Vulnerability index

Browse CVEs

1,344 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Certificate ValidationCWE-295 × clear
Unclassified MEDIUM 5.1
CVE-2026-63336

The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.0, com.rabbitmq…

Fix unknown
Fix from $4,000 2026-08-18
Unclassified CRITICAL 9.1
CVE-2026-52723

ePA 3.x Integration implements the authorization workflow and writes Medical Information Objects to Germany's electronic patient record. Prior to 1.3…

Fix unknown
Fix from $5,750 2026-08-18
Unclassified HIGH 7.5
CVE-2026-50578

ePA 3.x Integration implements the authorization workflow and writes Medical Information Objects to Germany's electronic patient record. Prior to 1.3…

Fix unknown
Fix from $4,900 2026-08-18
Unclassified HIGH 7.4
CVE-2026-59825

Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.19 and from 4.5.0 until 4.5.12, Mastodon's app/models/concer…

Fix unknown
Fix from $4,900 2026-08-18
Unclassified CRITICAL 9.1
CVE-2026-66795

A flaw was found in the managedcluster-import-controller. The Certificate Signing Request (CSR) auto-approval logic improperly validates incoming CSR…

Fix unknown
Fix from $5,750 2026-08-17
Unclassified CRITICAL 9.1
CVE-2026-49457

erlang_quic is a pure Erlang QUIC implementation. Prior to version 1.4.4, the QUIC client did not authenticate the server during the TLS 1.3 handshak…

No fix yet
Fix from $5,750 2026-08-14
Unclassified HIGH 7.5
CVE-2026-54481

Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override (CWE-295)

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 8.0
CVE-2026-70454

rsync 3.2.0 through 3.2.3 (openssl mode) and rsync-ssl through 3.4.4 (stunnel mode) contain a TLS certificate validation vulnerability that allows on…

No fix yet
Fix from $4,900 2026-08-13
Unclassified MEDIUM 5.8
CVE-2026-18679

When kuma-dp is started against an HTTPS control plane and the operator did not pass a CA certificate, the data plane connects with TLS peer verifica…

No fix yet
Fix from $4,000 2026-08-12
Unclassified MEDIUM 5.5
CVE-2026-18678

When an operator adds an HTTPS control plane profile to kumactl without providing a CA certificate, kumactl disables TLS verification and sends API t…

No fix yet
Fix from $4,000 2026-08-12
Httpclient CRITICAL 9.1
CVE-2026-71290

Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. HostnameVerificationPolicy#BUILTIN setting has no effe…

No fix yet
Fix from $5,750 2026-08-11
Unclassified HIGH 8.3
CVE-2026-66154

An insufficient certificate validation in a privileged communication workflow, was identified in a GMS application 9.5.1 (Build 9510.1044) and earlie…

No fix yet
Fix from $4,900 2026-08-11
C2pa MEDIUM 5.5
CVE-2026-48437

CAI Content Credentials is affected by an Improper Certificate Validation vulnerability that could result in a Security feature bypass. An attacker c…

Fix: 0.12.1 / 0.27.6+
Fix from $4,000 2026-08-11
Unclassified HIGH 8.1
CVE-2026-18129

Cleartext transmission of sensitive information in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a remote unauthenticated attack…

No fix yet
Fix from $4,900 2026-08-11
Unclassified HIGH 7.4
CVE-2026-15554

the Undertow AJP listener honours forged ssl_cert and is_ssl AJP attributes without requiring any shared-secret authentication. This enables an unaut…

No fix yet
Fix from $4,900 2026-08-11
Unclassified MEDIUM 6.4
CVE-2026-66760

SAP Approuter does not correctly validate client certificates in certain callback flows. An attacker with low privileges, holding a certificate from …

No fix yet
Fix from $4,000 2026-08-11
Unclassified MEDIUM 6.5
CVE-2026-66404

DEEBOT PRO M1 and DEEBOT PRO K1VAC do not validate server certificates in MQTT communications. Operation logs and activity logs stored on the affecte…

No fix yet
Fix from $4,000 2026-08-10
Rvtools CRITICAL 9.1
CVE-2026-64993

Dell RVTools versions prior to 4.8.1, contains an improper certificate validation vulnerability in the collector. A remote unauthenticated attacker c…

Fix: 4.8.1+
Fix from $2,300 2026-08-06
Unclassified MEDIUM 6.1
CVE-2026-16792

An improper certificate validation vulnerability was reported in multiple Lenovo XClarity Orchestrator (LXCO) 2.2.0 microservices that could allow an…

No fix yet
Fix from $1,600 2026-08-04
Unclassified MEDIUM 6.9
CVE-2026-69248

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 49.0.0, if an intermediate constrain…

No fix yet
Fix from $1,600 2026-08-03
Unclassified HIGH 7.4
CVE-2026-67598

Emlog Pro through 2.6.23 contains a disabled TLS certificate validation vulnerability in include/service/ai.php that allows network-adjacent attacker…

No fix yet
Fix from $1,950 2026-08-03
Omada Fusion 2.5g Firmware MEDIUM 6.5
CVE-2025-9291

A certification validation weakness exists in communication between affected Omada devices and cloud controllers. Certificate identity verification d…

No fix yet
Fix from $1,600 2026-08-03
Net\ HIGH 7.5
CVE-2026-18089

Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass by verifying responses against the response-embedded certificate in verify_…

Fix: 0.86+
Fix from $1,950 2026-08-03
Unclassified HIGH 7.3
CVE-2026-0392

eParakstītājs 3.0 for Windows before version 1.10.0 retrieves and executes its automatic updates over a channel that is not authenticated or integrit…

No fix yet
Fix from $1,950 2026-08-03
Unclassified CRITICAL 9.3
CVE-2026-58062

In Bouncy Castle for Java before 1.85, Stapled OCSP response accepted without binding to the checked certificate. This issue also affects Bouncy Cast…

No fix yet
Fix from $2,300 2026-08-03
Unclassified CRITICAL 9.3
CVE-2026-8763

In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in rfc822Name and URI. This issue also affects Bouncy Castle for Java…

Mitigation only
Fix from $2,300 2026-08-03
Unclassified MEDIUM 5.9
CVE-2026-67294

FreeRDP before 3.29.0 improperly validates the Extended Key Usage (EKU) purpose of the peer certificate during client-side server TLS authentication.…

No fix yet
Fix from $1,600 2026-08-01
Unclassified CRITICAL 9.8
CVE-2026-66402

FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains multiple TLS certificate identity validation weaknesses in tls_verify_certificate(), tls…

No fix yet
Fix from $2,300 2026-08-01
Unclassified HIGH 8.2
CVE-2026-18141

A flaw was found in aap-gateway, a component of Ansible Automation Platform's Event-Driven Ansible (EDA). An unauthenticated remote attacker can bypa…

No fix yet
Fix from $1,950 2026-07-31
Unclassified HIGH 7.4
CVE-2026-8497

Improper certificate validation in the Devolutions Server connection handling in Devolutions Password Manager 2026.2.1.0 and earlier on Android, iOS,…

No fix yet
Fix from $1,950 2026-07-29