SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated attacker with normal privileges to obtai
authentik is an open-source identity provider. Prior to 2025.8.6, 2025.10.4, and 2025.12.4, when using a SAML Source tha
Philips Hue Bridge hk_hap Ed25519 Signature Verification Authentication Bypass Vulnerability. This vulnerability allows
The Web-based Management allows a remote low privileged Engineer user to install additional APPs on the device downloade
Ghidra before 12.1 contains an authentication bypass vulnerability in PKIAuthenticationModule.authenticate() that allows
Incorrect authorization validation in refresh token signature allows non-admin users to obtain a signed JFrog administra
Zohocorp ManageEngine Password Manager Pro versions before 13232 and PAM360 versions before 8551 are vulnerable to an au
OpenClaw before 2026.3.12 contains an authentication bypass vulnerability in Feishu webhook mode when only verificationT
Network-AI before 5.13.4 contains an improper cryptographic signature verification vulnerability in APSAdapter where the
AVideo (current commit e01e41ecc and earlier) exposes stream credentials through the plugin/Live/view/Live_restreams/get
authentik is an open-source identity provider. Prior to versions 2025.12.5, 2026.2.3, and 2026.5.1, authentik's SAML Sou
There is a vulnerability in the Supermicro BMC firmware validation logic at Supermicro MBD-X13SEM-F . An attacker can up
A malicious GOPROXY was previously capable of forging up to two sumdb tiles that allow for a requested module to bypass
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.11.4, there is a flaw i
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.11.4, there is a flaw i
Authentication Bypass vulnerability exists in Netmaker versions prior to 1.5.0. The VerifyHostToken function in logic/jw
Admidio is an open-source user management solution. Prior to version 5.0.9, the Admidio SAML Identity Provider implement
Centrifugo is an open-source scalable real-time messaging server. Prior to 6.8.1, Centrifugo dynamic JWKS endpoint verif
Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor’s HMAC validation can be bypasse
Nebula is a scalable overlay networking tool. In versions from 1.7.0 to 1.10.2, when using P256 certificates (which is n
A flaw was found in Keycloak. An attacker can exploit this vulnerability by modifying the organization ID and target ema
A vulnerability was identified in Yi Technology YI Home Camera 2 2.1.1_20171024151200. This impacts an unknown function
ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.0 and zebra-consensus version 5.0.1, a logic
OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, OneUptime's SAML SSO implem
BSV Ruby SDK is the Ruby SDK for the BSV blockchain. From 0.3.1 to before 0.8.2, BSV::Wallet::WalletClient#acquire_certi
wolfSSL's ECCSI signature verifier `wc_VerifyEccsiHash` decodes the `r` and `s` scalars from the signature blob via `mp_
An authentication bypass vulnerability in Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with n
azureauthextension is the Azure Authenticator Extension. From 0.124.0 to 0.150.0, a server-side authentication bypass in
The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to Authentication Bypass in all version
A flaw was found in Keycloak. This JWT algorithm confusion vulnerability in the JWT Authorization Grant flow allows an a
Libreswan, via the function RSA_authenticate_hash_signature_raw_rsa(), did not correctly verify the length of the authen
Libreswan, via the function RSA_authenticate_hash_signature_pkcs1_1_5_rsa(), did not correctly verify the DER encoding o
Improper verification of cryptographic signature vulnerability in HAVELSAN Inc. Liman MYS allows Fake the Source of Data
Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature ov
Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass via XML signature wrapping because new_from_xm
A flaw was found in Picketlink's SP signature validation; a SAML response containing zero assertion elements matching th
@fastify/jwt is a JSON Web Token plugin for Fastify. In versions before 10.2.2, a per-request verification key passed to
Missing signature validation in JSON Web Tokens in Otalio Ship Property Management System versions before 2.22.0 allows
Certificate validation failures in SAML authentication in Apache CloudStack 4.20.3.0 and 4.22.1.0 on all platforms allow
Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2
pac4j-oidc before 6.5.6 fails to verify access token signatures, issuers, audiences, or expiry when extracting Keycloak
Zen is a firefox-based browser. Prior to 1.19.9b, Zen Browser ships a Mozilla Application Resource (MAR) updater (org.mo
Helm is a package manager for Charts for Kubernetes. From 4.0.0 to 4.1.3, Helm will install plugins missing provenance (
Multiple Lenze products are affected by an improper signature verification vulnerability in the SSH enablement mechanism
Improper verification of cryptographic signature in Windows Admin Center allows an authorized attacker to elevate privil
sm-crypto provides JavaScript implementations of the Chinese cryptographic algorithms SM2, SM3, and SM4. A signature for
sm-crypto provides JavaScript implementations of the Chinese cryptographic algorithms SM2, SM3, and SM4. A signature mal
Improper Verification of Cryptographic Signature vulnerability in Drupal Drupal Commerce Paybox Commerce Paybox on Drupa
Ethereum Name Service (ENS) is a distributed, open, and extensible naming system based on the Ethereum blockchain. In ve
Improper signature validation in PKCS7_verify() in AWS-LC allows an unauthenticated user to bypass signature verificatio
Frequently Asked Questions
What is CWE-347?
CWE-347 (CWE-347) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-347?
There are 253 CVE records associated with CWE-347 in our database. Of these, 50 are critical severity, 96 are high severity, and 52 are medium severity.
How can I protect against CWE-347 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-347 using AI-powered security agents.
Detect CWE-347 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-347 vulnerabilities across your infrastructure.
Get Started