VulnSea

CWE-347

CVEs classified under CWE-347, newest first.

165 CVEsRSS

CVE-2026-32597High· 7.5PoC
6mo ago

PyJWT is a JSON Web Token implementation in Python

PyJWT is a JSON Web Token implementation in Python. Prior to 2.12.0, PyJWT does not validate the crit (Critical) Header Parameter defined in RFC 7515 §4.1.11. When a JWS token contains a crit array listing extensions that PyJWT does not …

▾ Midnightpyjwt_project · pyjwtEPSS 0.28%via NVD
CVE-2026-28802Critical· 9.8⚖ disputed
6mo ago

Authlib is a Python library which builds OAuth and OpenID Connect servers

Authlib is a Python library which builds OAuth and OpenID Connect servers. From version 1.6.5 to before version 1.6.7, previous tests involving passing a malicious JWT containing alg: none and an empty signature was passing the signature…

▾ Midnightauthlib · authlibEPSS 0.55%via NVD
CVE-2025-12150Low· 3.1
7mo ago

A flaw was found in Keycloak’s WebAuthn registration component

A flaw was found in Keycloak’s WebAuthn registration component. This vulnerability allows an attacker to bypass the configured attestation policy and register untrusted or forged authenticators via submission of an attestation object wit…

▾ Sunlitredhat · build_of_keycloakEPSS 0.21%via NVD
CVE-2026-1529High· 8.1PoC
7mo ago

A flaw was found in Keycloak

A flaw was found in Keycloak. An attacker can exploit this vulnerability by modifying the organization ID and target email within a legitimate invitation token's JSON Web Token (JWT) payload. This lack of cryptographic signature verifica…

▾ MidnightEPSS 0.46%via NVD
CVE-2025-65295High· 8.1
9mo ago

Multiple vulnerabilities in Aqara Hub firmware update process in the Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 devices, allow attackers to install malicious firmware without proper verification

Multiple vulnerabilities in Aqara Hub firmware update process in the Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 devices, allow attackers to install malicious firmware without proper verification. The device fails …

▾ Twilightaqara · hub_m2_firmwareEPSS 0.23%via NVD
CVE-2025-64787Low· 3.3
9mo ago

Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and earlier are affected by an Improper Verification of Cryptographic Signature vulnerability that could result in a Security feature bypass

Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and earlier are affected by an Improper Verification of Cryptographic Signature vulnerability that could result in a Security feature bypass. An…

▾ Sunlitadobe · acrobatEPSS 0.45%via NVD
CVE-2025-64786Low· 3.3
9mo ago

Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and earlier are affected by an Improper Verification of Cryptographic Signature vulnerability that could result in a Security feature bypass

Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and earlier are affected by an Improper Verification of Cryptographic Signature vulnerability that could result in a Security feature bypass. An…

▾ Sunlitadobe · acrobatEPSS 0.43%via NVD
CVE-2025-65945High· 7.5PoC
9mo ago

auth0/node-jws is a JSON Web Signature implementation for Node.js

auth0/node-jws is a JSON Web Signature implementation for Node.js. In versions 3.2.2 and earlier and version 4.0.0, auth0/node-jws has an improper signature verification vulnerability when using the HS256 algorithm under specific conditi…

▾ Midnightauth0 · node-jwsEPSS 0.21%via NVD
CVE-2025-20248Medium· 6.0
1y ago

A vulnerability in the installation process of Cisco IOS XR Software could allow an authenticated, local attacker to bypass Cisco IOS XR Software image signature verification and load unsigned software on an affected device

A vulnerability in the installation process of Cisco IOS XR Software could allow an authenticated, local attacker to bypass Cisco IOS XR Software image signature verification and load unsigned software on an affected device. To exploit t…

▾ Sunlitcisco · ios_xrEPSS 0.10%via NVD
CVE-2024-49394Medium· 5.3
1y ago

In mutt and neomutt the In-Reply-To email header field is not protected by cryptographic signing which allows an attacker to reuse an unencrypted but signed email message to impersonate the original sender.

In mutt and neomutt the In-Reply-To email header field is not protected by cryptographic signing which allows an attacker to reuse an unencrypted but signed email message to impersonate the original sender.

▾ Sunlitmutt · muttEPSS 0.33%via NVD
CVE-2024-49393Medium· 6.5
1y ago

In neomutt and mutt, the To and Cc email headers are not validated by cryptographic signing which allows an attacker that intercepts a message to change their value and include himself as a one of the recipients to compromise message con…

In neomutt and mutt, the To and Cc email headers are not validated by cryptographic signing which allows an attacker that intercepts a message to change their value and include himself as a one of the recipients to compromise message con…

▾ Sunlitmutt · muttEPSS 0.33%via NVD
CVE-2024-8698High· 7.7PoC
2y ago

A flaw exists in the SAML signature validation method within the Keycloak XMLSignatureUtil class

A flaw exists in the SAML signature validation method within the Keycloak XMLSignatureUtil class. The method incorrectly determines whether a SAML signature is for the full document or only for specific assertions based on the position o…

▾ MidnightEPSS 2.0%via NVD
CVE-2024-23680Medium· 5.3
2y ago

AWS Encryption SDK for Java versions 2.0.0 to 2.2.0 and less than 1.9.0 incorrectly validates some invalid ECDSA signatures.

AWS Encryption SDK for Java versions 2.0.0 to 2.2.0 and less than 1.9.0 incorrectly validates some invalid ECDSA signatures.

▾ Sunlitamazon · aws_encryption_sdkEPSS 0.21%via NVD
CVE-2020-3308Medium· 4.9
6y ago

A vulnerability in the Image Signature Verification feature of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker with administrator-level credentials to install a malicious software patch on an a…

A vulnerability in the Image Signature Verification feature of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker with administrator-level credentials to install a malicious software patch on an a…

▾ Sunlitcisco · secure_firewall_threat_defenseEPSS 0.60%via NVD
CVE-2020-3138Medium· 6.7
6y ago

A vulnerability in the upgrade component of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to install a malicious file when upgrading

A vulnerability in the upgrade component of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to install a malicious file when upgrading. The vulnerability is due to insufficient signature …

▾ Sunlitcisco · enterprise_nfv_infrastructure_softwareEPSS 0.21%via NVD
CWE-347 vulnerabilities (CVEs) — page 6 · VulnSea