CWE-347
Improper Verification of Cryptographic Signature
MITRENo catalog description on file. The MITRE CWE site has the canonical reference.
Recent CVEs
showing 19 of 19- CVE-2026-41694Low· 3.7EPSS 0%17 h ago
Since Spring Security SAML decrypts SAML Responses as well as elements of SAML LogoutRequests and LogoutResponses without requiring a valid signature, attackers may be able to craft these SAML payloads and use the Service Provider as a decr
- CVE-2026-50634Medium· 6.5EPSS 0%18 h ago
A vulnerability in Apache CXF's JwsJsonContainerRequestFilter can be exploited to cause CXF to process metadata that was not authenticated by the accepted signature. This can bypass the application's assumption that accepted `Content-Type`
- CVE-2026-48558Critical· 10.019 h ago
SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login are accepted wi
- CVE-2020-2021Critical· 10.0KEVEPSS 19%20 h ago
Palo Alto Networks PAN-OS Authentication Bypass Vulnerability
- CVE-2020-1464High· 7.8KEVEPSS 8%20 h ago
Microsoft Windows Spoofing Vulnerability
- CVE-2025-59718Critical· 9.8KEVEPSS 12%20 h ago
Fortinet Multiple Products Improper Verification of Cryptographic Signature Vulnerability
- CVE-2022-20703Critical· 10.0KEVEPSS 2%20 h ago
Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability
- CVE-2026-50010High· 7.5EPSS 0%21 h ago
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, SimpleTrustManagerFactory.engineGetTrustManagers() and related paths wrap any user-supplied plain X5
- CVE-2026-41005Critical· 9.0EPSS 0%21 h ago
Cloud Foundry UAA incorrectly treated XML encryption to the Service Provider (confidentiality) as a substitute for XML signatures from the Identity Provider (authenticity) in two SAML flows: the OAuth 2.0 SAML2 bearer grant (token endpoint)
- CVE-2026-52754High· 8.8EPSS 0%1 d ago
Ghidra before 12.1 contains an authentication bypass vulnerability in PKIAuthenticationModule.authenticate() that allows any user with a valid CA-signed certificate to impersonate other users by presenting their public certificate with a nu
- CVE-2026-42462High· 7.0EPSS 0%1 d ago
Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Prior to versions 1.9.11, 1.10.10, 2.0.18, 2.1.14, and 2.2.3, an attacker can make use of JSON-LD features to restructure a JSON-LD document that woul
npm - CVE-2026-10795High· 8.1EPSS 0%1 d ago
The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.26.4 via the UpdraftPlus_Remote_Communications_V2::wp_loaded function. This is due to insuffic
- CVE-2026-36721Critical· 9.8EPSS 0%2 d ago
A lack of cryptographic signature verification in the validateAccessToken function of bookcars v8.3 allows attackers to bypass authentication via a forged JWT token.
- CVE-2026-0265—EPSS 0%4 d ago
An authentication bypass vulnerability in Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to bypass authentication controls when Cloud Authentication Service (CAS) is enabled. The risk is highe
- CVE-2025-59719Critical· 9.8EPSS 0%4 d ago
An improper verification of cryptographic signature vulnerability in Fortinet FortiWeb 8.0.0, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9 may allow an unauthenticated attacker to bypass the FortiCloud SSO login authentication
- CVE-2026-23687High· 8.8EPSS 0%4 d ago
SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated attacker with normal privileges to obtain a valid signed message and send modified signed XML documents to the verifier. This may result in acceptance of tamper
- CVE-2026-44748Critical· 9.9EPSS 0%4 d ago
SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated attacker with normal privileges to obtain a valid signed message and send modified signed XML documents to the verifier. This may result in acceptance of tamper
- CVE-2026-45614Medium· 4.7EPSS 0%7 d ago
OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Prior to version 4.11.0, on many of the ECDH shared secret paths, the public k
- CVE-2022-47549Medium· 6.4EPSS 0%7 d ago
An unprotected memory-access operation in optee_os in TrustedFirmware Open Portable Trusted Execution Environment (OP-TEE) before 3.20 allows a physically proximate adversary to bypass signature verification and install malicious trusted ap
CWE catalog data sourced from MITRE. CVE associations come from NVD weakness mappings; some CVEs carry multiple CWEs.