Skip to main content

CWE archive

CWE-347 CVEs

Programmatic archive

734 CVEs tagged with CWE-347130 Critical, 313 High, 262 Medium, 28 Low, 1 Unrated.

CVE-2022-31156

Published Jul 14, 2022

Gradle is a build tool. Dependency verification is a security feature in Gradle Build Tool that was introduced to allow validation of external dependencies either through their ch…

CVSS 6.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-25898

Published Jul 1, 2022

The package jsrsasign before 10.5.25 are vulnerable to Improper Verification of Cryptographic Signature when JWS or JWT signature with non Base64URL encoding special characters or…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2021-22573

Published May 3, 2022

The vulnerability is that IDToken verifier does not verify if token is properly signed. Signature verification makes sure that the token's payload comes from valid provider, not f…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-32977

Published Apr 4, 2022

AVEVA System Platform versions 2017 through 2020 R2 P01 does not verify, or incorrectly verifies, the cryptographic signature for data.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2015-3298

Published Mar 30, 2022

Yubico ykneo-openpgp before 1.0.10 has a typo in which an invalid PIN can be used. When first powered up, a signature will be issued even though the PIN has not been validated.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-24773

Published Mar 18, 2022

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.3.0, RSA PKCS#1 v1.5 signature verification code does not…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-24772

Published Mar 18, 2022

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.3.0, RSA PKCS#1 v1.5 signature verification code does not…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-24771

Published Mar 18, 2022

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.3.0, RSA PKCS#1 v1.5 signature verification code is lenie…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-24759

Published Mar 17, 2022

`@chainsafe/libp2p-noise` contains TypeScript implementation of noise protocol, an encryption protocol used in libp2p. `@chainsafe/libp2p-noise` before 4.1.2 and 5.0.3 does not co…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2022-23610

Published Mar 16, 2022

wire-server provides back end services for Wire, an open source messenger. In versions of wire-server prior to the 2022-01-27 release, it was possible to craft DSA Signatures to b…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-20319

Published Mar 4, 2022

An improper signature verification vulnerability was found in coreos-installer. A specially crafted gzip installation image can bypass the image signature verification and as a co…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-23655

Published Feb 24, 2022

Octobercms is a self-hosted CMS platform based on the Laravel PHP Framework. Affected versions of OctoberCMS did not validate gateway server signatures. As a result non-authoritat…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 451-475 of 734 CVEsPage 19 of 30