Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-347

MITRE ↗

CWE-347

142
CRITICAL
324
HIGH
268
MEDIUM
25
LOW
803 CVEs · Page 9/17
5.5
CVE-2024-53267

sigstore-java is a sigstore java client for interacting with sigstore infrastructure. sigstore-java has insufficient ver

5.4
CVE-2024-37886

user_oidc app is an OpenID Connect user backend for Nextcloud. An attacker could potentially trick the app into acceptin

5.4
CVE-2024-11696

The application failed to account for exceptions thrown by the `loadManifestFromFile` method during add-on signature ver

5.3
CVE-2024-23680

AWS Encryption SDK for Java versions 2.0.0 to 2.2.0 and less than 1.9.0 incorrectly validates some invalid ECDSA signatu

5.3
CVE-2024-34358

TYPO3 is an enterprise content management system. Starting in version 9.0.0 and prior to versions 9.5.48 ELTS, 10.4.45 E

5.3
CVE-2024-21988

StorageGRID (formerly StorageGRID Webscale) versions prior to 11.7.0.9 and 11.8.0.5 are susceptible to disclosure of se

5.3
CVE-2024-36277

Improper verification of cryptographic signature issue exists in "FreeFrom - the nostr client" App versions prior to 1.3

5.3
CVE-2024-41254

An issue was discovered in litestream v0.3.13. The usage of the ssh.InsecureIgnoreHostKey() disables host key verificati

5.3
CVE-2024-41258

An issue was discovered in filestash v0.4. The usage of the ssh.InsecureIgnoreHostKey() disables host key verification,

5.3
CVE-2024-42459

In the Elliptic package 6.5.6 for Node.js, EDDSA signature malleability occurs because there is a missing signature leng

5.3
CVE-2024-49394

In mutt and neomutt the In-Reply-To email header field is not protected by cryptographic signing which allows an attacke

4.9
CVE-2021-1461

A vulnerability in the Image Signature Verification feature of Cisco SD-WAN Software could allow an authenticated,

4.8
CVE-2024-48948

The Elliptic package 6.5.7 for Node.js, in its for ECDSA implementation, does not correctly verify valid signatures if t

4.6
CVE-2024-23960

Alpine Halo9 Improper Verification of Cryptographic Signature Vulnerability. This vulnerability allows physically presen

4.5
CVE-2022-3864

A vulnerability exists in the Relion update package signature validation. A tampered update package could cause the IED

3.5
CVE-2023-2030

An issue has been discovered in GitLab CE/EE affecting all versions from 12.2 prior to 16.5.6, 16.6 prior to 16.6.4, and

3.3
CVE-2024-21383

Microsoft Edge (Chromium-based) Spoofing Vulnerability

CVE-2024-1721

Improper Verification of Cryptographic Signature vulnerability in HYPR Passwordless on Windows allows Malicious Software

CVE-2024-5912

An improper file signature check in Palo Alto Networks Cortex XDR agent may allow an attacker to bypass the Cortex XDR a

CVE-2024-50347

Laravel Reverb provides a real-time WebSocket communication backend for Laravel applications. Prior to 1.4.0, there is a

CVE-2024-54126

This vulnerability exists in the TP-Link Archer C50 due to improper signature verification mechanism in the firmware upg

9.8
CVE-2020-22653

In Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n

9.8
CVE-2022-23334

The Robot application in Ip-label Newtest before v8.5R0 was discovered to use weak signature checks on executed binaries

9.8
CVE-2021-36226

Western Digital My Cloud devices before OS5 do not use cryptographically signed Firmware upgrade files.

9.8
CVE-2023-25718

In ConnectWise Control through 22.9.10032 (formerly known as ScreenConnect), after an executable file is signed, additio

9.8
CVE-2023-28610

The update process in OMICRON StationGuard and OMICRON StationScout before 2.21 can be exploited by providing a modified

9.6
CVE-2023-28801

An Improper Verification of Cryptographic Signature in the SAML authentication of the Zscaler Admin UI allows a Privileg

9.3
CVE-2023-49079

Misskey is an open source, decentralized social media platform. Misskey's missing signature validation allows arbitrary

9.1
CVE-2023-34205

In Moov signedxml through 1.0.0, parsing the raw XML (as received) can result in different output than parsing the canon

9.0
CVE-2023-39969

uthenticode is a small cross-platform library for partially verifying Authenticode digital signatures. Version 1.0.9 of

8.8
CVE-2023-39211

Improper privilege management in Zoom Desktop Client for Windows and Zoom Rooms for Windows before 5.15.5 may allow an a

8.7
CVE-2023-34120

Improper privilege management in Zoom for Windows, Zoom Rooms for Windows, and Zoom VDI for Windows clients before 5.14.

8.3
CVE-2023-33959

notation is a CLI tool to sign and verify OCI artifacts and container images. An attacker who has compromised a registry

8.2
CVE-2022-25333

The Texas Instruments OMAP L138 (secure variants) trusted execution environment (TEE) performs an RSA check implemented

8.2
CVE-2023-28804

An Improper Verification of Cryptographic Signature vulnerability in Zscaler Client Connector on Linux allows replacing

7.8
CVE-2022-34459

Dell Command | Update, Dell Update, and Alienware Update versions prior to 4.7 contain a improper verification of crypt

7.8
CVE-2023-20940

In the Android operating system, there is a possible way to replace a boot partition due to improperly used crypto. This

7.8
CVE-2022-20929

A vulnerability in the upgrade signature verification of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allo

7.8
CVE-2022-4418

Local privilege escalation due to unrestricted loading of unsigned libraries. The following products are affected: Acron

7.8
CVE-2023-38418

The BIG-IP Edge Client Installer on macOS does not follow best practices for elevating privileges during the installati

7.8
CVE-2023-41744

Local privilege escalation due to unrestricted loading of unsigned libraries. The following products are affected: Acron

7.8
CVE-2023-40727

A vulnerability has been identified in QMS Automotive (All versions < V12.39). The QMS.Mobile module of the affected app

7.8
CVE-2023-43611

The BIG-IP Edge Client Installer on macOS does not follow best practices for elevating privileges during the installati

7.5
CVE-2020-22659

In Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n

7.5
CVE-2023-24025

CRYSTALS-DILITHIUM (in Post-Quantum Cryptography Selected Algorithms 2022) in PQClean d03da30 may allow universal forger

7.5
CVE-2023-39392

Vulnerability of insecure signatures in the OsuLogin module. Successful exploitation of this vulnerability may cause Osu

7.5
CVE-2023-39393

Vulnerability of insecure signatures in the ServiceWifiResources module. Successful exploitation of this vulnerability m

7.5
CVE-2023-46324

pkg/suci/suci.go in free5GC udm before 1.2.0, when Go before 1.19 is used, allows an Invalid Curve Attack because it may

7.3
CVE-2023-23431

Some Honor products are affected by signature management vulnerability, successful exploitation could cause the forged

7.3
CVE-2023-23432

Some Honor products are affected by signature management vulnerability, successful exploitation could cause the forged

Frequently Asked Questions

What is CWE-347?

CWE-347 (CWE-347) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-347?

There are 947 CVE records associated with CWE-347 in our database. Of these, 142 are critical severity, 324 are high severity, and 268 are medium severity.

How can I protect against CWE-347 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-347 using AI-powered security agents.

Detect CWE-347 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-347 vulnerabilities across your infrastructure.

Get Started