VYPR

CWE-347

Improper Verification of Cryptographic Signature

BaseDraft

Description

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-463 · CAPEC-475

CVEs mapped to this weakness (803)

page 39 of 41
  • CVE-2026-22097CriJul 13, 2026
    risk 0.00cvss epss 0.00

    The firmware update mechanism does not include cryptographic signature validation. This allows anyone with access to the firmware update capability to upload arbitrary files which can then lead to arbitrary code execution.

  • CVE-2026-54736HigJul 10, 2026
    risk 0.00cvss epss 0.00

    Phalcon is a high-performance, full-stack PHP framework. Prior to 5.14.1, Phalcon\Encryption\Crypt::decrypt compares the attacker-supplied HMAC tag against the freshly computed HMAC using PHP/Zephir identity comparison, which lowers to a byte-wise comparison that returns early…

  • CVE-2026-9027MedJul 9, 2026
    risk 0.00cvss 5.3epss 0.00

    The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulnerable to Payment Bypass via Improper Verification of Cryptographic Signature in all versions up to, and including, 2.7.4. The `corvuspay_success_handler` function registers the REST endpoint `POST…

  • CVE-2026-11348HigJul 7, 2026
    risk 0.00cvss 8.1epss 0.00

    Improper verification of cryptographic signature vulnerability in HAVELSAN Inc. Liman MYS allows Fake the Source of Data. This issue affects Liman MYS: before release.Master.1107.

  • CVE-2025-0824LowJun 29, 2026
    risk 0.00cvss 3.7epss 0.00

    Lack of validation for firmware update in Hitachi Hitachi Virtual Storage Platform One Block 23, 24, 26, 28. This issue affects Hitachi Virtual Storage Platform One Block 23, 24, 26, 28: before DKCMAIN A3-04-21-40/00, ESM A3-04-21/00.

  • CVE-2024-23581MedJun 26, 2026
    risk 0.00cvss 6.7epss 0.00

    The HCL Traveler for Microsoft Outlook libraries are being flagged as potentially malicious software or an unrecognized application.

  • CVE-2026-11800HigJun 25, 2026
    risk 0.00cvss 8.1epss 0.00

    A flaw was found in Keycloak. This JWT algorithm confusion vulnerability in the JWT Authorization Grant flow allows an attacker with valid client credentials to bypass signature verification. By forging an assertion, the attacker can create unauthorized access tokens. This…

  • CVE-2025-15469MedJan 27, 2026
    risk 0.00cvss 5.5epss 0.00

    Issue summary: The 'openssl dgst' command-line tool silently truncates input data to 16MB when using one-shot signing algorithms and reports success instead of an error. Impact summary: A user signing or verifying files larger than 16MB with one-shot algorithms (such as…

  • CVE-2025-15444CriJan 6, 2026
    risk 0.00cvss 9.8epss 0.00

    Crypt::Sodium::XS module versions prior to 0.000042, for Perl, include a vulnerable version of libsodium libsodium <= 1.0.20 or a version of libsodium released before December 30, 2025 contains a vulnerability documented as CVE-2025-69277 …

  • CVE-2025-40934CriNov 26, 2025
    risk 0.00cvss 9.3epss 0.00

    XML-Sig versions 0.27 through 0.67 for Perl incorrectly validates XML files if signatures are omitted. An attacker can remove the signature from the XML document to make it pass the verification check. XML-Sig is a Perl module to validate signatures on XML files.  An unsigned…

  • CVE-2025-59334CriSep 16, 2025
    risk 0.00cvss 9.6epss 0.00

    Linkr is a lightweight file delivery system that downloads files from a webserver. Linkr versions through 2.0.0 do not verify the integrity or authenticity of .linkr manifest files before using their contents, allowing a tampered manifest to inject arbitrary file entries into a…

  • CVE-2025-43903MedApr 18, 2025
    risk 0.00cvss 4.3epss 0.00

    NSSCryptoSignBackend.cc in Poppler before 25.04.0 does not verify the adbe.pkcs7.sha1 signatures on documents, resulting in potential signature forgeries.

  • CVE-2025-29915HigApr 10, 2025
    risk 0.00cvss 7.5epss 0.00

    Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. The AF_PACKET defrag option is enabled by default and allows AF_PACKET to re-assemble fragmented packets before reaching Suricata. However the default packet…

  • CVE-2024-37886MedJun 14, 2024
    risk 0.00cvss 5.4epss 0.00

    user_oidc app is an OpenID Connect user backend for Nextcloud. An attacker could potentially trick the app into accepting a request that is not signed by the correct server. It is recommended that the Nextcloud user_oidc app is upgraded to 1.3.5, 2.0.0, 3.0.0, 4.0.0 or 5.0.0.

  • CVE-2023-41337MedDec 12, 2023
    risk 0.00cvss 6.1epss 0.00

    h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. In version 2.3.0-beta2 and prior, when h2o is configured to listen to multiple addresses or ports with each of them using different backend servers managed by multiple entities, a malicious backend entity that…

  • CVE-2023-43660MedSep 27, 2023
    risk 0.00cvss 4.8epss 0.00

    Warpgate is a smart SSH, HTTPS and MySQL bastion host for Linux that doesn't need special client apps. The SSH key verification for a user can be bypassed by sending an SSH key offer without a signature. This allows bypassing authentication under following conditions: 1. The…

  • CVE-2023-40012MedAug 9, 2023
    risk 0.00cvss 5.9epss 0.00

    uthenticode is a small cross-platform library for partially verifying Authenticode digital signatures. Versions of uthenticode prior to the 2.x series did not check Extended Key Usages in certificates, in violation of the Authenticode X.509 certificate profile. As a result, a…

  • CVE-2023-39969CriAug 9, 2023
    risk 0.00cvss 9.0epss 0.01

    uthenticode is a small cross-platform library for partially verifying Authenticode digital signatures. Version 1.0.9 of uthenticode hashed the entire file rather than hashing sections by virtual address, in violation of the Authenticode specification. As a result, an attacker…

  • CVE-2023-23928MedFeb 1, 2023
    risk 0.00cvss 5.9epss 0.00

    reason-jose is a JOSE implementation in ReasonML and OCaml.`Jose.Jws.validate` does not check HS256 signatures. This allows tampering of JWS header and payload data if the service does not perform additional checks. Such tampering could expose applications using reason-jose to…

  • CVE-2023-22742MedJan 20, 2023
    risk 0.00cvss 5.3epss 0.01

    libgit2 is a cross-platform, linkable library implementation of Git. When using an SSH remote with the optional libssh2 backend, libgit2 does not perform certificate checking by default. Prior versions of libgit2 require the caller to set the `certificate_check` field of…