VulnSea

CWE-347

CVEs classified under CWE-347, newest first.

144 CVEsRSS

CVE-2026-75939High· 7.4
yesterday

A flaw was found in openshift/oc-mirror

A flaw was found in openshift/oc-mirror. The tool incorrectly verifies PGP (Pretty Good Privacy) release image signatures by checking for signature errors before the entire signed body is processed, leading to a bypass of the signature v…

TwilightRed Hat · openshift4/oc-mirror-plugin-rhel8via NVD
CVE-2026-94368High· 7.1
yesterday

A flaw was found in the signature verification logic of noobaa-core, the core component of the NooBaa Multicloud Object Gateway

A flaw was found in the signature verification logic of noobaa-core, the core component of the NooBaa Multicloud Object Gateway. The issue occurs when the service processes S3 presigned URLs using Signature Version 4 (SigV4). Due to impr…

TwilightRed Hat · odf4/mcg-core-rhel9via NVD
CVE-2026-9832Medium· 5.3
3d ago

The Payment Gateway of Stripe for WooCommerce plugin for WordPress is vulnerable to Improper Verification of Cryptographic Signature in all versions up to, and including, 5.0.8

The Payment Gateway of Stripe for WooCommerce plugin for WordPress is vulnerable to Improper Verification of Cryptographic Signature in all versions up to, and including, 5.0.8. This is due to the publicly accessible `woocommerce_api_wt_…

Sunlitthemehigh · Payment Gateway of Stripe for WooCommerceEPSS 0.23%via NVD
CVE-2026-59163Critical· 9.1PoC
4d ago

Mnemosyne is a memory layer for artificial intelligence agents

Mnemosyne is a memory layer for artificial intelligence agents. Prior to v3.10.1, the auth check in mnemosyne/core/sync_server.py parsed the JWT's header and payload using base64 decoding, then passed the token to a jwt library call with…

Abyssalmnemosyne-memory · mnemosyne-memoryEPSS 0.25%via NVD
CVE-2026-93657High· 7.5
4d ago

hickory-resolver versions before 0.26.2 fail to propagate bogus DNSSEC proof states through the Resolver::lookup() and Resolver::lookup_ip() APIs, allowing invalid records to be returned as successful results

hickory-resolver versions before 0.26.2 fail to propagate bogus DNSSEC proof states through the Resolver::lookup() and Resolver::lookup_ip() APIs, allowing invalid records to be returned as successful results. Attackers controlling the a…

Twilighthickory-dns · hickory-resolverEPSS 0.23%via NVD
CVE-2026-28198High· 8.8
4d ago

An authenticated, low-privileged user with access to the NetBackup Flex OS management shell could bypass the cryptographic signature verification step of a privileged support command by supplying a specially formed access credential

An authenticated, low-privileged user with access to the NetBackup Flex OS management shell could bypass the cryptographic signature verification step of a privileged support command by supplying a specially formed access credential. …

TwilightCohesity · NetBackup Flex OSEPSS 0.20%via NVD
CVE-2026-28199Low· 3.3
4d ago

An authenticated user with access to the NetBackup Flex OS management shell could read arbitrary files from the underlying operating system by supplying a specially crafted path argument to a diagnostic command

An authenticated user with access to the NetBackup Flex OS management shell could read arbitrary files from the underlying operating system by supplying a specially crafted path argument to a diagnostic command. Successful exploitatio…

SunlitCohesity · NetBackup Flex OSEPSS 0.07%via NVD
CVE-2026-54581High· 8.3
5d ago

mport is the MidnightBSD Package Manager

mport is the MidnightBSD Package Manager. Prior to 2.7.8, the mport_fetch_bootstrap_index() function in libmport/fetch.c could return success when bootstrap index hash verification encountered a missing or invalid hash because the failur…

TwilightMidnightBSD · mportEPSS 0.21%via NVD
CVE-2026-86038High· 7.5PoC
5d ago

libp2p is a JavaScript implementation of the libp2p networking stack

libp2p is a JavaScript implementation of the libp2p networking stack. From 15.0.0 until 16.0.5, @libp2p/gossipsub uses the default StrictSign policy in packages/gossipsub/src/utils/buildRawMessage.ts, where validateToRawMessage verifies …

Midnightlibp2p · @libp2p/gossipsubEPSS 0.16%via NVD
CVE-2026-78223Medium· 6.9
5d ago

Improper Verification of Cryptographic Signature vulnerability in team-alembic AshAuthentication allows a caller of the token revocation action to neutralise a revocation or write arbitrary rows into the token resource. AshAuthenticatio…

