VulnSea

CWE-347

CVEs classified under CWE-347, newest first.

164 CVEsRSS

CVE-2026-54155High· 7.7
1w ago

node-opcua is an OPC UA implementation for TypeScript and Node.js

node-opcua is an OPC UA implementation for TypeScript and Node.js. Prior to 2.166.0, the UserNameIdentityToken authentication handler in packages/node-opcua-server/source/opcua_server.ts decrypts an RSA-OAEP password blob but does not ve…

▾ Twilightnode-opcua · node-opcuaEPSS 0.42%via NVD
CVE-2026-57122High· 8.6
1w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. Prior to 4.6.59, the WhatsApp and Linear bot webhook handlers verify HMAC signatures only when WHATSAPP_APP_SECRET or LINEAR_WEBHOOK_SECRET is configured and otherwise parse and dispatch unsigned …

▾ TwilightMervinPraison · PraisonAIEPSS 0.19%via NVD
CVE-2026-54248Medium· 6.5
2w ago

Doco-CD is a GitOps continuous delivery tool that automatically deploys and updates Docker Compose projects/services and Swarm stacks

Doco-CD is a GitOps continuous delivery tool that automatically deploys and updates Docker Compose projects/services and Swarm stacks. Prior to version 0.90.1, a trust-boundary flaw in OCI artifact verification allowed artifact-provided …

▾ Sunlitkimdre · doco-cdEPSS 0.40%via NVD
CVE-2026-89169Medium· 4.1
2w ago

live-boot ff8867c allows attackers to bypass the dm-verity-enforce-roothash-signature protection mechanism when the .verity file is missing.

live-boot ff8867c allows attackers to bypass the dm-verity-enforce-roothash-signature protection mechanism when the .verity file is missing.

▾ SunlitDebian · live-bootEPSS 0.15%via NVD
CVE-2026-80469High· 8.3
2w ago

An attacker may achieve arbitrary code execution on a target system by uploading a malicious device driver package, bypassing driver verification mechanisms, and triggering the execution of attacker-controlled code

An attacker may achieve arbitrary code execution on a target system by uploading a malicious device driver package, bypassing driver verification mechanisms, and triggering the execution of attacker-controlled code. User interaction is r…

▾ TwilightSICK AG · Sentio Creator Extension 'Device Manager'EPSS 0.39%via NVD
CVE-2026-73784High· 8.8
2w ago

A potential security vulnerability in HPE IceWall products could be exploited to tamper SAML response, allowing an attacker to impersonate another user.

A potential security vulnerability in HPE IceWall products could be exploited to tamper SAML response, allowing an attacker to impersonate another user.

▾ TwilightHewlett Packard Enterprise · HPE IceWall productsEPSS 0.30%via NVD
CVE-2026-89086Critical· 9.1PoC
2w ago

In the jose package before 0.11.0 for OCaml, library calls to validate an RSA signature only confirm that PKCS #1 decoding succeeds, and proceed to declare the signature valid without the required steps that involve the public key.

In the jose package before 0.11.0 for OCaml, library calls to validate an RSA signature only confirm that PKCS #1 decoding succeeds, and proceed to declare the signature valid without the required steps that involve the public key.

▾ AbyssalOCaml · joseEPSS 0.28%via NVD
CVE-2026-89042Critical· 9.1
2w ago

passport-saml-encrypted through 0.1.13 Authentication Bypass via Missing Signature Verification

passport-saml-encrypted through 0.1.13 makes SAML signature verification conditional on an optional cert option, allowing attackers to bypass authentication by submitting unsigned SAML responses. Attackers can post forged SAML responses …

▾ Midnightkrakenjs · passport-saml-encryptedEPSS 0.39%via CVEORG
CVE-2026-89043High· 7.4PoC
2w ago

passport-saml-encrypted through 0.1.13 XML Signature Wrapping via Assertion Prepending

passport-saml-encrypted through 0.1.13 contains an XML signature wrapping vulnerability where signature verification and assertion extraction use independent XPath lookups with no cross-validation. Attackers holding any validly signed SA…

▾ Midnightkrakenjs · passport-saml-encryptedEPSS 0.31%via CVEORG
CVE-2026-79970Medium· 5.6
2w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Verification of Cryptographic Signature vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Verification of Cryptographic Signature vulnerability. An unauthenticated attacker with remote access cou…

▾ Sunlitdell · secure_connect_gatewayEPSS 0.17%via NVD
CVE-2023-54355High· 7.5
2w ago

