Vulnerability index

Browse CVEs

1,344 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Certificate ValidationCWE-295 × clear
File Station HIGH 8.8
CVE-2025-29883

An improper certificate validation vulnerability has been reported to affect File Station 5. If exploited, the vulnerability could allow remote attac…

Fix: 5.5.6.4791+
Fix from $1,950 2025-06-06
File Station HIGH 8.8
CVE-2025-29884

An improper certificate validation vulnerability has been reported to affect File Station 5. If exploited, the vulnerability could allow remote attac…

Fix: 5.5.6.4791+
Fix from $1,950 2025-06-06
File Station HIGH 8.8
CVE-2025-29885

An improper certificate validation vulnerability has been reported to affect File Station 5. If exploited, the vulnerability could allow remote attac…

Fix: 5.5.6.4791+
Fix from $1,950 2025-06-06
File Station HIGH 8.8
CVE-2025-22486

An improper certificate validation vulnerability has been reported to affect File Station 5. If exploited, the vulnerability could allow remote attac…

Fix: 5.5.6.4791+
Fix from $1,950 2025-06-06
Curl MEDIUM 6.5
CVE-2025-4947

libcurl accidentally skips the certificate verification for QUIC connections when connecting to a host specified as an IP address in the URL. Therefo…

Fix: 8.14.0+
Fix from $1,600 2025-05-28
Unclassified HIGH 7.0
CVE-2025-5279

When the Amazon Redshift Python Connector is configured with the BrowserAzureOAuth2CredentialsProvider plugin, the driver skips the SSL certificate v…

Mitigation only
Fix from $1,950 2025-05-27
Unclassified MEDIUM 6.7
CVE-2024-13956

SSL Verification Bypass vulnerabilities exist in ASPECT if administrator credentials become compromisedThis issue affects ASPECT-Enterprise: through …

Mitigation only
Fix from $1,600 2025-05-22
OpenSSL MEDIUM 6.5
CVE-2025-4575

Issue summary: Use of -addreject option with the openssl x509 application adds a trusted use instead of a rejected use for a certificate. Impact sum…

Patch available
Fix from $1,600 2025-05-22
Security Qradar Edr MEDIUM 6.5
CVE-2024-45641

IBM Security ReaQta EDR 3.12 could allow an attacker to perform unauthorized actions due to improper SSL certificate validation.

Fix: 3.12.17+
Fix from $1,600 2025-05-20
Security Qradar Edr MEDIUM 6.5
CVE-2023-33861

IBM Security ReaQta EDR 3.12 could allow an attacker to spoof a trusted entity by interfering with the communication path between the host and client.

Fix: 3.12.17+
Fix from $1,600 2025-05-20
Internet MEDIUM 5.9
CVE-2025-32407

Samsung Internet for Galaxy Watch version 5.0.9, available up until Samsung Galaxy Watch 3, does not properly validate TLS certificates, allowing for…

No fix yet
Fix from $1,600 2025-05-16
Unclassified CRITICAL 9.4
CVE-2025-3463

"This issue is limited to motherboards and does not affect laptops, desktop computers, or other endpoints." An insufficient validation vulnerability …

Mitigation only
Fix from $2,300 2025-05-09
Catalyst Sd Wan Manager MEDIUM 5.9
CVE-2025-20157

A vulnerability in certificate validation processing of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an unauthenticated,…

Mitigation only
Fix from $1,600 2025-05-07
Debian Linux HIGH 7.5
CVE-2024-47619

syslog-ng is an enhanced log daemo. Prior to version 4.8.2, `tls_wildcard_match()` matches on certificates such as `foo.*.bar` although that is not a…

Fix: 4.8.2+
Fix from $1,950 2025-05-07
I MEDIUM 5.4
CVE-2025-3218

IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 is vulnerable to authentication and authorization attacks due to incorrect validation processing in IBM i Netserver…

Mitigation only
Fix from $1,600 2025-05-07
Unclassified MEDIUM 6.5
CVE-2025-37730

