VulnSea

CWE-347

CVEs classified under CWE-347, newest first.

164 CVEsRSS

CVE-2026-80465High· 8.7
3w ago

A vulnerability has been identified in Mendix SAML (Mendix 10 compatible) (All versions < V4.2.3), Mendix SAML (Mendix 11 compatible) (All versions < V4.2.3), Mendix SAML (Mendix 9.24 compatible) (All versions < V3.6.27)

A vulnerability has been identified in Mendix SAML (Mendix 10 compatible) (All versions < V4.2.3), Mendix SAML (Mendix 11 compatible) (All versions < V4.2.3), Mendix SAML (Mendix 9.24 compatible) (All versions < V3.6.27). Affected versio…

▾ TwilightEPSS 0.28%via NVD
CVE-2026-80098Critical· 9.3
3w ago

Improper verification of cryptographic signature in Copilot Studio allows an unauthorized attacker to elevate privileges over a network.

Improper verification of cryptographic signature in Copilot Studio allows an unauthorized attacker to elevate privileges over a network.

▾ Midnightmicrosoft · copilot_studioEPSS 0.49%via NVD
CVE-2026-82876High· 8.2PoC
3w ago

Phison PS3111-S11 controller firmware verifies RSA signatures using a public modulus embedded within the firmware image itself rather than anchored in immutable storage

Phison PS3111-S11 controller firmware verifies RSA signatures using a public modulus embedded within the firmware image itself rather than anchored in immutable storage. Attackers can generate arbitrary RSA key pairs, sign modified firmw…

▾ MidnightPhison Electronics Corporation · PS3111-S11 Controller FirmwareEPSS 0.12%via NVD
CVE-2026-82645High· 8.6
4w ago

AVideo (current commit e01e41ecc and earlier) exposes stream credentials through the plugin/Live/view/Live_restreams/getLiveKey.json.php endpoint

AVideo (current commit e01e41ecc and earlier) exposes stream credentials through the plugin/Live/view/Live_restreams/getLiveKey.json.php endpoint. Supplying a 'token' request parameter waives both the Live::canRestream() access gate and …

▾ TwilightEPSS 0.20%via NVD
CVE-2026-75759None
4w ago

Improper Verification of Cryptographic Signature vulnerability in erlef oidcc allows an unauthenticated attacker to impersonate an arbitrary user via an encrypted ID token or JARM response carrying no nested signature

Improper Verification of Cryptographic Signature vulnerability in erlef oidcc allows an unauthenticated attacker to impersonate an arbitrary user via an encrypted ID token or JARM response carrying no nested signature. OpenID Connect Cor…

▾ SunlitEPSS 0.22%via NVD
CVE-2026-82461High· 8.1
4w ago

pac4j-oidc before 6.5.6 fails to verify access token signatures, issuers, audiences, or expiry when extracting Keycloak realm and client roles

pac4j-oidc before 6.5.6 fails to verify access token signatures, issuers, audiences, or expiry when extracting Keycloak realm and client roles. Attackers can forge access tokens with administrative roles paired with valid ID tokens to by…

▾ TwilightEPSS 0.32%via NVD
CVE-2026-82454Critical· 9.1
4w ago

The Omnivore API (packages/api) before the fix in commit abf53d6 contains an authentication bypass in Apple sign-in token verification

The Omnivore API (packages/api) before the fix in commit abf53d6 contains an authentication bypass in Apple sign-in token verification. The decodeAppleToken function extracted the 'alg' field from the attacker-supplied JWT header and pas…

▾ Midnightomnivore-app · omnivoreEPSS 0.39%via NVD
CVE-2026-54330High· 8.1
1mo ago

Ceph is an open-source distributed storage platform providing object, block, and file storage

Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2.4 and 19.2.6, the Ceph Object Gateway (RGW) SigV4 handler does not reject requests that carry x-amz-* headers absent…

▾ TwilightEPSS 0.37%via NVD
GHSA-73p9-6hrp-8qhrMedium
1mo ago

AIIR verification and policy gates could report success without enforcing the control (fail-open)

AIIR verification and policy gates could report success without enforcing the control (fail-open)

▾ Sunlitaiir · aiirvia GHSA
CVE-2026-57910Critical· 9.3
1mo ago

Improper authentication in the WatchGuard Agent allows an unauthenticated attacker with network access to cause the agent to execute arbitrary code with elevated privileges.

