Skip to main content

CWE archive

CWE-347 CVEs

Programmatic archive

733 CVEs tagged with CWE-347130 Critical, 313 High, 262 Medium, 27 Low, 1 Unrated.

CVE-2025-27498

Published Mar 3, 2025

aes-gcm is a pure Rust implementation of the AES-GCM. In decrypt_in_place_detached, the decrypted ciphertext (which is the correct ciphertext) is exposed even if the tag is incorr…

CVSS 5.6 · Medium

CVE-2023-25574

Published Feb 25, 2025

`jupyterhub-ltiauthenticator` is a JupyterHub authenticator for learning tools interoperability (LTI). LTI13Authenticator that was introduced in `jupyterhub-ltiauthenticator` 1.3.…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-10237

Published Feb 4, 2025

There is a vulnerability in the BMC firmware image authentication design at Supermicro MBD-X12DPG-OA6 . An attacker can modify the firmware to bypass BMC inspection and bypass…

CVSS 7.2 · High
evidence mentions
1
Buzz score
11.9

CVE-2024-56161

Published Feb 3, 2025

Improper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator privilege to load malicious CPU microcode resulting in loss of…

CVSS 7.2 · High
evidence mentions
3
Buzz score
20.4

CVE-2025-24800

Published Jan 28, 2025

Hyperbridge is a hyper-scalable coprocessor for verifiable, cross-chain interoperability. A critical vulnerability was discovered in the ismp-grandpa crate, that allowed a malicio…

CVSS 9.3 · Critical

CVE-2025-23369

Published Jan 21, 2025

An improper verification of cryptographic signature vulnerability was identified in GitHub Enterprise Server that allowed signature spoofing for unauthorized internal users. Inst…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2025-23206

Published Jan 17, 2025

The AWS Cloud Development Kit (AWS CDK) is an open-source software development framework to define cloud infrastructure in code and provision it through AWS CloudFormation. Users…

CVSS 1.8 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-13172

Published Jan 14, 2025

Improper signature verification in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to ac…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-54150

Published Dec 19, 2024

cjwt is a C JSON Web Token (JWT) Implementation. Algorithm confusion occurs when a system improperly verifies the type of signature used, allowing attackers to exploit the lack of…

CVSS 8.7 · High

CVE-2024-43106

Published Dec 18, 2024

A library injection vulnerability exists in Microsoft Excel 16.83 for macOS. A specially crafted library can leverage Excel's access privileges, leading to a permission bypass. A…

CVSS 7.1 · High
evidence mentions
3
Buzz score
21.9
Vendor/product tagsBeta · best-effort

CVE-2024-42220

Published Dec 18, 2024

A library injection vulnerability exists in Microsoft Outlook 16.83.3 for macOS. A specially crafted library can leverage Outlook's access privileges, leading to a permission bypa…

CVSS 7.1 · High
evidence mentions
3
Buzz score
21.9
Vendor/product tagsBeta · best-effort

CVE-2024-42004

Published Dec 18, 2024

A library injection vulnerability exists in Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially crafted library can leverage Teams's access privileges, le…

CVSS 7.1 · High
evidence mentions
3
Buzz score
21.9
Vendor/product tagsBeta · best-effort

CVE-2024-41165

Published Dec 18, 2024

A library injection vulnerability exists in Microsoft Word 16.83 for macOS. A specially crafted library can leverage Word's access privileges, leading to a permission bypass. A ma…

CVSS 7.1 · High
evidence mentions
3
Buzz score
21.9
Vendor/product tagsBeta · best-effort

CVE-2024-41159

Published Dec 18, 2024

A library injection vulnerability exists in Microsoft OneNote 16.83 for macOS. A specially crafted library can leverage OneNote's access privileges, leading to a permission bypass…

CVSS 7.1 · High
evidence mentions
3
Buzz score
21.9
Vendor/product tagsBeta · best-effort

CVE-2024-41145

Published Dec 18, 2024

A library injection vulnerability exists in the WebView.app helper app of Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially crafted library can leverage…

CVSS 7.1 · High
evidence mentions
3
Buzz score
21.9
Vendor/product tagsBeta · best-effort

CVE-2024-41138

Published Dec 18, 2024

A library injection vulnerability exists in the com.microsoft.teams2.modulehost.app helper app of Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially craf…

CVSS 7.1 · High
evidence mentions
3
Buzz score
21.9
Vendor/product tagsBeta · best-effort

CVE-2024-39804

Published Dec 18, 2024

A library injection vulnerability exists in Microsoft PowerPoint 16.83 for macOS. A specially crafted library can leverage PowerPoint's access privileges, leading to a permission…

CVSS 7.1 · High
evidence mentions
3
Buzz score
21.9
Vendor/product tagsBeta · best-effort

CVE-2024-54126

Published Dec 5, 2024

This vulnerability exists in the TP-Link Archer C50 due to improper signature verification mechanism in the firmware upgrade process at its web interface. An attacker with adminis…

CVSS 8.5 · High

CVE-2024-47476

Published Dec 3, 2024

Dell NetWorker Management Console, version(s) 19.11, contain(s) an Improper Verification of Cryptographic Signature vulnerability. An unauthenticated attacker with local access co…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-49413

Published Dec 3, 2024

Improper Verification of Cryptographic Signature in SmartSwitch prior to SMR Dec-2024 Release 1 allows local attackers to install malicious applications.

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-52958

Published Nov 27, 2024

A improper verification of cryptographic signature vulnerability in plugin management in iota C.ai Conversational Platform from 1.0.0 through 2.1.3 allows remote authenticated use…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-53267

Published Nov 26, 2024

sigstore-java is a sigstore java client for interacting with sigstore infrastructure. sigstore-java has insufficient verification for a situation where a validly-signed but "misma…

CVSS 5.5 · Medium

CVE-2024-11696

Published Nov 26, 2024

The application failed to account for exceptions thrown by the `loadManifestFromFile` method during add-on signature verification. This flaw, triggered by an invalid or unsupporte…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 251-275 of 733 CVEsPage 11 of 30