Skip to main content

CWE archive

CWE-347 CVEs

Programmatic archive

734 CVEs tagged with CWE-347130 Critical, 313 High, 262 Medium, 28 Low, 1 Unrated.

CVE-2024-11696

Published Nov 26, 2024

The application failed to account for exceptions thrown by the `loadManifestFromFile` method during add-on signature verification. This flaw, triggered by an invalid or unsupporte…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-1461

Published Nov 18, 2024

A vulnerability in the Image Signature Verification feature of Cisco SD-WAN Software could allow an authenticated, remote attacker with Administrator-level credentials to ins…

CVSS 4.9 · Medium

CVE-2024-40592

Published Nov 12, 2024

An improper verification of cryptographic signature vulnerability [CWE-347] in FortiClient MacOS version 7.4.0, version 7.2.4 and below, version 7.0.10 and below, version 6.4.10 a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-47073

Published Nov 7, 2024

DataEase is an open source data visualization analysis tool that helps users quickly analyze data and gain insights into business trends. In affected versions a the lack of signat…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-51526

Published Nov 5, 2024

Permission control vulnerability in the hidebug module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-50347

Published Oct 31, 2024

Laravel Reverb provides a real-time WebSocket communication backend for Laravel applications. Prior to 1.4.0, there is an issue where verification signatures for requests sent to…

CVSS 6.3 · Medium

CVE-2024-8036

Published Oct 25, 2024

ABB is aware of privately reported vulnerabilities in the product versions referenced in this CVE. An attacker could exploit these vulnerabilities by sending a specially crafted f…

CVSS 4.6 · Medium

CVE-2024-48948

Published Oct 15, 2024

The Elliptic package 6.5.7 for Node.js, in its for ECDSA implementation, does not correctly verify valid signatures if the hash contains at least four leading 0 bytes and when the…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-47943

Published Oct 15, 2024

The firmware upgrade function in the admin web interface of the Rittal IoT Interface & CMC III Processing Unit devices checks if the patch files are signed before executing the c…

CVSS 9.8 · Critical

CVE-2024-8531

Published Oct 11, 2024

CWE-347: Improper Verification of Cryptographic Signature vulnerability exists that could compromise the Data Center Expert software when an upgrade bundle is manipulated to inclu…

CVSS 7.2 · High

CVE-2024-9487

Published Oct 10, 2024

An improper verification of cryptographic signature vulnerability was identified in GitHub Enterprise Server that allowed SAML SSO authentication to be bypassed resulting in unaut…

CVSS 9.5 · Critical
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2024-48949

Published Oct 10, 2024

The verify function in lib/elliptic/eddsa/index.js in the Elliptic package before 6.5.6 for Node.js omits "sig.S().gte(sig.eddsa.curve.n) || sig.S().isNeg()" validation.

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-47832

Published Oct 9, 2024

ssoready is a single sign on provider implemented via docker. Affected versions are vulnerable to XML signature bypass attacks. An attacker can carry out signature bypass if you h…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-7481

Published Sep 25, 2024

Improper verification of cryptographic signature during installation of a Printer driver via the TeamViewer_service.exe component of TeamViewer Remote Clients prior version 15.58.…

CVSS 8.8 · High

CVE-2024-7479

Published Sep 25, 2024

Improper verification of cryptographic signature during installation of a VPN driver via the TeamViewer_service.exe component of TeamViewer Remote Clients prior version 15.58.4 fo…

CVSS 8.8 · High

CVE-2024-8698

Published Sep 19, 2024

A flaw exists in the SAML signature validation method within the Keycloak XMLSignatureUtil class. The method incorrectly determines whether a SAML signature is for the full docume…

CVSS 7.7 · High

CVE-2024-7788

Published Sep 17, 2024

Improper Digital Signature Invalidation  vulnerability in Zip Repair Mode of The Document Foundation LibreOffice allows Signature forgery vulnerability in LibreOfficeThis issue af…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-45607

Published Sep 12, 2024

whatsapp-api-js is a TypeScript server agnostic Whatsapp's Official API framework. It's possible to check the payload validation using the WhatsAppAPI.verifyRequestSignature and e…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-38807

Published Aug 23, 2024

Applications that use spring-boot-loader or spring-boot-loader-classic and contain custom code that performs signature verification of nested jar files may be vulnerable to signat…

CVSS 6.3 · Medium

CVE-2024-6800

Published Aug 20, 2024

An XML signature wrapping vulnerability was present in GitHub Enterprise Server (GHES) when using SAML authentication with specific identity providers utilizing publicly exposed s…

CVSS 9.5 · Critical
evidence mentions
5
Buzz score
27.4
Vendor/product tagsBeta · best-effort

CVE-2024-23460

Published Aug 6, 2024

The Zscaler Updater process does not validate the digital signature of the installer before execution, allowing arbitrary code to be locally executed. This affects Zscaler Client…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 276-300 of 734 CVEsPage 12 of 30