Improper authentication in the WatchGuard Agent allows an unauthenticated attacker with network access to cause the agent to execute arbitrary code with elevated privileges.

▾ MidnightWatchGuard · WatchGuard AgentEPSS 0.24%via NVD
CVE-2026-72861Medium· 5.8
1mo ago

The github-issue-bot templates in appwrite/templates verify the GitHub webhook signature with an inverted condition

The github-issue-bot templates in appwrite/templates verify the GitHub webhook signature with an inverted condition. verifyWebhook in node/github-issue-bot/src/github.js and in node-typescript/github-issue-bot/src/github.ts returns "type…

▾ Sunlitappwrite · templatesEPSS 0.27%via NVD
CVE-2026-62834Critical· 9.3
1mo ago

Azure Data Factory Elevation of Privilege Vulnerability

Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized attacker to elevate privileges over a network.

▾ MidnightMicrosoft · Azure Data FactoryEPSS 0.53%via CVEORG
CVE-2026-50719Medium· 6.8
1mo ago

The Ingenic T41, and probably also T32, T40, and A1 SoC boot ROMs parse and execute an attacker-controlled init table from the SPL header before checking the secure boot state and before invoking signature verification

The Ingenic T41, and probably also T32, T40, and A1 SoC boot ROMs parse and execute an attacker-controlled init table from the SPL header before checking the secure boot state and before invoking signature verification. The init table pa…

▾ SunlitEPSS 0.15%via NVD
CVE-2026-50720Medium· 6.4
1mo ago

The Ingenic T31 SoC boot ROM flash-boot verification path compares only a single 32-bit word of the RSA signature output against a single 32-bit word of the SHA-256 payload digest, rather than compare the full data

The Ingenic T31 SoC boot ROM flash-boot verification path compares only a single 32-bit word of the RSA signature output against a single 32-bit word of the SHA-256 payload digest, rather than compare the full data. This allows an attack…

▾ SunlitEPSS 0.13%via NVD
CVE-2026-76234High· 7.5
1mo ago

libcrux-ecdh and libcrux-ed25519 before 0.0.6, and libcrux-psq before 0.0.7, contain cryptographic implementation bugs

libcrux-ecdh and libcrux-ed25519 before 0.0.6, and libcrux-psq before 0.0.7, contain cryptographic implementation bugs. libcrux-ecdh did not properly check length and clamping during X25519 secret validation (and had a broken clamping ch…

▾ Twilightlibcrux-ecdh · libcrux-ecdhEPSS 0.31%via NVD
CVE-2021-43716Critical· 9.8PoC
1mo ago

Verification Bypass vulnerability exists in EPSON 150075647YWWV110 EasyMP Network Updater Ver.1.20

Verification Bypass vulnerability exists in EPSON 150075647YWWV110 EasyMP Network Updater Ver.1.20. The Epson projector can be updated by encrypted firmware through USB.

▾ AbyssalEPSS 0.34%via NVD
CVE-2026-55165Medium· 4.8
1mo ago

Lemur manages TLS certificate creation

Lemur manages TLS certificate creation. Prior to 1.9.2, the JWT verifier in lemur/auth/service.py:130-137 used fetch_token_header to read header_data["alg"] from an unverified token and passed that attacker-controlled value to decode_wit…

▾ Sunlitlemur · lemurEPSS 0.15%via NVD
GHSA-fhgh-wq4q-r37xHigh· 7.8
1mo ago

uniget CLI: Metadata signature verification only runs when UNIGET_IGNORE_METADATA_SIGNATURE is set

uniget CLI: Metadata signature verification only runs when UNIGET_IGNORE_METADATA_SIGNATURE is set

▾ Twilightuniget-org · gitlab.com/uniget-org/clivia GHSA
CVE-2026-18500High· 8.1
1mo ago

@fastify/jwt is a JSON Web Token plugin for Fastify

@fastify/jwt is a JSON Web Token plugin for Fastify. In versions before 10.2.2, a per-request verification key passed to request.jwtVerify({ key }) is silently overridden by the plugin's globally configured secret, because the option mer…

▾ TwilightEPSS 0.26%via NVD
CVE-2026-47191Low
1mo ago

kas is a setup tool for bitbake based projects

kas is a setup tool for bitbake based projects. Prior to version 5.3, when relying solely on a git commit ID (SHA-1 or SHA-256) to qualify if a checkout of a repository is equivalent to the state validated while adding its commit ID to a…

