CWE-347: CWE-347

182
Total CVEs
54
Critical
92
High
7.9
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
21
2025
51
2024
42
2023
21
2022
14

Top Affected Vendors

1 Microsoft 10
2 Fedoraproject 8
3 Debian 6
4 Dell 5
5 Apple 5
6 Onelogin 4
7 Cisco 4
8 Zoom 4
9 Zscaler 4
10 Github 3

All CWE-347 CVEs (182)

CVE-2026-29000
10.0

This critical authentication bypass vulnerability in pac4j-jwt allows attackers with the server's RSA public key to forge JWT authentication tokens an...

Mar 4, 2026
CVE-2023-25574
10.0

CVE-2023-25574 is a critical authentication bypass vulnerability in jupyterhub-ltiauthenticator's LTI13Authenticator that fails to validate JWT signat...

Feb 25, 2025
CVE-2024-45409
10.0

CVE-2024-45409 is a critical authentication bypass vulnerability in the Ruby SAML library where SAML response signatures are not properly verified. Th...

Sep 10, 2024
CVE-2024-32962
10.0

xml-crypto versions 4.0.0 through 5.x have a critical signature validation bypass vulnerability. Attackers can forge XML signatures by replacing certi...

May 2, 2024
CVE-2022-24884
10.0

This vulnerability in ecdsautils allows attackers to forge ECDSA signatures by providing zero-value signatures that are always considered valid. This ...

May 6, 2022
CVE-2021-33885
10.0

CVE-2021-33885 allows remote unauthenticated attackers to send malicious data to B. Braun SpaceCom2 devices that will be accepted without cryptographi...

Aug 25, 2021
CVE-2024-21669
9.9

This vulnerability in Hyperledger Aries Cloud Agent Python (ACA-Py) allows attackers to present forged verifiable credentials and enables malicious ve...

Jan 11, 2024
CVE-2026-23518
9.8

This vulnerability in Fleet's Windows MDM enrollment flow allows attackers to bypass authentication by submitting forged JWT tokens that aren't proper...

Jan 21, 2026
CVE-2025-9485
9.8

The OAuth Single Sign On plugin for WordPress has a critical authentication bypass vulnerability. Unauthenticated attackers can forge JWT tokens to ga...

Oct 4, 2025
CVE-2025-8454
9.8

CVE-2025-8454 is a critical vulnerability in the uscan tool (part of devscripts) that allows attackers to bypass OpenPGP signature verification when u...

Aug 1, 2025
CVE-2025-25291
EPSS 13.8% 9.8

CVE-2025-25291 is an authentication bypass vulnerability in ruby-saml that allows attackers to bypass SAML single sign-on authentication via signature...

Mar 12, 2025
CVE-2025-27670
9.8

CVE-2025-27670 is a critical vulnerability in Vasion Print (formerly PrinterLogic) that allows attackers to bypass signature validation mechanisms. Th...

Mar 5, 2025
CVE-2024-6800
9.8

An XML signature wrapping vulnerability in GitHub Enterprise Server's SAML authentication allows attackers with network access to forge SAML responses...

Aug 20, 2024
CVE-2018-25099
9.8

This vulnerability in the CryptX Perl module allows attackers to bypass authentication and integrity checks in cryptographic operations. It affects ap...

Mar 18, 2024
CVE-2024-21917
9.8

This vulnerability in Rockwell Automation FactoryTalk Service Platform allows attackers to steal service tokens and use them to authenticate to other ...

Jan 31, 2024
CVE-2023-44077
9.8

This vulnerability in Studio Network Solutions ShareBrowser on macOS allows attackers to bypass signature verification, potentially enabling arbitrary...

Jan 17, 2024
CVE-2016-20021
9.8

CVE-2016-20021 is a critical vulnerability in Gentoo Portage's emerge-webrsync tool that fails to validate PGP signatures on downloaded code. This all...

Jan 12, 2024
CVE-2023-28610
9.8

This vulnerability allows remote attackers to gain root access to OMICRON StationGuard and StationScout systems by exploiting the update process with ...

Mar 23, 2023
CVE-2023-25718
9.8

This vulnerability in ConnectWise Control (formerly ScreenConnect) allows attackers to modify signed executable files without invalidating their digit...

Feb 13, 2023
CVE-2021-36226
9.8

Western Digital My Cloud devices running firmware before OS5 lack cryptographic signature verification for firmware updates, allowing attackers to upl...

Feb 6, 2023
CVE-2022-31206
9.8

CVE-2022-31206 allows attackers to upload and execute arbitrary machine code on Omron SYSMAC PLCs due to lack of cryptographic authentication for down...

Jul 26, 2022
CVE-2022-31053
9.8

CVE-2022-31053 is a critical authentication bypass vulnerability in Biscuit v1 tokens that allows attackers to forge valid gamma signatures, enabling ...

Jun 13, 2022
CVE-2021-43568
9.8

This vulnerability allows attackers to forge digital signatures on arbitrary messages due to missing non-zero validation in the Stark Bank ECDSA libra...

Nov 9, 2021
CVE-2021-43570
9.8

This vulnerability allows attackers to forge digital signatures on arbitrary messages by exploiting a missing non-zero check in the Stark Bank Java EC...

Nov 9, 2021
CVE-2021-43572
9.8

This vulnerability in the Stark Bank Python ECDSA library allows attackers to forge digital signatures on arbitrary messages due to missing validation...

