CWE-347

Improper Verification of Cryptographic Signature

Parent: CWE-345 - Insufficient Verification of Data Authenticity

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

686 vulnerabilities with CWE-347
CVE-2025-66568 CRITICAL
ruby-saml < 1.18.0 - Authentication Bypass via Signature Wrapping Attack
CVSS 9.1
CVE-2025-66567 CRITICAL
ruby-saml < 1.18.0 - Authentication Bypass via Signature Wrapping Attack
CVSS 9.1
CVE-2025-13662 HIGH
Ivanti Endpoint Manager < 2024 SU4 SR1 - Remote Code Execution via Signature Bypass
CVSS 7.8
CVE-2025-65945 HIGH
auth0/node-jws <4.0.0 - Improper Signature Verification
CVSS 7.5
CVE-2025-40934 CRITICAL
XML-Sig 0.27-0.67 - Improper Verification of Cryptographic Signature via Omitted Signature
CVSS 9.3
CVE-2025-34324 HIGH
GoSign Desktop < 2.4.1 - Arbitrary Code Execution via Unsigned Update Manifest
CVSS 7.8
CVE-2025-64740 HIGH
Zoom Workplace VDI Client < 6.3.14 Privilege Escalation via Signature Bypass
CVSS 7.5
CVE-2025-64186 HIGH
evervault-go < 1.3.2 - Improper Verification of Cryptographic Signature in Attestation Logic
CVSS 8.7
CVE-2025-64456 HIGH
JetBrains ReSharper < 2025.2.4 - Local Privilege Escalation via Missing DPA Collector Signature Verification
CVSS 8.4
CVE-2025-55278 HIGH
HCL DevOps Loop >=1.0.2 <1.0.2 - Improper Verification of Cryptographic Signature in API Authentication Middleware
CVSS 8.1
CVE-2025-43468 MEDIUM
macOS < 14.8.2, < 15.7.2, < 26.1 - Unprotected User Data Exposure via Cryptographic Signature Verification Downgrade
CVSS 5.5
CVE-2025-43390 MEDIUM
macOS <15.7.2-26.1 - Info Disclosure
CVSS 5.5
CVE-2025-54549 MEDIUM
Cryptographic validation bypass - Info Disclosure
CVSS 5.9
CVE-2025-58356 HIGH
Constellation - Cryptographic Vulnerability
CVE-2025-12295 MEDIUM
D-Link DAP-2695 2.00RC13 - Insufficient Verification of Data Authenticity in Firmware Update Handler
CVSS 6.6
CVE-2025-34503 HIGH
Deck Mate 1 - Unauthenticated Arbitrary Code Execution via EEPROM Firmware Replacement
CVE-2025-34500 HIGH
Deck Mate 2 < all known versions prior to 2025-10-23 - Arbitrary Code Execution via Insecure Firmware Update Chain
CVE-2025-55039 MEDIUM
Apache Spark <4.0.0-3.5.2-3.4.4 - Info Disclosure
CVSS 6.5
CVE-2025-59288 MEDIUM
Playwright < 1.55.1 - Improper Verification of Cryptographic Signature
CVSS 5.3
CVE-2025-46774 HIGH
FortiClient MacOS <7.4.2, <7.2.9, All - Privilege Escalation
CVSS 7.5
CVE-2025-9485 CRITICAL
WordPress OAuth Client <6.26.12 - RCE
CVSS 9.8
CVE-2025-59934 CRITICAL
formbricks < 4.0.1 - Unauthenticated Authentication Bypass via JWT Signature Verification Missing
CVSS 9.4
CVE-2025-7937 HIGH
Supermicro MBD-X12STW - Code Injection
CVSS 7.2
CVE-2025-6198 HIGH
Supermicro MBD-X13SEM-F - Code Injection
CVSS 7.2
CVE-2025-59334 CRITICAL
Linkr < 2.0.1 - Arbitrary File Injection via Tampered Manifest
CVSS 9.6
Details
Vulnerabilities 686