▾ Sunlitkas · kasEPSS 0.25%via NVD
CVE-2026-47192Low
1mo ago

kas is a setup tool for bitbake based projects

kas is a setup tool for bitbake based projects. Starting in version 4.8 and prior to version 5.3, kas checks out and processes repositories regarding configuration includes prior to validating signatures of those repositories. This may a…

▾ Sunlitkas · kasEPSS 0.25%via NVD
CVE-2026-56865High· 8.8
1mo ago

golang.org/x/mod/sumdb/tlog: golang.org/x/mod/sumdb/tlog: Supply chain compromise via transparency log tile verification bypass (CVE-2026-5…

A flaw was found in golang.org/x/mod/sumdb/tlog. A malicious Go proxy (GOPROXY) could exploit this vulnerability by forging sumdb tiles. This allowed the proxy to bypass integrity checks and serve malicious module content to a local Go mod…

▾ TwilightRed Hat · Red Hat Advanced Cluster Security for Kubernetes 4.11EPSS 0.14%via CSAF
CVE-2026-48791Low· 2.0
1mo ago

sigstore-java is a sigstore java client for interacting with sigstore infrastructure

sigstore-java is a sigstore java client for interacting with sigstore infrastructure. Version 2.0.0 erroneously removed verification of the integrated (Rekor entry) time) against the Fulcio certificate. Version 2.1.0 re-added this verifi…

▾ Sunlitsigstore · dev.sigstore:sigstore-javaEPSS 0.07%via NVD
CVE-2026-68759High· 7.2
1mo ago

A holder of a valid integration credential may impersonate other users under specific conditions.

A holder of a valid integration credential may impersonate other users under specific conditions.

▾ TwilightEPSS 0.33%via NVD
CVE-2026-68757High· 7.5
1mo ago

A user with access to a valid SAML response may impersonate another user under specific conditions.

A user with access to a valid SAML response may impersonate another user under specific conditions.

▾ TwilightEPSS 0.27%via NVD
CVE-2026-15556High· 8.1
1mo ago

A flaw was found in Picketlink's SP signature validation; a SAML response containing zero assertion elements matching the signature check can allow an attacker to forge a SAML response and auth as any principal with any roles on the prot…

A flaw was found in Picketlink's SP signature validation; a SAML response containing zero assertion elements matching the signature check can allow an attacker to forge a SAML response and auth as any principal with any roles on the prot…

▾ TwilightRed Hat · org.picketlink/picketlink-federationEPSS 0.24%via NVD
CVE-2026-10579Critical· 9.8
1mo ago

A flaw was found in Picketlink Federation SAML; the unsolcited response handler would accept forged assertions with no verification or validation, permitting an unauthed attacker to authenticate as any principal in any role

A flaw was found in Picketlink Federation SAML; the unsolcited response handler would accept forged assertions with no verification or validation, permitting an unauthed attacker to authenticate as any principal in any role. This could l…

▾ MidnightRed Hat · org.picketlink/picketlink-federationEPSS 0.32%via NVD
CVE-2026-66776Medium· 5.9
1mo ago

SAP Approuter does not consistently enforce integrity verification on certain session-related request headers under specific conditions

SAP Approuter does not consistently enforce integrity verification on certain session-related request headers under specific conditions. An attacker with low privileges could send a specially crafted request that bypasses the integrity c…

▾ Sunlitsap · approuterEPSS 0.20%via NVD
CVE-2026-62757Medium· 5.3
1mo ago

Windows Schannel Security Feature Bypass Vulnerability

Improper verification of cryptographic signature in Windows Schannel allows an unauthorized attacker to bypass a security feature over a network.

▾ SunlitMicrosoft · Windows 10 Version 1607EPSS 0.35%via CVEORG
CVE-2026-10754None
1mo ago

Pega Platform versions 8.5.0 through 25.1.2 are affected by an improper validation of cryptographic signatures that may allow an attacker to bypass security controls.

Pega Platform versions 8.5.0 through 25.1.2 are affected by an improper validation of cryptographic signatures that may allow an attacker to bypass security controls.

▾ SunlitEPSS 0.78%via NVD
CWE-347 vulnerabilities (CVEs) — page 3 · VulnSea