CWE-347
Improper Verification of Cryptographic Signature
The product does not verify, or incorrectly verifies, the cryptographic signature for data.
742 vulnerabilities with CWE-347
CVE-2026-21002
MEDIUM
Samsung Galaxy Store <4.6.03.8 - Auth Bypass
CVSS 5.5
CVE-2026-20997
CRITICAL
Samsung Mobile Smart Switch <3.7.69.15 - Auth Bypass
CVSS 9.8
CVE-2026-20989
LOW
Samsung Mobile Devices - Auth Bypass
CVSS 2.4
CVE-2026-32597
HIGH
PyJWT < 2.12.0 - Insufficient Verification of Data Authenticity via crit Header Parameter
CVSS 7.5
CVE-2026-28432
HIGH
Misskey < 2026.3.1 - HTTP Signature Verification Bypass
CVSS 7.5
CVE-2026-3706
LOW
Dropbear <=2025.89 - Improper Signature Verification
CVSS 3.7
CVE-2026-28802
CRITICAL
Authlib 1.6.5-1.6.6 - Improper Verification of Cryptographic Signature
CVSS 9.8
CVE-2026-29000
CRITICAL
pac4j-jwt <4.5.9/5.7.9/6.3.3 - Auth Bypass
CVSS 9.1
CVE-2026-2746
MEDIUM
SEPPmail Secure Email Gateway <15.0.1 - Info Disclosure
CVSS 5.3
CVE-2026-27445
MEDIUM
SEPPmail Secure Email Gateway <15.0.1 - Auth Bypass
CVSS 5.3
CVE-2026-3338
HIGH
AWS-LC < 1.69.0 - Improper Verification of Cryptographic Signature in PKCS7_verify()
CVSS 7.5
CVE-2026-22866
HIGH
Ethereum Name Service (ENS) <=1.6.2 - Auth Bypass
CVSS 7.5
CVE-2026-2968
LOW
Cesanta Mongoose <=7.20 - Auth Bypass
CVSS 3.7
CVE-2026-25922
HIGH
authentik <2025.8.6, 2025.10.4, 2025.12.4 - SSRF
CVSS 8.8
CVE-2026-23687
HIGH
SAP NetWeaver Application Server ABAP/ABAP Platform - Privilege Esc...
CVSS 8.8
CVE-2026-1529
HIGH
Keycloak 26.5.0-26.5.2 - Unauthenticated Organization Access via JWT Invitation Token Tampering
CVSS 8.1
CVE-2026-25793
HIGH
Nebula 1.7.0-1.10.2 - Blocklist Bypass via ECDSA Signature Malleability
CVSS 8.1
CVE-2026-1568
CRITICAL
Rapid7 InsightVM <8.34.0 - Privilege Escalation
CVSS 9.6
CVE-2026-0750
HIGH
Drupal Commerce Paybox 7.x-1.0-7.x-1.5 - Authentication Bypass via Improper Cryptographic Signature Verification
CVSS 7.5
CVE-2026-1237
LOW
juju - Improper Verification of Cryptographic Signature in Cross-Model Authorization
CVE-2026-24850
MEDIUM
ml-dsa 0.0.4-0.1.0-rc.3 - Improper Verification of Cryptographic Signature via Duplicate Hint Indices
CVSS 5.3
CVE-2026-24807
MEDIUM
liuyueyi quick-media < v1.0 - Improper Verification of Cryptographic Signature in SeekableOutputStream
CVE-2026-22696
CRITICAL
dcap-qvl < 0.3.9 - Improper Certificate Validation in QE Identity Collateral
CVE-2026-23992
MEDIUM
go-tuf 2.0.0-2.3.0 - Improper Verification of Cryptographic Signature
CVSS 5.9
CVE-2026-23967
HIGH
sm-crypto <0.3.14 - Signature Malleability
CVSS 7.5
Details
Vulnerabilities
742