Vulnerability index

Browse CVEs

16 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Signature VerificationCWE-347 × clear
Build Of Keycloak CRITICAL 9.1
CVE-2026-16443

A flaw was found in the SAML metadata import functionality of the keycloak-services component, which is the core engine for identity brokering in Red…

Fix: 26.4.14 / 26.6.5+
Fix from $2,300 2026-08-05
Build Of Keycloak HIGH 8.1
CVE-2026-11800

A flaw was found in Keycloak. This JWT algorithm confusion vulnerability in the JWT Authorization Grant flow allows an attacker with valid client cre…

Fix: 26.6.4+
Fix from $1,950 2026-06-25
Build Of Keycloak HIGH 7.5
CVE-2026-9793

A flaw was found in Keycloak. When a JSON Web Encryption (JWE) encrypted request object is submitted, Keycloak may incorrectly process unsigned claim…

Mitigation only
Fix from $1,950 2026-05-28
Hardened Images MEDIUM 5.5
CVE-2026-2625

A flaw was found in rust-rpm-sequoia. An attacker can exploit this vulnerability by providing a specially crafted Red Hat Package Manager (RPM) file.…

Mitigation only
Fix from $1,600 2026-04-03
Enterprise Linux MEDIUM 5.3
CVE-2024-49394

In mutt and neomutt the In-Reply-To email header field is not protected by cryptographic signing which allows an attacker to reuse an unencrypted but…

Patch available
Fix from $1,600 2024-11-12
Enterprise Linux MEDIUM 6.5
CVE-2024-49393

In neomutt and mutt, the To and Cc email headers are not validated by cryptographic signing which allows an attacker that intercepts a message to cha…

Patch available
Fix from $1,600 2024-11-12
Storage MEDIUM 5.9
CVE-2023-3347

A vulnerability was found in Samba's SMB2 packet signing mechanism. The SMB2 packet signing is not enforced if an admin configured "server signing = …

Fix: 4.17.10 / 4.18.5+
Fix from $1,600 2023-07-20
Coreos Installer HIGH 7.8
CVE-2021-20319

An improper signature verification vulnerability was found in coreos-installer. A specially crafted gzip installation image can bypass the image sign…

Fix: 0.10.1+
Fix from $1,950 2022-03-04
Enterprise Linux MEDIUM 5.5
CVE-2021-3421

A flaw was found in the RPM package in the read functionality. This flaw allows an attacker who can convince a victim to install a seemingly verifiab…

Fix: 4.16.1.3+
Fix from $1,600 2021-05-19
Ansible Engine HIGH 7.1
CVE-2020-14365

A flaw was found in the Ansible Engine, in ansible-engine 2.8.x before 2.8.15 and ansible-engine 2.9.x before 2.9.13, when installing packages using …

Fix: after 3.7.2
Fix from $1,950 2020-09-23
Enterprise Linux MEDIUM 6.0
CVE-2020-10759

A PGP signature bypass flaw was found in fwupd (all versions), which could lead to the installation of unsigned firmware. As per upstream, a signatur…

No fix yet
Fix from $1,600 2020-09-15
Enterprise Linux Atomic Host MEDIUM 6.4
CVE-2020-15705

GRUB2 fails to validate kernel signature when booted directly without shim, allowing secure boot to be bypassed. This only affects systems where the …

Fix: after 2.04
Fix from $1,600 2020-07-29
Ceph Storage CRITICAL 9.1
CVE-2019-14859

A flaw was found in all python-ecdsa versions before 0.13.3, where it did not correctly verify whether signatures used DER encoding. Without this ver…

Fix: 0.13.3+
Fix from $2,300 2020-01-02
Redhat Upgrade Tool CRITICAL 9.8
CVE-2014-3585

redhat-upgrade-tool: Does not check GPG signatures when upgrading versions

Mitigation only
Fix from $2,300 2019-11-22
Keycloak HIGH 8.1
CVE-2019-10201

It was found that Keycloak's SAML broker, versions up to 6.0.1, did not verify missing message signatures. If an attacker modifies the SAML Response …

Fix: after 6.0.1
Fix from $1,950 2019-08-14
Satellite HIGH 7.5
CVE-2016-1000338

In Bouncy Castle JCE Provider version 1.55 and earlier the DSA does not fully validate ASN.1 encoding of signature on verification. It is possible to…

Fix: 1.56+
Fix from $1,950 2018-06-01