Ever Gauzy v0.281.9 contains a JWT authentication vulnerability that allows attackers to exploit weak HMAC secret key im
Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.
An improper verification of cryptographic signature in Zscaler's SAML authentication mechanism on the server-side allowe
Linkr is a lightweight file delivery system that downloads files from a webserver. Linkr versions through 2.0.0 do not v
Formbricks is an open source qualtrics alternative. Prior to version 4.0.1, Formbricks is missing JWT signature verifica
XML-Sig versions 0.27 through 0.67 for Perl incorrectly validates XML files if signatures are omitted. An attacker can
A potential security vulnerability has been identified in the HP Linux Imaging and Printing Software documentation. This
gnark is a zero-knowledge proof system framework. In versions prior to 0.14.0, the Verify function in eddsa.go and ecdsa
The ruby-saml library is for implementing the client side of a SAML authorization. ruby-saml versions up to and includin
The ruby-saml library implements the client side of an SAML authorization. Versions up to and including 1.12.4, are vuln
An improper verification of cryptographic signature vulnerability was identified in GitHub Enterprise Server that allowe
Samsung SmartThings Improper Verification of Cryptographic Signature Authentication Bypass Vulnerability. This vulnerabi
A vulnerability has been identified in Mendix SAML (Mendix 10.12 compatible) (All versions < V4.0.3), Mendix SAML (Mendi
Evervault is a payment security solution. A vulnerability was identified in the `evervault-go` SDK’s attestation verific
The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. Prior to versions 4.17.0 and 5.0.0-alp
In JetBrains ReSharper before 2025.2.4 missing signature verification in DPA Collector allows local privilege escalation
Howyar UEFI Application "Reloader" (32-bit and 64-bit) is vulnerable to execution of unsigned software in a hardcoded
The AWS Cloud Development Kit (AWS CDK) is an open-source software development framework to define cloud infrastructure
MSI Center before 2.0.52.0 has Missing PE Signature Validation.
Improper authentication in the API authentication middleware of HCL DevOps Loop allows authentication tokens to be accep
Multiple vulnerabilities in Aqara Hub firmware update process in the Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hu
CarlinKit CPC200-CCPA update.cgi Improper Verification of Cryptographic Signature Code Execution Vulnerability. This vul
Improper signature verification in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Sec
GoSign Desktop versions 2.4.0 and earlier use an unsigned update manifest for distributing application updates. The mani
Improper verification of cryptographic signatures in the patch management component of Ivanti Endpoint Manager prior to
Improper verification of cryptographic signature in .NET allows an authorized attacker to execute code over a network.
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Th
Improper verification of cryptographic signature in Microsoft Azure Functions allows an authorized attacker to execute c
samlify is a Node.js library for SAML single sign-on. A Signature Wrapping attack has been found in samlify prior to ver
An Improper Verification of Cryptographic Signature vulnerability [CWE-347] in FortiClient MacOS installer version 7.4.2
Improper verification of cryptographic signature in the installer for Zoom Workplace VDI Client for Windows may allow an
auth0/node-jws is a JSON Web Signature implementation for Node.js. In versions 3.2.2 and earlier and version 4.0.0, auth
Improper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator pri
There is a vulnerability in the BMC firmware image authentication design at Supermicro MBD-X12DPG-OA6 . An attacker
E3 Site Supervisor Control (firmware version < 2.31F01) firmware upgrade packages are unsigned. An attacker can forge ma
There is a vulnerability in the Supermicro BMC firmware validation logic at Supermicro MBD-X13SEM-F . An attacker can up
There is a vulnerability in the Supermicro BMC firmware validation logic at Supermicro MBD-X12STW . An attacker can upda
A vulnerability in the interprocess communication (IPC) channel of Cisco Secure Client for Windows could allow an authen
CarlinKit CPC200-CCPA Improper Verification of Cryptographic Signature Code Execution Vulnerability. This vulnerability
A vulnerability in Cisco IOS Software for Cisco Catalyst 2960X, 2960XR, 2960CX, and 3560CX Series Switches could allow a
A potential vulnerability was reported in the Lenovo 510 FHD and Performance FHD web cameras that could allow an attacke
A vulnerability in the boot process of Cisco IOS XR Software could allow an authenticated, local attacker with high priv
A weakness has been identified in D-Link DAP-2695 2.00RC13. The affected element is the function sub_40C6B8 of the compo
This issue affects Apache Spark versions before 3.4.4, 3.5.2 and 4.0.0. Apache Spark versions before 4.0.0, 3.5.2 an
An issue was discovered in Foxit PDF and Editor for Windows and macOS before 13.2 and 2025 before 2025.2. A crafted PDF
ALTCHA is privacy-first software for captcha and bot protection. A cryptographic semantic binding flaw in ALTCHA librari
Improper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator pri
A vulnerability has been identified in Building X - Security Manager Edge Controller (ACC-AP) (All versions). Affected d
Improper verification of intent by broadcast receiver in System UI for Galaxy Watch prior to SMR Jul-2025 Release 1 allo
A vulnerability has been identified in TIA Administrator (All versions < V3.0.6). The affected application improperly va
Frequently Asked Questions
What is CWE-347?
CWE-347 (CWE-347) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-347?
There are 947 CVE records associated with CWE-347 in our database. Of these, 142 are critical severity, 324 are high severity, and 268 are medium severity.
How can I protect against CWE-347 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-347 using AI-powered security agents.
Detect CWE-347 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-347 vulnerabilities across your infrastructure.
Get Started