CWE-347
Improper Verification of Cryptographic Signature
The product does not verify, or incorrectly verifies, the cryptographic signature for data.
686 vulnerabilities with CWE-347
CVE-2025-66568
CRITICAL
ruby-saml < 1.18.0 - Authentication Bypass via Signature Wrapping Attack
CVSS 9.1
CVE-2025-66567
CRITICAL
ruby-saml < 1.18.0 - Authentication Bypass via Signature Wrapping Attack
CVSS 9.1
CVE-2025-13662
HIGH
Ivanti Endpoint Manager < 2024 SU4 SR1 - Remote Code Execution via Signature Bypass
CVSS 7.8
CVE-2025-65945
HIGH
auth0/node-jws <4.0.0 - Improper Signature Verification
CVSS 7.5
CVE-2025-40934
CRITICAL
XML-Sig 0.27-0.67 - Improper Verification of Cryptographic Signature via Omitted Signature
CVSS 9.3
CVE-2025-34324
HIGH
GoSign Desktop < 2.4.1 - Arbitrary Code Execution via Unsigned Update Manifest
CVSS 7.8
CVE-2025-64740
HIGH
Zoom Workplace VDI Client < 6.3.14 Privilege Escalation via Signature Bypass
CVSS 7.5
CVE-2025-64186
HIGH
evervault-go < 1.3.2 - Improper Verification of Cryptographic Signature in Attestation Logic
CVSS 8.7
CVE-2025-64456
HIGH
JetBrains ReSharper < 2025.2.4 - Local Privilege Escalation via Missing DPA Collector Signature Verification
CVSS 8.4
CVE-2025-55278
HIGH
HCL DevOps Loop >=1.0.2 <1.0.2 - Improper Verification of Cryptographic Signature in API Authentication Middleware
CVSS 8.1
CVE-2025-43468
MEDIUM
macOS < 14.8.2, < 15.7.2, < 26.1 - Unprotected User Data Exposure via Cryptographic Signature Verification Downgrade
CVSS 5.5
CVE-2025-43390
MEDIUM
macOS <15.7.2-26.1 - Info Disclosure
CVSS 5.5
CVE-2025-54549
MEDIUM
Cryptographic validation bypass - Info Disclosure
CVSS 5.9
CVE-2025-58356
HIGH
Constellation - Cryptographic Vulnerability
CVE-2025-12295
MEDIUM
D-Link DAP-2695 2.00RC13 - Insufficient Verification of Data Authenticity in Firmware Update Handler
CVSS 6.6
CVE-2025-34503
HIGH
Deck Mate 1 - Unauthenticated Arbitrary Code Execution via EEPROM Firmware Replacement
CVE-2025-34500
HIGH
Deck Mate 2 < all known versions prior to 2025-10-23 - Arbitrary Code Execution via Insecure Firmware Update Chain
CVE-2025-55039
MEDIUM
Apache Spark <4.0.0-3.5.2-3.4.4 - Info Disclosure
CVSS 6.5
CVE-2025-59288
MEDIUM
Playwright < 1.55.1 - Improper Verification of Cryptographic Signature
CVSS 5.3
CVE-2025-46774
HIGH
FortiClient MacOS <7.4.2, <7.2.9, All - Privilege Escalation
CVSS 7.5
CVE-2025-9485
CRITICAL
WordPress OAuth Client <6.26.12 - RCE
CVSS 9.8
CVE-2025-59934
CRITICAL
formbricks < 4.0.1 - Unauthenticated Authentication Bypass via JWT Signature Verification Missing
CVSS 9.4
CVE-2025-7937
HIGH
Supermicro MBD-X12STW - Code Injection
CVSS 7.2
CVE-2025-6198
HIGH
Supermicro MBD-X13SEM-F - Code Injection
CVSS 7.2
CVE-2025-59334
CRITICAL
Linkr < 2.0.1 - Arbitrary File Injection via Tampered Manifest
CVSS 9.6
Details
Vulnerabilities
686