VulnSea

CWE-347

CVEs classified under CWE-347, newest first.

164 CVEsRSS

CVE-2026-58262None
1mo ago

Klever-Go is the Go implementation of the Klever blockchain protocol

Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, header signature verification counts the unused padding bits of the PubKeysBitmap toward the two-thirds validator quorum. These padding bits do not co…

▾ SunlitEPSS 0.16%via NVD
CVE-2026-5430Critical· 10.0CISA KEVPoC
1mo ago

The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported

The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker to craft a JWT with an unsupported algorithm, which is then incorrectly validated, leadin…

▾ Hadalwso2 · api_control_planeEPSS 0.58%via NVD
CVE-2026-62918High· 7.5
1mo ago

Microsoft Teams Spoofing Vulnerability

Improper verification of cryptographic signature in Microsoft Teams allows an unauthorized attacker to perform spoofing over a network.

▾ TwilightMicrosoft · Microsoft TeamsEPSS 0.50%via CVEORG
CVE-2026-62873Critical· 9.8
1mo ago

Microsoft 365 Admin Center Elevation of Privilege Vulnerability

Improper verification of cryptographic signature in Microsoft 365 Admin Center allows an unauthorized attacker to elevate privileges over a network.

▾ MidnightMicrosoft · Microsoft 365 Admin CenterEPSS 0.61%via CVEORG
CVE-2026-7557Critical· 9.1
1mo ago

An improper verification of cryptographic signature vulnerability in the SAML authentication module of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass authentication and impersonate …

An improper verification of cryptographic signature vulnerability in the SAML authentication module of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass authentication and impersonate …

▾ MidnightEPSS 0.46%via NVD
CVE-2026-46713None
1mo ago

Misskey is an open source, federated social media platform

Misskey is an open source, federated social media platform. Versions 12.37.0 and later, but prior to 2026.5.4, contain a vulnerability in the JSON-LD signature validation and compaction process that allows spoofed activities to be accept…

▾ SunlitEPSS 0.28%via NVD
CVE-2026-59643High· 7.5
1mo ago

In Bouncy Castle for Java before 1.85, OpenPGP inline-signature policy failures silently ignored

In Bouncy Castle for Java before 1.85, OpenPGP inline-signature policy failures silently ignored. This issue also affects Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips 2.0.13.

▾ Twilightbouncycastle · bc-javaEPSS 0.24%via NVD
CVE-2026-59639High· 7.5
1mo ago

In Bouncy Castle for Java before 1.85, CMS verifySignatures returns true for SignedData with zero signers

In Bouncy Castle for Java before 1.85, CMS verifySignatures returns true for SignedData with zero signers. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0…

▾ TwilightRed Hat · Red Hat Ceph Storage 9EPSS 0.24%via NVD
CVE-2026-55735None
1mo ago

Improper Verification of Cryptographic Signature in ueberauth guardian allows an unauthenticated attacker to revoke a victim's session with a forged token. Guardian.revoke/3 in lib/guardian.ex decodes the supplied token with peek/1, whi…

Improper Verification of Cryptographic Signature in ueberauth guardian allows an unauthenticated attacker to revoke a victim's session with a forged token. Guardian.revoke/3 in lib/guardian.ex decodes the supplied token with peek/1, whi…

▾ SunlitEPSS 0.46%via NVD
CVE-2025-71402None
1mo ago

better-auth versions greater than 1.3.34 and before 1.4.0 contain a vulnerability in the multi-session plugin's /sign-out after-hook, which trusts raw multi-session cookies and forwards extracted values to internalAdapter.deleteSessions …

better-auth versions greater than 1.3.34 and before 1.4.0 contain a vulnerability in the multi-session plugin's /sign-out after-hook, which trusts raw multi-session cookies and forwards extracted values to internalAdapter.deleteSessions …