Improper Verification of Cryptographic Signature vulnerability in team-alembic AshAuthentication allows a caller of the token revocation action to neutralise a revocation or write arbitrary rows into the token resource. AshAuthenticatio…

Sunlitteam-alembic · ash_authenticationEPSS 0.32%via NVD
CVE-2026-92718High· 7.3PoC
6d ago

Nuclei versions before 3.11.1 cache template signature verification based only on file modification time without content checksums

Nuclei versions before 3.11.1 cache template signature verification based only on file modification time without content checksums. Attackers can replace verified templates with unsigned malicious content and restore the original modific…

Midnightprojectdiscovery · nucleiEPSS 0.11%via NVD
CVE-2026-42784High· 7.4
6d ago

A flaw was found in sequoia-openpgp

A flaw was found in sequoia-openpgp. The library incorrectly infers key flags for older certificates when a key flags subpacket is missing, leading to a discrepancy in how key capabilities are viewed. This key flag confusion allows an at…

TwilightRed Hat · rust-podman-sequoia-mainEPSS 0.16%via NVD
CVE-2026-19033Medium· 6.5
6d ago

For a secondary zone with transfers restricted by TSIG, `named` may start to serve the data provided in a zone transfer before the final message with the TSIG signature arrives

For a secondary zone with transfers restricted by TSIG, `named` may start to serve the data provided in a zone transfer before the final message with the TSIG signature arrives. This could allow an attacker that does not actually possess…

SunlitISC · BIND 9EPSS 0.20%via NVD
CVE-2026-86585High· 7.7
6d ago

The lack of signature verification of firmware update packages in VEO and VEO-XS Wi-Fi monitors, in versions prior to 01.48.001, allows an attacker who controls the delivery of an update to install unauthorised firmware.

The lack of signature verification of firmware update packages in VEO and VEO-XS Wi-Fi monitors, in versions prior to 01.48.001, allows an attacker who controls the delivery of an update to install unauthorised firmware.

TwilightFermax Electronica S.A.U. · DUOX PLUS monitor firmware (VEO Wi-Fi range)EPSS 0.14%via NVD
CVE-2026-86109Medium· 6.6
6d ago

The VeloCloud Edge software update workflow may accept update bundles without properly validating their signatures because the workflow does not restrict the digest algorithm used for artifact verification

The VeloCloud Edge software update workflow may accept update bundles without properly validating their signatures because the workflow does not restrict the digest algorithm used for artifact verification. An attacker with either suffic…

SunlitArista Networks · VeloCloud EdgeEPSS 0.24%via NVD
CVE-2026-58200High· 7.1
1w ago

Payload Plugins is a collection of plugins designed to enhance Payload CMS

Payload Plugins is a collection of plugins designed to enhance Payload CMS. From 0.3.0 until 0.4.0, @jhb.software/payload-cloudinary-plugin deployments with clientUploads enabled expose POST /api/cloudinary-generate-signature, whose hand…

Twilightjhb-software · payload-pluginsEPSS 0.18%via NVD
CVE-2026-87802Critical· 9.1
1w ago

Improper verification of cryptographic signature vulnerability in Apache Syncope. When SRA is configured for OAuth 2.0 without JWKS set URI assigned, an attacker can forge arbitrary JWTs to impersonate any user identity and permission…

Improper verification of cryptographic signature vulnerability in Apache Syncope. When SRA is configured for OAuth 2.0 without JWKS set URI assigned, an attacker can forge arbitrary JWTs to impersonate any user identity and permission…

MidnightApache Software Foundation · org.apache.syncope:syncope-sraEPSS 0.26%via NVD
CVE-2026-54155High· 7.7
1w ago

node-opcua is an OPC UA implementation for TypeScript and Node.js

node-opcua is an OPC UA implementation for TypeScript and Node.js. Prior to 2.166.0, the UserNameIdentityToken authentication handler in packages/node-opcua-server/source/opcua_server.ts decrypts an RSA-OAEP password blob but does not ve…

Twilightnode-opcua · node-opcuaEPSS 0.33%via NVD
CVE-2026-57122High· 8.6
1w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. Prior to 4.6.59, the WhatsApp and Linear bot webhook handlers verify HMAC signatures only when WHATSAPP_APP_SECRET or LINEAR_WEBHOOK_SECRET is configured and otherwise parse and dispatch unsigned …

TwilightMervinPraison · PraisonAIEPSS 0.13%via NVD
CVE-2026-54248Medium· 6.5
1w ago

Doco-CD is a GitOps continuous delivery tool that automatically deploys and updates Docker Compose projects/services and Swarm stacks

Doco-CD is a GitOps continuous delivery tool that automatically deploys and updates Docker Compose projects/services and Swarm stacks. Prior to version 0.90.1, a trust-boundary flaw in OCI artifact verification allowed artifact-provided …

Sunlitkimdre · doco-cdEPSS 0.23%via NVD
CVE-2026-89169Medium· 4.1
1w ago

live-boot ff8867c allows attackers to bypass the dm-verity-enforce-roothash-signature protection mechanism when the .verity file is missing.

live-boot ff8867c allows attackers to bypass the dm-verity-enforce-roothash-signature protection mechanism when the .verity file is missing.