PocketMine-MP versions before 5.3.1 and 4.23.1 fail to validate that the identityPublicKey in LoginPacket uses the required secp384r1 elliptic curve

PocketMine-MP versions before 5.3.1 and 4.23.1 fail to validate that the identityPublicKey in LoginPacket uses the required secp384r1 elliptic curve. Attackers can provide LoginPackets with keys using different curves or non-EC key types…

▾ Twilightpmmp · PocketMine-MPEPSS 0.22%via NVD
CVE-2026-56207Critical· 9.8
2w ago

Apache Impala: SAML authentication bypass via forged bearer token

Signature of Bearer token is not verified in last step of SAML2 authentication for Impala's hs2-http interface, allowing altering user name and acting as another user. This issue affects Apache Impala: >=4.0.0. Users are recommende…

▾ MidnightApache Software Foundation · Apache ImpalaEPSS 0.46%via CVEORG
CVE-2026-87732Medium· 6.2PoC
2w ago

An issue was discovered in the mirage-crypto package before 2.2.0 for OCaml

An issue was discovered in the mirage-crypto package before 2.2.0 for OCaml. The AES.GCM.authenticate_decrypt_into and Chacha20.authenticate_decrypt_into functions write the decrypted plaintext into a caller-provided buffer and only then…

▾ TwilightOCaml · mirage-cryptoEPSS 0.11%via NVD
CVE-2026-86080Medium· 5.3
2w ago

n8n is an open source workflow automation platform

n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the GitHub Trigger generated a webhook secret but discarded it when GitHub returned HTTP 422 and the node reused an existing webhook. Workflow sta…

▾ Sunlitn8n · n8nEPSS 0.26%via NVD
CVE-2026-52486Medium· 6.6PoC
2w ago

An issue in OpenDDS 3.33.x allows a local attacker to cause a denial of service via the verify function in the SIgnedDocument module

An issue in OpenDDS 3.33.x allows a local attacker to cause a denial of service via the verify function in the SIgnedDocument module

▾ TwilightEPSS 0.09%via NVD
CVE-2026-28590High· 7.8
2w ago

In multiple locations, there is a possible improper encryption key validation due to a logic error in the code

In multiple locations, there is a possible improper encryption key validation due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not need…

▾ Twilightgoogle · androidEPSS 0.05%via NVD
CVE-2026-69646High· 8.3
2w ago

Improper verification of cryptographic signature in Skype for Business allows an unauthorized attacker to perform spoofing over an adjacent network.

Improper verification of cryptographic signature in Skype for Business allows an unauthorized attacker to perform spoofing over an adjacent network.

▾ Twilightmicrosoft · skype_for_business_serverEPSS 0.32%via NVD
CVE-2026-57098High· 7.5
2w ago

Improper verification of cryptographic signature in Windows RDP Client allows an unauthorized attacker to disclose information over a network.

Improper verification of cryptographic signature in Windows RDP Client allows an unauthorized attacker to disclose information over a network.

▾ Twilightmicrosoft · remote_desktop_clientEPSS 0.64%via NVD
CVE-2026-77105High· 8.8
2w ago

CommServe contained a cryptographic signature verification issue affecting privilege management

CommServe contained a cryptographic signature verification issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update CommServe and Web Server.

▾ Twilightcommvault · commvaultEPSS 0.30%via NVD
CVE-2026-14296High· 7.5
2w ago

When using the Direct XIP update strategy, the main application image starts other cores (i.e

When using the Direct XIP update strategy, the main application image starts other cores (i.e. radio core), based on the currently active slot without additional verification. The MCUboot in the bare (upstream) configuration assumes that…

▾ TwilightNordic Semiconductor ASA · nRF54H20EPSS 0.11%via NVD
CVE-2026-86304Critical· 9.8
3w ago

MojoX::Authentication versions before 0.006 for Perl allow SAML authentication bypass because parse_assertion builds Net::SAML2::Binding::POST without a trust anchor. parse_assertion in MojoX::Authentication::Model::SAML2 calls Net::SAM…

MojoX::Authentication versions before 0.006 for Perl allow SAML authentication bypass because parse_assertion builds Net::SAML2::Binding::POST without a trust anchor. parse_assertion in MojoX::Authentication::Model::SAML2 calls Net::SAM…