▾ SunlitEPSS 0.27%via NVD
CVE-2026-53501High· 8.2
1mo ago

Thumbor is an open-source photo thumbnail service by globo.com

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor’s HMAC validation can be bypassed due to the use of Python’s .replace() when removing the signature from the URL before validation. Since .replace() …

▾ Twilightthumbor · thumborEPSS 0.35%via NVD
CVE-2026-59243Critical· 9.8PoC
2mo ago

The FAB auth manager's Azure AD OAuth login defaulted `verify_signature=False` when decoding the ID token, so an attacker able to present a forged or unsigned (`alg:none`) ID token to the OAuth callback could bypass authentication and lo…

The FAB auth manager's Azure AD OAuth login defaulted `verify_signature=False` when decoding the ID token, so an attacker able to present a forged or unsigned (`alg:none`) ID token to the OAuth callback could bypass authentication and lo…

▾ Abyssalapache · apache-airflow-providers-fabEPSS 0.64%via NVD
CVE-2026-58426Critical· 9.6
2mo ago

Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write

Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write

▾ Midnightgitea · code.gitea.io/giteaEPSS 0.30%via GHSA
CVE-2026-49834Medium· 5.9
2mo ago

github.com/sigstore/sigstore-go: sigstore-go: Security Policy Bypass via Compromised Log (CVE-2026-49834)

A flaw was found in sigstore-go, a Go library for Sigstore signing and verification. This vulnerability allows a single compromised transparency log or Certificate Transparency (CT) log to bypass the multi-log threshold requirements. An at…

▾ SunlitRed Hat · Red Hat Trusted Artifact SignerEPSS 0.18%via CSAF
CVE-2026-15013Critical· 9.8PoC
2mo ago

The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass via SAML Signature Algorithm Confusion in all versions up to, and including, 5.4.3

The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass via SAML Signature Algorithm Confusion in all versions up to, and including, 5.4.3. The vulnerability exists because `Mo_SAML_Utilities::mo_s…

▾ AbyssalEPSS 1.5%via NVD
CVE-2026-46684None
2mo ago

DataEase is an open source data visualization and analysis tool

DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase enterprise token handling can let TokenFilter#doFilter() pass X-DE-TOKEN values to TokenUtils.validate(), which checks only token presence and le…

▾ SunlitEPSS 0.32%via NVD
CVE-2026-15265Critical· 9.1
2mo ago

A path traversal vulnerability in Tenable Agent 11.2.0 and 11.1.3 and lower allows a privileged attacker to write arbitrary files outside the intended plugin directory, potentially leading to remote code execution.

A path traversal vulnerability in Tenable Agent 11.2.0 and 11.1.3 and lower allows a privileged attacker to write arbitrary files outside the intended plugin directory, potentially leading to remote code execution.

▾ Midnighttenable · nessus_agentEPSS 0.56%via NVD
CVE-2026-47304High· 8.1
2mo ago

.NET Security Feature Bypass Vulnerability

Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.

▾ TwilightMicrosoft · .NET 10.0EPSS 0.29%via CVEORG
CVE-2026-54736None
2mo ago

Phalcon is a high-performance, full-stack PHP framework

Phalcon is a high-performance, full-stack PHP framework. Prior to 5.14.1, Phalcon\Encryption\Crypt::decrypt compares the attacker-supplied HMAC tag against the freshly computed HMAC using PHP/Zephir identity comparison, which lowers to a…

▾ SunlitEPSS 0.18%via NVD
CVE-2026-9547High· 7.4PoC
2mo ago

When a libcurl-based application performs transfers via `SCP://` or `SFTP://` and utilizes the `CURLOPT_SSH_KEYFUNCTION` callback, it may silently accept an untrusted server

When a libcurl-based application performs transfers via `SCP://` or `SFTP://` and utilizes the `CURLOPT_SSH_KEYFUNCTION` callback, it may silently accept an untrusted server. This vulnerability occurs when a server presents a host key ty…

