Skip to main content

CWE archive

CWE-347 CVEs

Programmatic archive

743 CVEs tagged with CWE-347133 Critical, 317 High, 265 Medium, 28 Low, 0 Unrated.

CVE-2026-53501

Published Jul 31, 2026

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor’s HMAC validation can be bypassed due to the use of Python’s .replace() when removing the s…

CVSS 8.2 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-44104

Published Jul 30, 2026

The firmware update process for the basemodule of the charging controller only validates the CRC32 checksum without cryptographic signature verification. This allows an unauthenti…

CVSS 9.3 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-17872

Published Jul 30, 2026

Cryptographic Flaw in WebAppInstalls in Google Chrome on Android prior to 151.0.7922.72 allowed a local attacker to potentially perform a sandbox escape via a crafted HTML page. (…

CVSS 6.1 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-13305

Published Jul 29, 2026

Autel MaxiCharger AC Elite Home Software Update Improper Verification of Cryptographic Signature Arbitrary Code Execution Vulnerability. This vulnerability allows physically prese…

CVSS 6.4 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-59243

Published Jul 29, 2026

The FAB auth manager's Azure AD OAuth login defaulted `verify_signature=False` when decoding the ID token, so an attacker able to present a forged or unsigned (`alg:none`) ID toke…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
25.4

CVE-2026-63237

Published Jul 29, 2026

A TOTP two-factor authentication bypass vulnerability in Koollab LMS allowed an attacker to supply a client-controlled seed to generate a matching one-time password and bypass the…

CVSS 4.8 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-65616

Published Jul 27, 2026

Incorrect authorization validation in refresh token signature allows non-admin users to obtain a signed JFrog administrator token.

CVSS 8.8 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-14837

Published Jul 27, 2026

Multiple Lenze products are affected by an improper signature verification vulnerability in the SSH enablement mechanism. A low-privileged local attacker can bypass verification o…

CVSS 8.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-48021

Published Jul 24, 2026

In epa4all, prior to version 2026-05-20, an attacker who can intercept the TLS connection between epa4all and the ePA backend can complete the VAU handshake with attacker-controll…

CVSS 9.1 · Critical
evidence mentions
3
Buzz score
23.9

CVE-2026-52686

Published Jul 23, 2026

The issue is a DNSSEC validation bypass where wildcard expansion proofs (NSEC/NSEC3 records) are accepted without signature validation when the wildcard answer is a CNAME or DNAME…

CVSS 3.7 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-13089

Published Jul 22, 2026

OIDC::Lite versions through 0.12.1 for Perl allow ID Token signature verification bypass via a token-controlled algorithm allowlist in verify. When the caller does not pin an alg…

CVSS 7.5 · High
evidence mentions
4
Buzz score
29.1

CVE-2026-10723

Published Jul 22, 2026

BIND may accept incorrect child-zone NSEC3 records as valid, which could allow an attacker to forge authenticated NXDOMAIN responses. This issue affects BIND 9 versions 9.18.0 thr…

CVSS 6.8 · Medium
evidence mentions
3
Buzz score
23.9

CVE-2026-64623

Published Jul 20, 2026

Network-AI before 5.13.4 contains an improper cryptographic signature verification vulnerability in APSAdapter where the default local verifier accepts any non-empty string as val…

CVSS 8.8 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-49834

Published Jul 17, 2026

sigstore-go is a Go library for Sigstore signing and verification. Prior to 1.2.0, a verifier configured with WithTransparencyLog(N>1) or WithSignedCertificateTimestamps(N>1) coun…

CVSS 5.9 · Medium
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-49998

Published Jul 16, 2026

Centrifugo is an open-source scalable real-time messaging server. Prior to 6.8.1, Centrifugo dynamic JWKS endpoint verification could reuse a key for one allowed issuer to verify…

CVSS 8.2 · High
evidence mentions
4
Buzz score
21.1

CVE-2026-45795

Published Jul 16, 2026

The Janssen Project is an open-source identity and access management (IAM) platform. Prior to 2.0.0, jans-auth-server accepts unsigned JWE request objects because JwtAuthorization…

CVSS 5.3 · Medium
evidence mentions
4
Buzz score
21.1

CVE-2026-54733

Published Jul 16, 2026

The Microsoft 365 and Microsoft Entra ID Plugins for Moodle provide Office 365 and Azure Active Directory integration for Moodle. Prior to 4.5.6, 5.0.5, and 5.1.1, the Microsoft O…

CVSS 9.3 · Critical
evidence mentions
7
Buzz score
25.8

CVE-2026-15013

Published Jul 16, 2026

The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass via SAML Signature Algorithm Confusion in all versions up to, and including, 5.4.3.…

CVSS 9.8 · Critical
evidence mentions
8
Buzz score
33.5

CVE-2026-46684

Published Jul 15, 2026

DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase enterprise token handling can let TokenFilter#doFilter() pass X-DE-TOKEN values to Toke…

CVSS 9.5 · Critical
evidence mentions
3
Buzz score
18.9

CVE-2026-48815

Published Jul 14, 2026

sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 4.1.1, the documented certificateOIDs option in sigstore.verify() is accepted by the pub…

CVSS 7.5 · High
evidence mentions
4
Buzz score
21.1

CVE-2026-48758

Published Jul 14, 2026

sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 3.2.1, the preAuthEncoding function in @sigstore/core uses Node.js ascii encoding when c…

CVSS 5.4 · Medium
evidence mentions
4
Buzz score
21.1

CVE-2026-48747

Published Jul 14, 2026

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 7.4.13 and 8.0.13, MailomatRequestParser::validateSignature() parsed X-M…

CVSS 6.3 · Medium
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-47212

Published Jul 14, 2026

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.12, and 8.0.12, TwilioRequestParser::doParse() received the…

CVSS 6.9 · Medium
evidence mentions
5
Buzz score
22.9
Vendor/product tagsBeta · best-effort

CVE-2026-45755

Published Jul 14, 2026

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 7.4.12 and 8.0.12, MailtrapRequestParser::doParse() received the configu…

CVSS 6.9 · Medium
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort
Showing 1-25 of 743 CVEsPage 1 of 30