CWE-347

Improper Verification of Cryptographic Signature

Parent: CWE-345 - Insufficient Verification of Data Authenticity

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

651 vulnerabilities with CWE-347
CVE-2025-31335 MEDIUM
OpenSAML C++ <3.3.1 - SSRF
CVSS 4.0
CVE-2025-29775 CRITICAL
NPM Xml-crypto < 6.0.1 - Signature Verification Bypass
CVE-2025-29774 CRITICAL
NPM Xml-crypto < 6.0.1 - Signature Verification Bypass
CVE-2025-25292 CRITICAL
ruby-saml <1.12.4,1.18.0 - Auth Bypass
CVSS 9.8
CVE-2025-25291 CRITICAL
ruby-saml <1.12.4,1.18.0 - Auth Bypass
CVSS 9.8
CVE-2025-20143 MEDIUM
Cisco IOS XR - Privilege Escalation
CVSS 6.7
CVE-2025-2233 HIGH
Samsung Smartthings < 0.55.5 - Signature Verification Bypass
CVSS 8.8
CVE-2025-27773 HIGH
Simplesamlphp Saml2 < 4.17.0 - Signature Verification Bypass
CVSS 8.6
CVE-2025-24043 HIGH
Microsoft Windbg < 1.2502.25002.0 - Signature Verification Bypass
CVSS 7.5
CVE-2025-20206 HIGH
Cisco Secure Client - DLL Hijacking
CVSS 7.1
CVE-2025-27670 CRITICAL
Printerlogic Vasion Print < 20.0.1923 - Signature Verification Bypass
CVSS 9.8
CVE-2025-27498 MEDIUM
aes-gcm <0.4.3 - Info Disclosure
CVE-2025-24800 CRITICAL
ismp-grandpa <15.0.1 - RCE
CVE-2025-23369 HIGH
Github Enterprise Server < 3.12.14 - Signature Verification Bypass
CVSS 8.8
CVE-2025-23206 HIGH
Amazon Aws Cloud Development Kit - Signature Verification Bypass
CVSS 8.1
CVE-2024-13990 CRITICAL
MicroWorld eScan AV - SSRF
CVE-2024-49365 HIGH
NPM Tiny-secp256k1 < 1.1.7 - Signature Verification Bypass
CVE-2024-36347 MEDIUM
AMD CPU ROM - Privilege Escalation
CVSS 6.4
CVE-2024-11957 CRITICAL
Kingsoft WPS Office <=12.1.0.18276 - Code Injection
CVE-2024-10237 HIGH
Supermicro MBD-X12DPG-OA6 - Auth Bypass
CVSS 7.2
CVE-2024-56161 HIGH
AMD CPU ROM - Privilege Escalation
CVSS 7.2
CVE-2024-13172 HIGH
Ivanti EPM - RCE
CVSS 7.8
CVE-2024-7344 HIGH
Cs-grp Neo Impact < 10.1.024-20241127 - Signature Verification Bypass
CVSS 8.2
CVE-2024-54150 CRITICAL
cjwt - Algorithm Confusion
CVSS 9.1
CVE-2024-43106 HIGH
Microsoft Excel 16.83 - Code Injection
CVSS 7.1
Details
Vulnerabilities 651