▾ MidnightEPSS 0.31%via NVD
CVE-2026-13608High· 7.4PoC⚖ disputed
3w ago

A flaw in the libcurl SASL negotiation for LDAP authentication allows an incomplete handshake sequence to be misinterpreted as a successful cryptographic verification

A flaw in the libcurl SASL negotiation for LDAP authentication allows an incomplete handshake sequence to be misinterpreted as a successful cryptographic verification. An attacker executing a Man-in-the-Middle (MITM) attack can inject a …

▾ Midnighthaxx · curlEPSS 0.48%via NVD
CVE-2026-67278Critical· 9.1PoC⚖ disputed
3w ago

MikroTik RouterOS accepts malformed RSA/PKCS#1 v1.5 signatures across RSA-based services, including TLS/X.509 certificate validation and SSH host-key authentication

MikroTik RouterOS accepts malformed RSA/PKCS#1 v1.5 signatures across RSA-based services, including TLS/X.509 certificate validation and SSH host-key authentication. Because its trust store includes an e=3 root CA, an attacker controllin…

▾ Abyssalmikrotik · routerosEPSS 0.28%via NVD
CVE-2026-67276High· 8.1PoC
3w ago

RouterOS does not compare the complete RSA public key when matching an SSH authentication request to an authorized user key, checking the key type and modulus but omitting the exponent

RouterOS does not compare the complete RSA public key when matching an SSH authentication request to an authorized user key, checking the key type and modulus but omitting the exponent. Because signature verification uses the client-supp…

▾ Midnightmikrotik · routerosEPSS 0.37%via NVD
CVE-2026-52767High· 8.2PoC
3w ago

YesWiki is a wiki system written in PHP

YesWiki is a wiki system written in PHP. From version 4.6.2 to before version 4.6.6, HttpSignatureService::verifySignature() checks the result of PHP's openssl_verify() with a loose boolean negation - if (!openssl_verify(...)) { throw ..…

▾ MidnightYesWiki · yeswikiEPSS 0.35%via NVD
CVE-2026-79389High· 7.4
3w ago

Trueview T18161 S 6.0.23.4 contains an improper verification in MQTT command processing

Trueview T18161 S 6.0.23.4 contains an improper verification in MQTT command processing. An attacker with network access can replay or modify captured MQTT messages, including security-related nonce, timestamp, and signature fields, and …

▾ TwilightEPSS 0.21%via NVD
CVE-2026-85525High· 7.4
3w ago

Improper OCSP response validation in the Snowflake Python, Go, JDBC, and Node.js drivers allowed a revoked TLS certificate to be accepted as valid, because OCSP responses were not reliably bound to the certificate being validated and def…

Improper OCSP response validation in the Snowflake Python, Go, JDBC, and Node.js drivers allowed a revoked TLS certificate to be accepted as valid, because OCSP responses were not reliably bound to the certificate being validated and def…

▾ TwilightSnowflake · snowflake-connector-pythonEPSS 0.16%via NVD
CVE-2026-85393High· 7.5
3w ago

node-forge through 1.4.0 fails to validate element count in nested DigestAlgorithm sequences during RSA PKCS#1 v1.5 signature verification

node-forge through 1.4.0 fails to validate element count in nested DigestAlgorithm sequences during RSA PKCS#1 v1.5 signature verification. Attackers can embed garbage bytes inside the DigestAlgorithm sequence to forge valid signatures f…

▾ TwilightEPSS 0.33%via NVD
CVE-2026-85394Critical· 9.1
3w ago

python-jose through 3.5.0 fails to properly validate asymmetric keys in HMAC initialization, accepting DER-encoded public keys that lack PEM armor or SSH prefixes

python-jose through 3.5.0 fails to properly validate asymmetric keys in HMAC initialization, accepting DER-encoded public keys that lack PEM armor or SSH prefixes. Attackers holding the service's public key can forge HS256 tokens that pa…

▾ Midnightmpdavis · python-joseEPSS 0.35%via NVD
CVE-2026-84185Medium· 5.9
3w ago

A flaw was found in the jwcrypto library, which is used for implementing Javascript Object Signing and Encryption (JOSE) standards

A flaw was found in the jwcrypto library, which is used for implementing Javascript Object Signing and Encryption (JOSE) standards. The issue occurs when the library verifies a General JSON Serialization JWS using a set of keys. Due to a…

▾ SunlitEPSS 0.13%via NVD
CWE-347 vulnerabilities (CVEs) — page 2 · VulnSea