Vulnerability index

Browse CVEs

12 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Jsrsasign HIGH 7.5
CVE-2026-4602

Versions of the package jsrsasign before 11.1.1 are vulnerable to Incorrect Conversion between Numeric Types due to handling negative exponents in ex…

Fix: 11.1.1+
Fix from $1,950 2026-03-23
Jsrsasign MEDIUM 5.3
CVE-2026-4603

Versions of the package jsrsasign before 11.1.1 are vulnerable to Division by zero due to the RSASetPublic/KEYUTIL parsing path in ext/rsa.js and the…

Fix: 11.1.1+
Fix from $1,600 2026-03-23
Jsrsasign CRITICAL 9.1
CVE-2026-4599

Versions of the package jsrsasign from 7.0.0 and before 11.1.1 are vulnerable to Incomplete Comparison with Missing Factors via the getRandomBigInteg…

Fix: 11.1.1+
Fix from $2,300 2026-03-23
Jsrsasign CRITICAL 9.1
CVE-2026-4600

Versions of the package jsrsasign before 11.1.1 are vulnerable to Improper Verification of Cryptographic Signature via the DSA domain-parameter valid…

Fix: 11.1.1+
Fix from $2,300 2026-03-23
Jsrsasign CRITICAL 9.1
CVE-2026-4601

Versions of the package jsrsasign before 11.1.1 are vulnerable to Missing Cryptographic Step via the KJUR.crypto.DSA.signWithMessageHash process in t…

Fix: 11.1.1+
Fix from $2,300 2026-03-23
Jsrsasign HIGH 7.5
CVE-2026-4598

Versions of the package jsrsasign before 11.1.1 are vulnerable to Infinite loop via the bnModInverse function in ext/jsbn2.js when the BigInteger.mod…

Fix: 11.1.1+
Fix from $1,950 2026-03-23
Jsrsasign MEDIUM 5.9
CVE-2024-21484

Versions of the package jsrsasign before 11.0.0 are vulnerable to Observable Discrepancy via the RSA PKCS1.5 or RSAOAEP decryption process. An attack…

Fix: 11.0.0+
Fix from $1,600 2024-01-22
Jsrsasign CRITICAL 9.8
CVE-2022-25898

The package jsrsasign before 10.5.25 are vulnerable to Improper Verification of Cryptographic Signature when JWS or JWT signature with non Base64URL …

Fix: 10.5.25+
Fix from $2,300 2022-07-01
Jsrsasign CRITICAL 9.1
CVE-2021-30246

In the jsrsasign package through 10.1.13 for Node.js, some invalid RSA PKCS#1 v1.5 signatures are mistakenly recognized to be valid. NOTE: there is n…

Fix: after 10.1.13
Fix from $2,300 2021-04-07
Jsrsasign CRITICAL 9.8
CVE-2020-14967

An issue was discovered in the jsrsasign package before 8.0.18 for Node.js. Its RSA PKCS1 v1.5 decryption implementation does not detect ciphertext m…

Fix: 8.0.18+
Fix from $2,300 2020-06-22
Jsrsasign CRITICAL 9.8
CVE-2020-14968

An issue was discovered in the jsrsasign package before 8.0.17 for Node.js. Its RSASSA-PSS (RSA-PSS) implementation does not detect signature manipul…

Fix: 8.0.17+
Fix from $2,300 2020-06-22
Jsrsasign HIGH 7.5
CVE-2020-14966

An issue was discovered in the jsrsasign package through 8.0.18 for Node.js. It allows a malleability in ECDSA signatures by not checking overflows i…

Fix: after 8.0.18
Fix from $1,950 2020-06-22