Skip to main content

CWE archive

CWE-347 CVEs

Programmatic archive

734 CVEs tagged with CWE-347130 Critical, 313 High, 262 Medium, 28 Low, 1 Unrated.

CVE-2022-39366

Published Oct 28, 2022

DataHub is an open-source metadata platform. Prior to version 0.8.45, the `StatelessTokenService` of the DataHub metadata service (GMS) does not verify the signature of JWT tokens…

CVSS 9.9 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-3322

Published Oct 28, 2022

Lock Warp switch is a feature of Zero Trust platform which, when enabled, prevents users of enrolled devices from disabling WARP client. Due to insufficient policy verification…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-39300

Published Oct 13, 2022

node SAML is a SAML 2.0 library based on the SAML implementation of passport-saml. A remote attacker may be able to bypass SAML authentication on a website using passport-saml. A…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2022-39299

Published Oct 12, 2022

Passport-SAML is a SAML 2.0 authentication provider for Passport, the Node.js authentication library. A remote attacker may be able to bypass SAML authentication on a website usin…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2022-42010

Published Oct 10, 2022

An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-39237

Published Oct 6, 2022

syslabs/sif is the Singularity Image Format (SIF) reference implementation. In versions prior to 2.8.1the `github.com/sylabs/sif/v2/pkg/integrity` package did not verify that the…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-36056

Published Sep 14, 2022

Cosign is a project under the sigstore organization which aims to make signatures invisible infrastructure. In versions prior to 1.12.0 a number of vulnerabilities have been found…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-39200

Published Sep 12, 2022

Dendrite is a Matrix homeserver written in Go. In affected versions events retrieved from a remote homeserver using the `/get_missing_events` path did not have their signatures ve…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2021-3521

Published Aug 22, 2022

There is a flaw in RPM's signature functionality. OpenPGP subkeys are associated with a primary key via a "binding signature." RPM does not check the binding signature of subkeys…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-2790

Published Aug 19, 2022

Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulenrable to CWE-347 Improper Verification of Cryptographic Signature, and does not properly verify compiled…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-28752

Published Aug 17, 2022

Zoom Rooms for Conference Rooms for Windows versions before 5.11.0 are susceptible to a Local Privilege Escalation vulnerability. A local low-privileged malicious user could explo…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-28751

Published Aug 17, 2022

The Zoom Client for Meetings for MacOS (Standard and for IT Admin) before version 5.11.3 contains a vulnerability in the package signature validation during the update process. A…

CVSS 8.8 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2022-28756

Published Aug 15, 2022

The Zoom Client for Meetings for macOS (Standard and for IT Admin) starting with version 5.7.3 and before 5.11.5 contains a vulnerability in the auto update process. A local low-p…

CVSS 8.8 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2022-35930

Published Aug 4, 2022

PolicyController is a utility used to enforce supply chain policy in Kubernetes clusters. In versions prior to 0.2.1 PolicyController will report a false positive, resulting in an…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2022-35929

Published Aug 4, 2022

cosign is a container signing and verification utility. In versions prior to 1.10.1 cosign can report a false positive if any attestation exists. `cosign verify-attestation` used…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2022-31207

Published Jul 26, 2022

The Omron SYSMAC Cx product family PLCs (CS series, CJ series, and CP series) through 2022-05-18 lack cryptographic authentication. They utilize the Omron FINS (9600/TCP) protocol…

CVSS 9.8 · Critical

CVE-2022-31172

Published Jul 22, 2022

OpenZeppelin Contracts is a library for smart contract development. Versions 4.1.0 until 4.7.1 are vulnerable to the SignatureChecker reverting. `SignatureChecker.isValidSignature…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 426-450 of 734 CVEsPage 18 of 30