Vulnerability index

Browse CVEs

1,344 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Certificate ValidationCWE-295 × clear
Vigor166 Firmware HIGH 8.8
CVE-2024-41334

Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.9.8.8, Vigor 2860/2925 prior to v3.9.7, Vigor 2862/2926 prior to v3.9.9…

Fix: 3.9.7 / 3.9.8+
Fix from $1,950 2025-02-27
Debian Linux HIGH 7.4
CVE-2024-55581

When AdaCore Ada Web Server 25.0.0 is linked with GnuTLS, the default behaviour of AWS.Client is vulnerable to a man-in-the-middle attack because of …

No fix yet
Fix from $1,950 2025-02-26
Isolarcloud HIGH 7.4
CVE-2024-50691

SunGrow iSolarCloud Android app V2.1.6.20241104 and prior suffers from Missing SSL Certificate Validation. The app explicitly ignores certificate err…

Fix: 2.1.6.20241115+
Fix from $1,950 2025-02-26
Unclassified MEDIUM 5.7
CVE-2025-1001

Medixant RadiAnt DICOM Viewer is vulnerable due to failure of the update mechanism to verify the update server's certificate which could allow an att…

Mitigation only
Fix from $1,600 2025-02-21
Openpages With Watson HIGH 8.2
CVE-2024-49782

IBM OpenPages with Watson 8.3 and 9.0  could allow a remote attacker to spoof mail server identity when using SSL/TLS security. An attacker could …

Fix: 8.3.0.3 / 9.0.0.5+
Fix from $1,950 2025-02-20
Bsafe Ssl J HIGH 7.5
CVE-2024-29171

Dell BSAFE SSL-J, versions prior to 6.6 and versions 7.0 through 7.2, contains an Improper certificate verification vulnerability. A remote attacker …

Fix: 6.6 / 7.2.1+
Fix from $1,950 2025-02-12
Dicom Viewer MEDIUM 5.3
CVE-2025-1002

MicroDicom DICOM Viewer version 2024.03 fails to adequately verify the update server's certificate, which could make it possible for attackers in a …

Mitigation only
Fix from $1,600 2025-02-10
Remote Desktop Manager HIGH 8.1
CVE-2025-1193

Improper host validation in the certificate validation component in Devolutions Remote Desktop Manager on 2024.3.19 and earlier on Windows allows an …

Fix: 2024.3.20.0+
Fix from $1,950 2025-02-10
Remote Desktop Manager HIGH 8.8
CVE-2024-11621

Missing certificate validation in Devolutions Remote Desktop Manager on macOS, iOS, Android, Linux allows an attacker to intercept and modify encrypt…

Fix: 2024.3.2.9 / 2024.3.4.0+
Fix from $1,950 2025-02-10
Unclassified HIGH 8.1
CVE-2024-47258

2N Access Commander version 2.1 and prior is vulnerable in default settings to Man In The Middle attack due to not verifying certificates of 2N edge …

Mitigation only
Fix from $1,950 2025-02-06
Unclassified CRITICAL 9.0
CVE-2025-23114

A vulnerability in Veeam Updater component allows Man-in-the-Middle attackers to execute arbitrary code on the affected server. This issue occurs due…

Mitigation only
Fix from $2,300 2025-02-05
Firefox HIGH 8.8
CVE-2025-1014

Certificate length was not properly checked when added to a certificate store. In practice only trusted data was processed. This vulnerability was fi…

Fix: 128.7.0 / 135.0+
Fix from $1,950 2025-02-04
Unclassified MEDIUM 5.9
CVE-2025-23091

An Improper Certificate Validation on UniFi OS devices, with Identity Enterprise configured, could allow a malicious actor to execute a man-in-the-mi…

Mitigation only
Fix from $1,600 2025-02-01
Dmh Wt7600nex Firmware MEDIUM 6.5
CVE-2024-23928

This vulnerability allows network-adjacent attackers to compromise the integrity of downloaded information on affected installations of Pioneer DMH-W…

Mitigation only
Fix from $1,600 2025-01-31
Home Flex Nema 14 50 Plug Firmware MEDIUM 6.5
CVE-2024-23970

This vulnerability allows network-adjacent attackers to compromise transport security on affected installations of ChargePoint Home Flex charging sta…