SunlitDebian · live-bootEPSS 0.11%via NVD
CVE-2026-80469High· 8.3
1w ago

An attacker may achieve arbitrary code execution on a target system by uploading a malicious device driver package, bypassing driver verification mechanisms, and triggering the execution of attacker-controlled code

An attacker may achieve arbitrary code execution on a target system by uploading a malicious device driver package, bypassing driver verification mechanisms, and triggering the execution of attacker-controlled code. User interaction is r…

TwilightSICK AG · Sentio Creator Extension 'Device Manager'EPSS 0.23%via NVD
CVE-2026-73784High· 8.8
1w ago

A potential security vulnerability in HPE IceWall products could be exploited to tamper SAML response, allowing an attacker to impersonate another user.

A potential security vulnerability in HPE IceWall products could be exploited to tamper SAML response, allowing an attacker to impersonate another user.

TwilightHewlett Packard Enterprise · HPE IceWall productsEPSS 0.18%via NVD
CVE-2026-89086Critical· 9.1PoC
1w ago

In the jose package before 0.11.0 for OCaml, library calls to validate an RSA signature only confirm that PKCS #1 decoding succeeds, and proceed to declare the signature valid without the required steps that involve the public key.

In the jose package before 0.11.0 for OCaml, library calls to validate an RSA signature only confirm that PKCS #1 decoding succeeds, and proceed to declare the signature valid without the required steps that involve the public key.

AbyssalOCaml · joseEPSS 0.20%via NVD
CVE-2026-89042Critical· 9.1
1w ago

passport-saml-encrypted through 0.1.13 Authentication Bypass via Missing Signature Verification

passport-saml-encrypted through 0.1.13 makes SAML signature verification conditional on an optional cert option, allowing attackers to bypass authentication by submitting unsigned SAML responses. Attackers can post forged SAML responses …

Midnightkrakenjs · passport-saml-encryptedEPSS 0.27%via CVEORG
CVE-2026-89043High· 7.4PoC
1w ago

passport-saml-encrypted through 0.1.13 XML Signature Wrapping via Assertion Prepending

passport-saml-encrypted through 0.1.13 contains an XML signature wrapping vulnerability where signature verification and assertion extraction use independent XPath lookups with no cross-validation. Attackers holding any validly signed SA…

Midnightkrakenjs · passport-saml-encryptedEPSS 0.28%via CVEORG
CVE-2026-79970Medium· 5.6
1w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Verification of Cryptographic Signature vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Verification of Cryptographic Signature vulnerability. An unauthenticated attacker with remote access cou…

Sunlitdell · secure_connect_gatewayEPSS 0.11%via NVD
CVE-2023-54355High· 7.5
1w ago

PocketMine-MP versions before 5.3.1 and 4.23.1 fail to validate that the identityPublicKey in LoginPacket uses the required secp384r1 elliptic curve

PocketMine-MP versions before 5.3.1 and 4.23.1 fail to validate that the identityPublicKey in LoginPacket uses the required secp384r1 elliptic curve. Attackers can provide LoginPackets with keys using different curves or non-EC key types…

Twilightpmmp · PocketMine-MPEPSS 0.22%via NVD
CVE-2026-56207Critical· 9.8
1w ago

Apache Impala: SAML authentication bypass via forged bearer token

Signature of Bearer token is not verified in last step of SAML2 authentication for Impala's hs2-http interface, allowing altering user name and acting as another user. This issue affects Apache Impala: >=4.0.0. Users are recommende…

MidnightApache Software Foundation · Apache ImpalaEPSS 0.47%via CVEORG
CVE-2026-87732Medium· 6.2PoC
1w ago

An issue was discovered in the mirage-crypto package before 2.2.0 for OCaml

An issue was discovered in the mirage-crypto package before 2.2.0 for OCaml. The AES.GCM.authenticate_decrypt_into and Chacha20.authenticate_decrypt_into functions write the decrypted plaintext into a caller-provided buffer and only then…

TwilightOCaml · mirage-cryptoEPSS 0.08%via NVD
CWE-347 vulnerabilities (CVEs) · VulnSea