Misskey is an open source, federated social media platform. All Misskey servers prior to 2026.3.1 contain a vulnerabilit
PyJWT is a JSON Web Token implementation in Python. Prior to 2.12.0, PyJWT does not validate the crit (Critical) Header
Go ShangMi (Commercial Cryptography) Library (GMSM) is a cryptographic library that covers the Chinese commercial crypto
Versions of the package sjcl before 1.0.9 are vulnerable to Improper Verification of Cryptographic Signature due to miss
goxmlsig provides XML Digital Signatures implemented in Go. Prior to version 1.6.0, the `validateSignature` function in
Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version
Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version
JOSE is a Javascript Object Signing and Encryption (JOSE) library. Prior to version 0.3.5+1, a vulnerability in jose cou
Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcpkix on all
The Payment Gateway for Redsys & WooCommerce Lite plugin for WordPress is vulnerable to Improper Verification of Cryptog
A malicious module proxy can exploit a flaw in the go command's validation of module checksums to bypass checksum databa
The bitcoinj library is a Java implementation of the Bitcoin protocol. Prior to 0.17.1, ScriptExecution.correctlySpends(
The RSA and DSA public key parsers did not enforce size limits on key parameters. A crafted public key with an excessive
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Fina
wolfSSL_PKCS7_verify() returning success for a degenerate (certs-only) PKCS#7 object that contains no signer. Such an ob
HMAC zero-length tag forgery in EVP_DigestVerifyFinal, where a zero-length tag could be accepted as valid during HMAC ve
PKCS7_verify signer confusion allows forged signatures, where the signer associated with a signature is not correctly bo
sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 4.1.1, the documented certifi
OIDC::Lite versions through 0.12.1 for Perl allow ID Token signature verification bypass via a token-controlled algorith
Improper Verification of Cryptographic Signature in ueberauth guardian allows an unauthenticated attacker to revoke a vi
In Bouncy Castle for Java before 1.85, CMS verifySignatures returns true for SignedData with zero signers. This issue al
Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass by verifying responses against the response-em
XML::Sig versions from 0.29 before 0.72 for Perl allow signature verification bypass because verify returns true when ev
Improper verification of cryptographic signature in Microsoft Teams allows an unauthorized attacker to perform spoofing
In CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4, bootxsa.efi fails to properly validate LUKS encryption and, i
A user with access to a valid SAML response may impersonate another user under specific conditions.
A malicious GOSUMDB was capable of serving arbitrary module content not contained within the transparency log. This atta
PAX Technology Q80 Application Installer Signature Verification Bypass Remote Code Execution Vulnerability. This vulnera
After dispatching a decrypt operation to OCF and receiving the result, the wg(4) driver failed to check whether the MAC
libcrux-ecdh and libcrux-ed25519 before 0.0.6, and libcrux-psq before 0.0.7, contain cryptographic implementation bugs.
Versions of the package jsrsasign before 11.1.1 are vulnerable to Improper Verification of Cryptographic Signature via t
Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_ocsp module) allows OCSP designated-respo
epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. Prior to 1.2.2, an attacker who
PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, when the verifier is decoding JSON Web Tokens, whil
CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1,
CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1,
A flaw was found in the SAML metadata import functionality of the keycloak-services component, which is the core engine
IBM ApplinX 11.1 is vulnerable due to a privilege escalation vulnerability due to improper verification of JWT tokens. A
A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP3 with UMC). The affected application contains a
There is a vulnerability in the Supermicro BMC firmware validation logic at Supermicro MBD-X12STW-F . An attacker can up
A high-privileged remote attacker can fully compromise the device by abusing an update signature bypass vulnerability in
ATEN Unizon doCryptoHugeFileToFile Improper Verification of Cryptographic Signature Remote Code Execution Vulnerability.
WatchGuard Fireware OS contains a firmware validation bypass when processing a backup image via the backup/restore featu
A holder of a valid integration credential may impersonate other users under specific conditions.
Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Prior to versions 1.9.11, 1.10
openssl_encrypt (pip: openssl-encrypt) versions <= 1.4.8 use suffix-tolerant fingerprint matching in enroll_trust_key wh
nimiq-transaction provides the transaction primitive to be used in Nimiq's Rust implementation. Prior to version 1.3.0,
BIND may accept incorrect child-zone NSEC3 records as valid, which could allow an attacker to forge authenticated NXDOMA
The Ingenic T41, and probably also T32, T40, and A1 SoC boot ROMs parse and execute an attacker-controlled init table fr
The system suffers from the absence of a kernel module signature verification. If an attacker can execute commands on be
Frequently Asked Questions
What is CWE-347?
CWE-347 (CWE-347) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-347?
There are 947 CVE records associated with CWE-347 in our database. Of these, 142 are critical severity, 324 are high severity, and 268 are medium severity.
How can I protect against CWE-347 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-347 using AI-powered security agents.
Detect CWE-347 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-347 vulnerabilities across your infrastructure.
Get Started