Nov 9, 2021
CVE-2021-37160
9.8

CVE-2021-37160 is a critical firmware validation bypass vulnerability in Swisslog Healthcare Nexus Panel HMI3 Control Panel. It allows attackers to up...

Aug 2, 2021
CVE-2021-32685
9.8

This vulnerability in tEnvoy's NaCl signature verification allows attackers to forge signatures by providing any invalid signature that matches the SH...

Jun 16, 2021
CVE-2021-22160
9.8

This vulnerability in Apache Pulsar allows attackers to bypass JWT token authentication by using tokens with the 'none' algorithm, which are not prope...

May 26, 2021
CVE-2021-3406
9.8

CVE-2021-3406 is a critical vulnerability in Keylime versions 5.8.1 and older that breaks the cryptographic chain of trust from hardware endorsement k...

Feb 25, 2021
CVE-2025-59334
9.6

Linkr versions through 2.0.0 fail to verify the integrity of .linkr manifest files, allowing attackers to inject malicious file entries into package d...

Sep 16, 2025
CVE-2025-54982
9.6

This vulnerability allows attackers to bypass SAML authentication in Zscaler's identity provider implementation by exploiting improper cryptographic s...

Aug 5, 2025
CVE-2025-32977
9.6

This vulnerability allows unauthenticated attackers to upload malicious backup files to Quest KACE Systems Management Appliance due to weaknesses in s...

Jun 24, 2025
CVE-2023-28801
9.6

CVE-2023-28801 is an improper cryptographic signature verification vulnerability in Zscaler's SAML authentication for the Admin UI. This allows attack...

Aug 31, 2023
CVE-2025-40934
9.3

CVE-2025-40934 is a critical signature validation bypass vulnerability in XML-Sig Perl module versions 0.27 through 0.67. Attackers can remove signatu...

Nov 26, 2025
CVE-2023-49079
9.3

This vulnerability in Misskey allows arbitrary users to impersonate any remote user due to missing signature validation in the decentralized social me...

Nov 29, 2023
CVE-2020-26290
9.3

This vulnerability in Dex's SAML connector allows attackers to bypass XML signature validation through XML encoding issues in the underlying Go librar...

Dec 28, 2020
CVE-2025-66567
9.1

The ruby-saml library contains an authentication bypass vulnerability due to XML parsing differences between ReXML and Nokogiri, allowing attackers to...

Dec 9, 2025
CVE-2025-66568
9.1

The ruby-saml library versions up to 1.12.4 are vulnerable to authentication bypass via Signature Wrapping attacks. Attackers can exploit libxml2's ca...

Dec 9, 2025
CVE-2025-57801
9.1

This vulnerability in gnark's signature verification allows signature malleability, enabling multiple distinct witnesses to satisfy the same public in...

Aug 22, 2025
CVE-2025-43023
9.1

This vulnerability involves HP Linux Imaging and Printing Software using a weak DSA signing key for code signing, which could allow attackers to forge...

Jul 28, 2025
CVE-2024-54150
9.1

CVE-2024-54150 is an algorithm confusion vulnerability in cjwt, a C JSON Web Token implementation. Attackers can forge JWT signatures by exploiting im...

Dec 19, 2024
CVE-2024-47073
9.1

This vulnerability allows attackers to forge JWT tokens due to missing signature verification in DataEase. Attackers can gain unauthorized access to a...

Nov 7, 2024
CVE-2024-9487
9.1

This vulnerability allows attackers to bypass SAML SSO authentication in GitHub Enterprise Server by exploiting improper cryptographic signature verif...

Oct 10, 2024
CVE-2024-42461
9.1

This vulnerability in the Elliptic package for Node.js allows attackers to create multiple valid signatures for the same message due to BER-encoded si...

Aug 2, 2024
CVE-2023-52538
9.1

This vulnerability allows attackers to bypass package name verification in the HwIms module, potentially disrupting services. It affects Huawei device...

Apr 8, 2024
CVE-2023-34205
9.1

CVE-2023-34205 is a signature validation bypass vulnerability in Moov signedxml library. Attackers can manipulate XML signatures through signature wra...

May 30, 2023
CVE-2020-35169
9.1

CVE-2020-35169 is an improper input validation vulnerability in Dell BSAFE cryptographic libraries that could allow attackers to execute arbitrary cod...

Jul 11, 2022
CVE-2022-23610
9.1

This vulnerability allows attackers to bypass SAML SSO authentication in wire-server and impersonate any user with SAML credentials. It affects all wi...

Mar 16, 2022
CVE-2021-20487
9.1

This vulnerability allows a privileged user to inject malicious code into IBM Power9 Self Boot Engine (SBE), bypassing firmware signature verification...

May 26, 2021
CVE-2021-29451
9.1

This vulnerability in Portofino web framework allows attackers to forge valid JSON Web Tokens due to improper signature verification. This affects all...

Apr 16, 2021

About CWE-347 (CWE-347)

Our database tracks 182 CVEs classified as CWE-347, with 54 rated critical and 92 rated high severity. The average CVSS score for CWE-347 vulnerabilities is 7.9.

External reference: View CWE-347 on MITRE CWE →

Monitor CWE-347 Vulnerabilities

Get alerted when new CWE-347 CVEs affect your infrastructure.

Start Monitoring Free