Improper certificate validation in Logstash's TCP output could lead to a man-in-the-middle (MitM) attack in “client” mode, as hostname verification i…

Mitigation only
Fix from $1,600 2025-05-06
Nr16 MEDIUM 5.7
CVE-2025-20670

In Modem, there is a possible permission bypass due to improper certificate validation. This could lead to remote information disclosure, if a UE has…

Mitigation only
Fix from $1,600 2025-05-05
Httpclient HIGH 7.5
CVE-2025-27820

A bug in PSL validation logic in Apache HttpClient 5.4.x disables domain checks, affecting cookie management and host name verification. Discovered b…

Fix: 5.4.3+
Fix from $1,950 2025-04-24
Unclassified HIGH 8.1
CVE-2025-28169

BYD QIN PLUS DM-i Dilink OS v3.0_13.1.7.2204050.1 to v3.0_13.1.7.2312290.1_0 was discovered to cend broadcasts to the manufacturer's cloud server une…

Mitigation only
Fix from $1,950 2025-04-23
Elastic Cloud Storage MEDIUM 6.5
CVE-2025-26478

Dell ECS version 3.8.1.4 and prior contain an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent network access…

Fix: 4.0.0.0+
Fix from $1,600 2025-04-17
Bigfix Platform HIGH 8.1
CVE-2024-42193

HCL BigFix Web Reports' service communicates over HTTPS but exhibits a weakness in its handling of SSL certificate validation. This scenario presents…

Fix: 10.0.13 / 11.0.4+
Fix from $1,950 2025-04-15
Unclassified MEDIUM 6.7
CVE-2025-30000

A vulnerability has been identified in Siemens License Server (SLS) (All versions < V4.3). The affected application does not properly restrict permis…

Mitigation only
Fix from $1,600 2025-04-08
Libreoffice MEDIUM 5.5
CVE-2021-25635

An Improper Certificate Validation vulnerability in LibreOffice allowed an attacker to self sign an ODF document, with a signature untrusted by the…

Fix: 7.0.5.1+
Fix from $1,600 2025-03-21
Unclassified MEDIUM 5.9
CVE-2025-0254

HCL Digital Experience components Ring API and dxclient may be vulnerable to man-in-the-middle (MitM) attacks prior to 9.5 CF226. An attacker could …

Mitigation only
Fix from $1,600 2025-03-20
Diskstation Manager HIGH 7.5
CVE-2024-10444

Improper certificate validation vulnerability in the LDAP utilities in Synology DiskStation Manager (DSM) before 7.1.1-42962-8, 7.2.1-69057-7 and 7.2…

Fix: 7.1.1-42962-8 / 7.2.1-69057-7+
Fix from $1,950 2025-03-19
Beestation Os MEDIUM 5.3
CVE-2024-10445

Improper certificate validation vulnerability in the update functionality in Synology BeeStation OS (BSM) before 1.1-65374 and Synology DiskStation M…

Fix: 6.2.4-25556-8 / 7.2.1-69057-6+
Fix from $1,600 2025-03-19
Unclassified HIGH 8.7
CVE-2024-41724

Improper Certificate Validation (CWE-295) in the Gallagher Command Centre SALTO integration allowed an attacker to spoof the SALTO server. This …

Mitigation only
Fix from $1,950 2025-03-10
Unclassified HIGH 7.2
CVE-2024-43107

Improper Certificate Validation (CWE-295) in the Gallagher Milestone Integration Plugin (MIP) permits unauthenticated messages (e.g. alarm events) to…

Mitigation only
Fix from $1,950 2025-03-10
Helpdesk HIGH 8.8
CVE-2024-50394

An improper certificate validation vulnerability has been reported to affect Helpdesk. If exploited, the vulnerability could allow remote attackers t…

Fix: 3.3.3+
Fix from $1,950 2025-03-07
Unclassified MEDIUM 6.4
CVE-2025-23118

An Improper Certificate Validation vulnerability could allow an authenticated malicious actor with access to UniFi Protect Cameras adjacent network t…

Mitigation only
Fix from $1,600 2025-03-01