CWE-347— Improper Verification of Cryptographic Signature
The product does not verify, or incorrectly verifies, the cryptographic signature for data.— MITRE CWE catalog
743 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-347page 10 of 15
- CVE-2024-39804HIGHCVSS 7.1EG 7.12024-12-18
A library injection vulnerability exists in Microsoft PowerPoint 16.83 for macOS. A specially crafted library can leverage PowerPoint's access privileges, leading to a permission bypass. A malicious application could inject a library and s…
- CVE-2024-40592HIGHCVSS 7.5EG 7.52024-11-12
An improper verification of cryptographic signature vulnerability [CWE-347] in FortiClient MacOS version 7.4.0, version 7.2.4 and below, version 7.0.10 and below, version 6.4.10 and below may allow a local authenticated attacker to swap t…
- CVE-2024-41138HIGHCVSS 7.1EG 7.12024-12-18
A library injection vulnerability exists in the com.microsoft.teams2.modulehost.app helper app of Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially crafted library can leverage Teams's access privileges, leading …
- CVE-2024-41145HIGHCVSS 7.1EG 7.12024-12-18
A library injection vulnerability exists in the WebView.app helper app of Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially crafted library can leverage Teams's access privileges, leading to a permission bypass. …
- CVE-2024-41159HIGHCVSS 7.1EG 7.12024-12-18
A library injection vulnerability exists in Microsoft OneNote 16.83 for macOS. A specially crafted library can leverage OneNote's access privileges, leading to a permission bypass. A malicious application could inject a library and start t…
- CVE-2024-41165HIGHCVSS 7.1EG 7.12024-12-18
A library injection vulnerability exists in Microsoft Word 16.83 for macOS. A specially crafted library can leverage Word's access privileges, leading to a permission bypass. A malicious application could inject a library and start the pro…
- CVE-2024-41254MEDIUMCVSS 5.3EG 5.32024-07-31
An issue was discovered in litestream v0.3.13. The usage of the ssh.InsecureIgnoreHostKey() disables host key verification, possibly allowing attackers to obtain sensitive information via a man-in-the-middle attack.
- CVE-2024-41258MEDIUMCVSS 5.3EG 5.32024-07-31
An issue was discovered in filestash v0.4. The usage of the ssh.InsecureIgnoreHostKey() disables host key verification, possibly allowing attackers to obtain sensitive information via a man-in-the-middle attack.
- CVE-2024-42004HIGHCVSS 7.1EG 7.12024-12-18
A library injection vulnerability exists in Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially crafted library can leverage Teams's access privileges, leading to a permission bypass. A malicious application could …
- CVE-2024-42220HIGHCVSS 7.1EG 7.12024-12-18
A library injection vulnerability exists in Microsoft Outlook 16.83.3 for macOS. A specially crafted library can leverage Outlook's access privileges, leading to a permission bypass. A malicious application could inject a library and start…
- CVE-2024-42459MEDIUMCVSS 5.3EG 5.32024-08-02
In the Elliptic package 6.5.6 for Node.js, EDDSA signature malleability occurs because there is a missing signature length check, and thus zero-valued bytes can be removed or appended.
- CVE-2024-42461CRITICALCVSS 9.1EG 9.12024-08-02
In the Elliptic package 6.5.6 for Node.js, ECDSA signature malleability occurs because BER-encoded signatures are allowed.
- CVE-2024-43106HIGHCVSS 7.1EG 7.12024-12-18
A library injection vulnerability exists in Microsoft Excel 16.83 for macOS. A specially crafted library can leverage Excel's access privileges, leading to a permission bypass. A malicious application could inject a library and start the p…
- CVE-2024-45409CRITICALCVSS 10.0EG 10.02024-09-10
The Ruby SAML library is for implementing the client side of a SAML authorization. Ruby-SAML in <= 12.2 and 1.13.0 <= 1.16.0 does not properly verify the signature of the SAML Response. An unauthenticated attacker with access to any signed…
- CVE-2024-45607MEDIUMCVSS 5.8EG 5.82024-09-12
whatsapp-api-js is a TypeScript server agnostic Whatsapp's Official API framework. It's possible to check the payload validation using the WhatsAppAPI.verifyRequestSignature and expect false when the signature is valid. Incorrect Access Co…
- CVE-2024-47073CRITICALCVSS 9.1EG 9.12024-11-07
DataEase is an open source data visualization analysis tool that helps users quickly analyze data and gain insights into business trends. In affected versions a the lack of signature verification of jwt tokens allows attackers to forge jwt…
- CVE-2024-47476HIGHCVSS 7.8EG 7.82024-12-03
Dell NetWorker Management Console, version(s) 19.11, contain(s) an Improper Verification of Cryptographic Signature vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Code …
- CVE-2024-47832CRITICALCVSS 9.8EG 9.82024-10-09
ssoready is a single sign on provider implemented via docker. Affected versions are vulnerable to XML signature bypass attacks. An attacker can carry out signature bypass if you have access to certain IDP-signed messages. The underlying me…
- CVE-2024-47943CRITICALCVSS 9.8EG 9.82024-10-15
The firmware upgrade function in the admin web interface of the Rittal IoT Interface & CMC III Processing Unit devices checks if the patch files are signed before executing the containing run.sh script. The signing process is kind of an…
- CVE-2024-48948MEDIUMCVSS 4.8EG 4.82024-10-15
The Elliptic package 6.5.7 for Node.js, in its for ECDSA implementation, does not correctly verify valid signatures if the hash contains at least four leading 0 bytes and when the order of the elliptic curve's base point is smaller than th…
- CVE-2024-48949CRITICALCVSS 9.1EG 9.12024-10-10
The verify function in lib/elliptic/eddsa/index.js in the Elliptic package before 6.5.6 for Node.js omits "sig.S().gte(sig.eddsa.curve.n) || sig.S().isNeg()" validation.
