Sm Crypto 0.3.14+ Fix from $1,9502026-01-22 HIGH 7.5 CVE-2026-23992 go-tuf is a Go implementation of The Update Framework (TUF). Starting in version 2.0.0 and prior to version 2.3.1, a compromised or misconfigured TUF… Go Tuf 2.3.1+ Fix from $1,9502026-01-22 HIGH 7.5 CVE-2026-23965 sm-crypto provides JavaScript implementations of the Chinese cryptographic algorithms SM2, SM3, and SM4. A signature forgery vulnerability exists in … Sm Crypto 0.4.0+ Fix from $1,9502026-01-22 CRITICAL 9.8 CVE-2026-23518 Fleet is open source device management software. In versions prior to 4.78.3, 4.77.1, 4.76.2, 4.75.2, and 4.53.3, a vulnerability in Fleet's Windows … Fleet 4.53.3 / 4.75.2+ Fix from $2,3002026-01-21 CRITICAL 9.8 CVE-2025-36418 IBM ApplinX 11.1 is vulnerable due to a privilege escalation vulnerability due to improper verification of JWT tokens. An attacker may be able to cra… Applinx Mitigation only Fix from $2,3002026-01-20 HIGH 8.4 CVE-2025-12007 There is a vulnerability in the Supermicro BMC firmware validation logic at Supermicro MBD-X13SEM-F . An attacker can update the system firmware with… Mitigation only Fix from $1,9502026-01-16 HIGH 7.2 CVE-2025-12006 There is a vulnerability in the Supermicro BMC firmware validation logic at Supermicro MBD-X12STW-F . An attacker can update the system firmware with… Mitigation only Fix from $1,9502026-01-16 MEDIUM 6.5 CVE-2026-22817 Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.11.4, there is a flaw in Hono’s JWK/JWKS JWT verific… Hono 4.11.4+ Fix from $1,6002026-01-13 MEDIUM 6.5 CVE-2026-22818 Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.11.4, there is a flaw in Hono’s JWK/JWKS JWT verific… Hono 4.11.4+ Fix from $1,6002026-01-13 MEDIUM 5.3 CVE-2025-68925 Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, the code doesn't validate that the JWT header spe… Jervis 2.2+ Fix from $1,6002026-01-13 HIGH 7.5 CVE-2026-20965 Improper verification of cryptographic signature in Windows Admin Center allows an authorized attacker to elevate privileges locally. Windows Admin Center 0.70.0.0+ Fix from $1,9502026-01-13 CRITICAL 9.8 CVE-2025-15444 Crypt::Sodium::XS module versions prior to 0.000042, for Perl, include a vulnerable version of libsodium libsodium <= 1.0.20 or a version of libsodi… Crypt\ 0.000042+ Fix from $2,3002026-01-06 CRITICAL 9.8 CVE-2023-53951 Ever Gauzy v0.281.9 contains a JWT authentication vulnerability that allows attackers to exploit weak HMAC secret key implementation. Attackers can l… Mitigation only Fix from $2,3002025-12-19 MEDIUM 6.5 CVE-2025-68113 ALTCHA is privacy-first software for captcha and bot protection. A cryptographic semantic binding flaw in ALTCHA libraries allows challenge payload s… Patch available Fix from $1,6002025-12-16 MEDIUM 5.5 CVE-2025-43521 A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions. This issue is fixed in macOS Sequoia 1… macOS 15.7.3+ Fix from $1,6002025-12-12 MEDIUM 5.3 CVE-2025-59803 Foxit PDF Editor and Reader before 2025.2.1 allow signature spoofing via triggers. An attacker can embed triggers (e.g., JavaScript) in a PDF documen… Pdf Editor after 2025.2.0.68868 Fix from $1,6002025-12-11 MEDIUM 6.5 CVE-2025-55311 An issue was discovered in Foxit PDF and Editor for Windows and macOS before 13.2 and 2025 before 2025.2. A crafted PDF can use JavaScript to alter a… Pdf Editor after 2025.1.0.66692 Fix from $1,6002025-12-11 HIGH 8.1 CVE-2025-65295 Multiple vulnerabilities in Aqara Hub firmware update process in the Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 devices, allo… Hub M2 Firmware No fix yet Fix from $1,9502025-12-10 CRITICAL 9.8 CVE-2025-59719EPSS 25% An improper verification of cryptographic signature vulnerability in Fortinet FortiWeb 8.0.0, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.… Fortiweb after 7.6.4 Fix from $2,3002025-12-09 CRITICAL 9.8 CVE-2025-59718 KEVEPSS 63% A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 … Fortiproxy 7.0.6 / 7.0.18+ Fix from $2,3002025-12-09 CRITICAL 9.1 CVE-2025-66567 The ruby-saml library is for implementing the client side of a SAML authorization. ruby-saml versions up to and including 1.12.4 contain an authentic… Ruby Saml 1.18.0+ Fix from $2,3002025-12-09 CRITICAL 9.1 CVE-2025-66568 The ruby-saml library implements the client side of an SAML authorization. Versions up to and including 1.12.4, are vulnerable to authentication bypa… Ruby Saml 1.18.0+ Fix from $2,3002025-12-09 HIGH 7.8 CVE-2025-13662 Improper verification of cryptographic signatures in the patch management component of Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a… Endpoint Manager 2024+ Fix from $1,9502025-12-09 HIGH 7.5 CVE-2025-65945 auth0/node-jws is a JSON Web Signature implementation for Node.js. In versions 3.2.2 and earlier and version 4.0.0, auth0/node-jws has an improper si… Node Jws 3.2.3+ Fix from $1,9502025-12-04 CRITICAL 9.3 CVE-2025-40934 XML-Sig versions 0.27 through 0.67 for Perl incorrectly validates XML files if signatures are omitted. An attacker can remove the signature from the… \ after 0.67 Fix from $2,3002025-11-26 HIGH 7.8 CVE-2025-34324 GoSign Desktop versions 2.4.0 and earlier use an unsigned update manifest for distributing application updates. The manifest contains package URLs an… Gosign 2.4.1+ Fix from $1,9502025-11-18 HIGH 7.8 CVE-2025-64740 Improper verification of cryptographic signature in the installer for Zoom Workplace VDI Client for Windows may allow an authenticated user to conduc… Workplace Virtual Desktop Infrastructure 6.3.14 / 6.4.12+ Fix from $1,9502025-11-13 MEDIUM 6.5 CVE-2025-64186 Evervault is a payment security solution. A vulnerability was identified in the `evervault-go` SDK’s attestation verification logic in versions of `e… Evervault 1.3.2+ Fix from $1,6002025-11-12 HIGH 7.8 CVE-2025-64456 In JetBrains ReSharper before 2025.2.4 missing signature verification in DPA Collector allows local privilege escalation Resharper 2025.2.4+ Fix from $1,9502025-11-10