Mitigation only
Fix from $1,600 2025-01-31
Cognos Analytics MEDIUM 5.9
CVE-2023-38009

IBM Cognos Mobile Client 1.1 iOS may be vulnerable to information disclosure through man in the middle techniques due to the lack of certificate pinn…

Mitigation only
Fix from $1,600 2025-01-26
Home HIGH 7.4
CVE-2024-52329

ECOVACS HOME mobile app plugins for specific robots do not properly validate TLS certificates. An unauthenticated attacker can read or modify TLS tra…

Fix: 3.0.0+
Fix from $1,950 2025-01-23
Deebot X2 Omni Firmware HIGH 7.4
CVE-2024-52330

ECOVACS lawnmowers and vacuums do not properly validate TLS certificates. An unauthenticated attacker can read or modify TLS traffic, possibly modify…

Fix: 1.17.0 / 1.38.0+
Fix from $1,950 2025-01-23
Unclassified HIGH 7.5
CVE-2025-0500

An issue in the native clients for Amazon WorkSpaces (when running Amazon DCV protocol), Amazon AppStream 2.0, and Amazon DCV Clients may allow an at…

Mitigation only
Fix from $1,950 2025-01-15
Unclassified HIGH 7.5
CVE-2025-0501

An issue in the native clients for Amazon WorkSpaces (when running PCoIP protocol) may allow an attacker to access remote sessions via man-in-the-mid…

Mitigation only
Fix from $1,950 2025-01-15
Cp Vnr 3104 Firmware MEDIUM 5.9
CVE-2024-54847

An issue in CP Plus CP-VNR-3104 B3223P22C02424 allows attackers to access the Diffie-Hellman (DH) parameters and access sensitive data or execute a m…

No fix yet
Fix from $1,600 2025-01-10
Cp Vnr 3104 Firmware HIGH 7.4
CVE-2024-54848

Improper handling and storage of certificates in CP Plus CP-VNR-3104 B3223P22C02424 allow attackers to decrypt communications or execute a man-in-the…

No fix yet
Fix from $1,950 2025-01-10
Cp Vnr 3104 Firmware MEDIUM 5.9
CVE-2024-54849

An issue in CP Plus CP-VNR-3104 B3223P22C02424 allows attackers to obtain the second RSA private key and access sensitive data or execute a man-in-th…

No fix yet
Fix from $1,600 2025-01-10
Cp Vnr 3104 Firmware MEDIUM 5.9
CVE-2024-54846

An issue in CP Plus CP-VNR-3104 B3223P22C02424 allows attackers to obtain the EC private key and access sensitive data or execute a man-in-the-middle…

No fix yet
Fix from $1,600 2025-01-10
Cognos Controller HIGH 8.2
CVE-2024-40702

IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 could allow an unauthorized user to obtain valid tokens to gain access to prote…

Fix: after 11.0.1
Fix from $1,950 2025-01-07
Tcpdf CRITICAL 9.8
CVE-2024-56521

An issue was discovered in TCPDF before 6.8.0. If libcurl is used, CURLOPT_SSL_VERIFYHOST and CURLOPT_SSL_VERIFYPEER are set unsafely.

Fix: 6.8.0+
Fix from $2,300 2024-12-27
Storage Defender Resiliency Service HIGH 7.5
CVE-2024-47119

IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.9 does not properly validate a certificate which could allow an attacker to spoof a trust…

Fix: after 2.0.9
Fix from $1,950 2024-12-18
Unclassified HIGH 8.1
CVE-2024-6001

An improper certificate validation vulnerability was reported in LADM that could allow a network attacker with the ability to redirect an update requ…

Mitigation only
Fix from $1,950 2024-12-16
Unclassified HIGH 7.8
CVE-2024-4762

An improper validation vulnerability was reported in the firmware update mechanism of LADM and LDCC that could allow a local attacker to escalate pri…

Mitigation only
Fix from $1,950 2024-12-16
Unclassified HIGH 7.1
CVE-2024-21543

Versions of the package djoser before 2.3.0 are vulnerable to Authentication Bypass when the authenticate() function fails. This is because the syste…

Patch available
Fix from $1,950 2024-12-13