- CVE-2024-49365HIGHCVSS 8.1EG 8.12025-07-01
tiny-secp256k1 is a tiny secp256k1 native/JS wrapper. Prior to version 1.1.7, a malicious JSON-stringifyable message can be made passing on verify(), when global Buffer is the buffer package. This affects only environments where require('b…
- CVE-2024-49393HIGHCVSS 5.9EG 7.42024-11-12
In neomutt and mutt, the To and Cc email headers are not validated by cryptographic signing which allows an attacker that intercepts a message to change their value and include himself as a one of the recipients to compromise message confi…
- CVE-2024-49394MEDIUMCVSS 5.3EG 5.32024-11-12
In mutt and neomutt the In-Reply-To email header field is not protected by cryptographic signing which allows an attacker to reuse an unencrypted but signed email message to impersonate the original sender.
- CVE-2024-49413HIGHCVSS 7.1EG 7.12024-12-03
Improper Verification of Cryptographic Signature in SmartSwitch prior to SMR Dec-2024 Release 1 allows local attackers to install malicious applications.
- CVE-2024-50347MEDIUMCVSS 6.3EG 6.32024-10-31
Laravel Reverb provides a real-time WebSocket communication backend for Laravel applications. Prior to 1.4.0, there is an issue where verification signatures for requests sent to Reverb's Pusher-compatible API were not being verified. This…
- CVE-2024-51526HIGHCVSS 8.2EG 8.22024-11-05
Permission control vulnerability in the hidebug module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2024-52958HIGHCVSS 7.2EG 7.22024-11-27
A improper verification of cryptographic signature vulnerability in plugin management in iota C.ai Conversational Platform from 1.0.0 through 2.1.3 allows remote authenticated users to load a malicious DLL via upload plugin function.
- CVE-2024-53267MEDIUMCVSS 5.5EG 5.52024-11-26
sigstore-java is a sigstore java client for interacting with sigstore infrastructure. sigstore-java has insufficient verification for a situation where a validly-signed but "mismatched" bundle is presented as proof of inclusion into a tran…
- CVE-2024-54126HIGHCVSS 8.5EG 8.52024-12-05
This vulnerability exists in the TP-Link Archer C50 due to improper signature verification mechanism in the firmware upgrade process at its web interface. An attacker with administrative privileges within the router’s Wi-Fi range could e…
- CVE-2024-54150CRITICALCVSS 9.1EG 9.12024-12-19
cjwt is a C JSON Web Token (JWT) Implementation. Algorithm confusion occurs when a system improperly verifies the type of signature used, allowing attackers to exploit the lack of distinction between signing methods. If the system doesn't…
- CVE-2024-56161HIGHCVSS 7.2EG 7.22025-02-03
Improper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator privilege to load malicious CPU microcode resulting in loss of confidentiality and integrity of a confidential guest runni…
- CVE-2024-5912MEDIUMCVSS 6.8EG 6.82024-07-10
An improper file signature check in Palo Alto Networks Cortex XDR agent may allow an attacker to bypass the Cortex XDR agent's executable blocking capabilities and run untrusted executables on the device. This issue can be leveraged to exe…
- CVE-2024-6580MEDIUMCVSS 6.5EG 6.52024-07-08
The /n software IPWorks SSH library SFTPServer component can be induced to make unintended filesystem or network path requests when loading a SSH public key or certificate. To be exploitable, an application calling the SFTPServer component…
- CVE-2024-6800CRITICALCVSS 9.8EG 9.82024-08-20
An XML signature wrapping vulnerability was present in GitHub Enterprise Server (GHES) when using SAML authentication with specific identity providers utilizing publicly exposed signed federation metadata XML. This vulnerability allowed an…
- CVE-2024-7344HIGHCVSS 8.2EG 8.22025-01-14
Howyar UEFI Application "Reloader" (32-bit and 64-bit) is vulnerable to execution of unsigned software in a hardcoded path.
