Vulnerability index

Browse CVEs

8 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Signature VerificationCWE-347 × clear
CRITICAL 9.8 CVE-2026-59243 The FAB auth manager's Azure AD OAuth login defaulted `verify_signature=False` when decoding the ID token, so an attacker able to present a forged or… Apache Airflow Providers Fab 3.7.3+ Fix from $2,3002026-07-29 MEDIUM 6.5 CVE-2026-50634 A vulnerability in Apache CXF's JwsJsonContainerRequestFilter can be exploited to cause CXF to process metadata that was not authenticated by the acc… Cxf 4.1.7 / 4.2.2+ Fix from $1,6002026-06-12 MEDIUM 6.5 CVE-2025-55039 This issue affects Apache Spark versions before 3.4.4, 3.5.2 and 4.0.0. Apache Spark versions before 4.0.0, 3.5.2 and 3.4.4 use an insecure defau… Spark 3.4.4 / 3.5.2+ Fix from $1,6002025-10-15 HIGH 7.5 CVE-2021-41832 It is possible for an attacker to manipulate documents to appear to be signed by a trusted source. All versions of Apache OpenOffice up to 4.1.10 are… Openoffice 4.1.11+ Fix from $1,9502021-10-11 HIGH 7.5 CVE-2021-41830 It is possible for an attacker to manipulate signed documents and macros to appear to come from a trusted source. All versions of Apache OpenOffice u… Openoffice 4.1.11+ Fix from $1,9502021-10-11 MEDIUM 5.3 CVE-2021-41831 It is possible for an attacker to manipulate the timestamp of signed documents. All versions of Apache OpenOffice up to 4.1.10 are affected. Users ar… Openoffice 4.1.11+ Fix from $1,6002021-10-11 CRITICAL 9.8 CVE-2021-22160EPSS 53% If Apache Pulsar is configured to authenticate clients using tokens based on JSON Web Tokens (JWT), the signature of the token is not validated if th… Pulsar 2.7.1+ Fix from $2,3002021-05-26 HIGH 7.5 CVE-2019-17561 The "Apache NetBeans" autoupdate system does not fully validate code signatures. An attacker could modify the downloaded nbm and include additional c… Netbeans after 11.2 Fix from $1,9502020-03-30