▾ Midnighthaxx · curlEPSS 0.51%via NVD
CVE-2026-49998High· 8.2
2mo ago

Centrifugo's dynamic JWKS key cache keyed only by `kid` allows cross-issuer JWT authentication bypass

Centrifugo's dynamic JWKS key cache keyed only by `kid` allows cross-issuer JWT authentication bypass

▾ Twilightcentrifugal · github.com/centrifugal/centrifugo/v6EPSS 0.27%via GHSA
CVE-2026-48815Medium· 5.9
2mo ago

sigstore: Sigstore: Unauthorized certificates accepted due to ignored `certificateOIDs` verification option (CVE-2026-48815)

A flaw was found in sigstore. The `certificateOIDs` option, intended to restrict which certificates can sign artifacts, is accepted by the public application programming interface (API) but is not used during the verification process. This…

▾ SunlitRed Hat · Red Hat Enterprise Linux 8EPSS 0.19%via CSAF
CVE-2025-0824Low· 3.7
3mo ago

Lack of validation for firmware update in Hitachi Hitachi Virtual Storage Platform One Block 23, 24, 26, 28. This issue affects Hitachi Virtual Storage Platform One Block 23, 24, 26, 28: before DKCMAIN A3-04-21-40/00, ESM A3-04-21/00.

Lack of validation for firmware update in Hitachi Hitachi Virtual Storage Platform One Block 23, 24, 26, 28. This issue affects Hitachi Virtual Storage Platform One Block 23, 24, 26, 28: before DKCMAIN A3-04-21-40/00, ESM A3-04-21/00.

▾ SunlitEPSS 0.13%via NVD
CVE-2026-48758Medium· 5.4
3mo ago

@sigstore/core has DSSE payloadType type-binding failure

@sigstore/core has DSSE payloadType type-binding failure

▾ Sunlitsigstore · @sigstore/coreEPSS 0.26%via GHSA
CVE-2026-49454Critical· 9.1
3mo ago

Relyra SAML SignatureValue not cryptographically verified -> authentication bypass

Relyra SAML SignatureValue not cryptographically verified -> authentication bypass

▾ Midnightrelyra · relyraEPSS 0.23%via GHSA
CVE-2026-46560High· 7.5
3mo ago

OpenAM: Unauthenticated Authentication Bypass via RADIUS Spoofing

OpenAM: Unauthenticated Authentication Bypass via RADIUS Spoofing

▾ Twilightopenidentityplatform · org.openidentityplatform.openam:openam-radiusvia GHSA
GHSA-qxvg-h7q2-hcxhCritical· 9.8
3mo ago

motionEye: LFI → pass‑the‑hash admin → unsafe restore → unauth action exec (RCE)

motionEye: LFI → pass‑the‑hash admin → unsafe restore → unauth action exec (RCE)

▾ Midnightmotioneye · motioneyevia GHSA
CVE-2026-54773Medium· 5.9
3mo ago

CoreWCF: WS-Security signature substitution via document-wide Signature lookup

CoreWCF: WS-Security signature substitution via document-wide Signature lookup

▾ SunlitCoreWCF · CoreWCF.PrimitivesEPSS 0.37%via GHSA
CVE-2026-54774High· 7.4
3mo ago

CoreWCF: SamlSerializer skips SignatureValue verification when SAML signing token is not an X.509 certificate

CoreWCF: SamlSerializer skips SignatureValue verification when SAML signing token is not an X.509 certificate

▾ TwilightCoreWCF · CoreWCF.PrimitivesEPSS 0.20%via GHSA
CVE-2026-54782Critical· 10.0
3mo ago

CoreWCF: Authentication bypass in CoreWCF SAML 1.1 / 2.0 token signature validation

CoreWCF: Authentication bypass in CoreWCF SAML 1.1 / 2.0 token signature validation

▾ MidnightCoreWCF · CoreWCF.PrimitivesEPSS 0.41%via GHSA
CWE-347 vulnerabilities (CVEs) — page 4 · VulnSea