- CVE-2024-7479HIGHCVSS 8.8EG 8.82024-09-25
Improper verification of cryptographic signature during installation of a VPN driver via the TeamViewer_service.exe component of TeamViewer Remote Clients prior version 15.58.4 for Windows allows an attacker with local unprivileged access …
- CVE-2024-7481HIGHCVSS 8.8EG 8.82024-09-25
Improper verification of cryptographic signature during installation of a Printer driver via the TeamViewer_service.exe component of TeamViewer Remote Clients prior version 15.58.4 for Windows allows an attacker with local unprivileged acc…
- CVE-2024-7788HIGHCVSS 7.8EG 7.82024-09-17
Improper Digital Signature Invalidation vulnerability in Zip Repair Mode of The Document Foundation LibreOffice allows Signature forgery vulnerability in LibreOfficeThis issue affects LibreOffice: from 24.2 before < 24.2.5.
- CVE-2024-8036MEDIUMCVSS 5.9EG 5.92024-10-25
ABB is aware of privately reported vulnerabilities in the product versions referenced in this CVE. An attacker could exploit these vulnerabilities by sending a specially crafted firmware or configuration to the system node, causing the nod…
- CVE-2024-8531HIGHCVSS 7.2EG 7.22024-10-11
CWE-347: Improper Verification of Cryptographic Signature vulnerability exists that could compromise the Data Center Expert software when an upgrade bundle is manipulated to include arbitrary bash scripts that are executed as root.
- CVE-2024-8698HIGHCVSS 7.7EG 7.72024-09-19
A flaw exists in the SAML signature validation method within the Keycloak XMLSignatureUtil class. The method incorrectly determines whether a SAML signature is for the full document or only for specific assertions based on the position of …
- CVE-2024-9487CRITICALCVSS 9.1EG 9.12024-10-10
An improper verification of cryptographic signature vulnerability was identified in GitHub Enterprise Server that allowed SAML SSO authentication to be bypassed resulting in unauthorized provisioning of users and access to the instance. Ex…
- CVE-2025-0824LOWCVSS 3.7EG 3.72026-06-29
Lack of validation for firmware update in Hitachi Hitachi Virtual Storage Platform One Block 23, 24, 26, 28. This issue affects Hitachi Virtual Storage Platform One Block 23, 24, 26, 28: before DKCMAIN A3-04-21-40/00, ESM A3-04-21/00.
- CVE-2025-12006HIGHCVSS 7.2EG 7.22026-01-16
There is a vulnerability in the Supermicro BMC firmware validation logic at Supermicro MBD-X12STW-F . An attacker can update the system firmware with a specially crafted image.
- CVE-2025-12007HIGHCVSS 8.4EG 8.42026-01-16
There is a vulnerability in the Supermicro BMC firmware validation logic at Supermicro MBD-X13SEM-F . An attacker can update the system firmware with a specially crafted image.
- CVE-2025-12150LOWCVSS 3.1EG 3.12026-02-27
A flaw was found in Keycloak’s WebAuthn registration component. This vulnerability allows an attacker to bypass the configured attestation policy and register untrusted or forged authenticators via submission of an attestation object wit…
- CVE-2025-12295MEDIUMCVSS 6.6EG 6.62025-10-27
A weakness has been identified in D-Link DAP-2695 2.00RC13. The affected element is the function sub_40C6B8 of the component Firmware Update Handler. Executing manipulation can lead to improper verification of cryptographic signature. The …
- CVE-2025-13662HIGHCVSS 7.8EG 7.82025-12-09
Improper verification of cryptographic signatures in the patch management component of Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote unauthenticated attacker to execute arbitrary code. User Interaction is required.
- CVE-2025-15444CRITICALCVSS 9.8EG 9.82026-01-06
Crypt::Sodium::XS module versions prior to 0.000042, for Perl, include a vulnerable version of libsodium libsodium <= 1.0.20 or a version of libsodium released before December 30, 2025 contains a vulnerability documented as CVE-2025-692…
Map vulnerabilities like CWE-347 to your infrastructure
EchelonGraph correlates every CVE — across CWE-347 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →