The product does not verify, or incorrectly verifies, the cryptographic signature for data.
Volume of CVEs assigned to CWE-347 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
735 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-59718CRITICAL A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 t | Dec 9, 2025 | 9.8 | 94 | YES | NO |
CVE-2026-48558CRITICAL SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is config | Jun 12, 2026 | 10.0 | 87 | YES | NO |
CVE-2013-3900HIGH Why is Microsoft republishing a CVE from 2013?
We are republishing CVE-2013-3900 in the Security Update Guide to update the Security Updates table and to inform customers that the | Dec 11, 2013 | 8.8 | 86 | YES | NO |
CVE-2020-1464HIGH A spoofing vulnerability exists when Windows incorrectly validates file signatures. An attacker who successfully exploited this vulnerability could bypass security features and loa | Aug 17, 2020 | 7.8 | 79 | YES | NO |
CVE-2020-2021CRITICAL When Security Assertion Markup Language (SAML) authentication is enabled and the 'Validate Identity Provider Certificate' option is disabled (unchecked), improper verification of s | Jun 29, 2020 | 10.0 | 73 | YES | NO |
CVE-2025-25292CRITICAL ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. An authentication bypass vulnerability was found in ruby-saml prior to versions 1.12.4 a | Mar 12, 2025 | 9.8 | 67 | NO | NO |
CVE-2018-16042MEDIUM Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019.008.20081 and earlier, 2017.011.30106 and earlier version, 2017.011.30105 and earlier | Jan 18, 2019 | 6.5 | 66 | NO | NO |
CVE-2018-0114HIGH A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker to re-sign tokens using a key that is embedded within the t | Jan 4, 2018 | 7.5 | 62 | NO | YES |
CVE-2021-22160CRITICAL If Apache Pulsar is configured to authenticate clients using tokens based on JSON Web Tokens (JWT), the signature of the token is not validated if the algorithm of the presented to | May 26, 2021 | 9.8 | 61 | NO | NO |
CVE-2025-47827MEDIUM In IGEL OS before 11, Secure Boot can be bypassed because the igel-flash-driver module improperly verifies a cryptographic signature. Ultimately, a crafted root filesystem can be m | Jun 5, 2025 | 4.6 | 58 | YES | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.