Browse and filter security vulnerabilities across ecosystems
Browse and filter security vulnerabilities across ecosystems
SSH Enablement Signature Verification Bypass
epa4all Security Incident: Implement keystore based on Telematik TSL, implement hostname check and certificate check for lib-vau
OIDC::Lite versions through 0.12.1 for Perl allow ID Token signature verification bypass via a token-controlled algorithm allowlist in verify
Incorrect acceptance of NSEC3 records
Network-AI before 5.13.4 Cryptographic Signature Verification Bypass
sigstore-go: Multi-log threshold bypass via single compromised log
Centrifugo: Dynamic JWKS key cache keyed only by `kid` allows cross-issuer JWT authentication bypass
Janssen Project: JWE Request Object Signature Verification Bypass in jans-auth-server
moodle-local_o365: Authentication bypass via unverified JWT signature in Teams SSO endpoint
SAML Single Sign On <= 5.4.3 - Unauthenticated Authentication Bypass via 'SAMLResponse' Parameter Signature Algorithm Confusion
DataEase: Unauthorized Command Execution Vulnerability
sigstore-js: DSSE payloadType type-binding failure
sigstore-js: `certificateOIDs` verification constraints are silently dropped and never enforced
Symfony: Mailomat Mailer Webhook Parser Reads the HMAC Algorithm from the Request: Signature Algorithm Downgrade
Symfony: Twilio Notifier Webhook Parser Never Verifies the X-Twilio-Signature HMAC: Unauthenticated Webhook Event Injection
Symfony: Mailtrap Mailer Webhook Parser Never Verifies the X-Mt-Signature HMAC — Unauthenticated Webhook Event Injection
.NET Security Feature Bypass Vulnerability
Tenable Agent Path Traversal Leading to Remote Code Execution
A vulnerability has been identified in Opcenter X (All versions < V2604)
Missing firmware validation allows remote code execution
Showing 1 - 20 of 1,000+ results