Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 8.4
CVE-2025-23364
A vulnerability has been identified in TIA Administrator (All versions < V3.0.6). The affected application improperly validates code signing certific…
Tia Administrator
3.0.6+
MEDIUM 5.5
CVE-2025-21004
Improper verification of intent by broadcast receiver in System UI for Galaxy Watch prior to SMR Jul-2025 Release 1 allows local attackers to power o…
Wear Os
Mitigation only
HIGH 8.1
CVE-2024-49365
tiny-secp256k1 is a tiny secp256k1 native/JS wrapper. Prior to version 1.1.7, a malicious JSON-stringifyable message can be made passing on verify(),…
Patch available
MEDIUM 6.4
CVE-2024-36347
Improper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator privilege to load malicious micr…
Mitigation only
CRITICAL 9.6
CVE-2025-32977
Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 (Patch 5)…
Mitigation only
CRITICAL 9.3
CVE-2025-52556
rfc3161-client is a Python library implementing the Time-Stamp Protocol (TSP) described in RFC 3161. Prior to version 1.0.3, there is a flaw in the t…
Patch available
MEDIUM 5.1
CVE-2025-33069
Improper verification of cryptographic signature in App Control for Business (WDAC) allows an unauthorized attacker to bypass a security feature loca…
Windows 11 24h2
10.0.26100.4270+
MEDIUM 5.3
CVE-2025-24015
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Versions 1.46.0 through 2.1.6 have an issue that affects AES-256-GCM and AES-128-GCM in De…
Deno
2.1.7+
MEDIUM 5.5
CVE-2022-31807
A vulnerability has been identified in Building X - Security Manager Edge Controller (ACC-AP) (All versions). Affected devices do not properly check …
Sipass Integrated Ac5102 \(acc G2\) Firmware
Mitigation only
HIGH 7.5
CVE-2025-47949
samlify is a Node.js library for SAML single sign-on. A Signature Wrapping attack has been found in samlify prior to version 2.10.0, allowing an atta…
Samlify
2.10.0+
HIGH 8.7
CVE-2025-47934
OpenPGP.js is a JavaScript implementation of the OpenPGP protocol. Startinf in version 5.0.1 and prior to versions 5.11.3 and 6.1.1, a maliciously mo…
Patch available
CRITICAL 9.8
CVE-2025-3757
Versions of OpenPubkey library prior to 0.10.0 contained a vulnerability that would allow a specially crafted JWS to bypass signature verification.
Openpubkey
0.10.0+
CRITICAL 9.8
CVE-2025-4658
Versions of OpenPubkey library prior to 0.10.0 contained a vulnerability that would allow a specially crafted JWS to bypass signature verification. …
Openpubkey
0.5.0 / 0.10.0+
MEDIUM 6.8
CVE-2025-20181
A vulnerability in Cisco IOS Software for Cisco Catalyst 2960X, 2960XR, 2960CX, and 3560CX Series Switches could allow an authenticated, local attack…
iOS
Mitigation only
HIGH 8.8
CVE-2025-33074
Improper verification of cryptographic signature in Microsoft Azure Functions allows an authorized attacker to execute code over a network.
Azure Functions
Mitigation only
MEDIUM 5.5
CVE-2025-2866
Improper Verification of Cryptographic Signature vulnerability in LibreOffice allows PDF Signature Spoofing by Improper Validation.
In the affect…
Libreoffice
24.8.6.0 / 25.2.2+
MEDIUM 6.8
CVE-2025-2763
CarlinKit CPC200-CCPA Improper Verification of Cryptographic Signature Code Execution Vulnerability. This vulnerability allows physically present att…
Autokit
Mitigation only
HIGH 8.0
CVE-2025-2764
CarlinKit CPC200-CCPA update.cgi Improper Verification of Cryptographic Signature Code Execution Vulnerability. This vulnerability allows network-adj…
Autokit
Mitigation only
HIGH 7.2
CVE-2025-20178
A vulnerability in the web-based management interface of Cisco Secure Network Analytics could allow an authenticated, remote attacker with valid admi…
Secure Network Analytics
Mitigation only
HIGH 7.5
CVE-2025-29915
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. The AF_PACKET defrag option is …
Suricata
7.0.9+
HIGH 8.1
CVE-2025-27813
MSI Center before 2.0.52.0 has Missing PE Signature Validation.
Mitigation only
HIGH 8.7
CVE-2025-31489
MinIO is a High Performance Object Storage released under GNU Affero General Public License v3.0. The signature component of the authorization may be…
Patch available
CRITICAL 9.3
CVE-2025-29775EPSS 9%
xml-crypto is an XML digital signature and encryption library for Node.js. An attacker may be able to exploit a vulnerability in versions prior to 6.…
Patch available
CRITICAL 9.3
CVE-2025-29774EPSS 9%
xml-crypto is an XML digital signature and encryption library for Node.js. An attacker may be able to exploit a vulnerability in versions prior to 6.…
Patch available
CRITICAL 9.8
CVE-2025-25291EPSS 20%
ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. An authentication bypass vulnerability was found in ruby-…
Omniauth Saml
1.10.6 / 1.12.4+
CRITICAL 9.8
CVE-2025-25292EPSS 65%
ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. An authentication bypass vulnerability was found in ruby-…
Omniauth Saml
1.10.6 / 1.12.4+
MEDIUM 6.7
CVE-2025-20143
A vulnerability in the boot process of Cisco IOS XR Software could allow an authenticated, local attacker with high privileges to bypass the Secure B…
Ios Xr
7.9.1+
HIGH 8.8
CVE-2025-2233
Samsung SmartThings Improper Verification of Cryptographic Signature Authentication Bypass Vulnerability. This vulnerability allows network-adjacent …
Smartthings
0.55.5+
HIGH 8.6
CVE-2025-27773
The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. Prior to versions 4.17.0 and 5.0.0-alpha.20, there is a signature c…
Patch available
HIGH 7.5
CVE-2025-24043
Improper verification of cryptographic signature in .NET allows an authorized attacker to execute code over a network.
Windbg
1.2502.25002.0+