Vulnerability index

Browse CVEs

1,344 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Certificate ValidationCWE-295 × clear
Unclassified MEDIUM 6.8
CVE-2024-54147

Altair is a GraphQL client for all platforms. Prior to version 8.0.5, Altair GraphQL Client's desktop app does not validate HTTPS certificates allowi…

Mitigation only
Fix from $1,600 2024-12-09
Qts HIGH 7.5
CVE-2024-48865

An improper certificate validation vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability …

Mitigation only
Fix from $1,950 2024-12-06
Unclassified MEDIUM 5.5
CVE-2024-53846

OTP is a set of Erlang libraries, which consists of the Erlang runtime system, a number of ready-to-use components mainly written in Erlang, and a se…

Mitigation only
Fix from $1,600 2024-12-05
Unclassified HIGH 7.1
CVE-2024-45205

An Improper Certificate Validation on the UniFi iOS App managing a standalone UniFi Access Point (not using UniFi Network Application) could allow a …

Mitigation only
Fix from $1,950 2024-12-04
Globalprotect HIGH 8.8
CVE-2024-5921

An insufficient certification validation issue in the Palo Alto Networks GlobalProtect app enables attackers to connect the GlobalProtect app to arbi…

Fix: 6.1.6 / 6.1.7+
Fix from $1,950 2024-11-27
Rax30 Firmware HIGH 7.5
CVE-2023-51634

NETGEAR RAX30 Improper Certificate Validation Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to compromise…

Fix: 1.0.12.100_hotfix+
Fix from $1,950 2024-11-22
Desktop HIGH 7.5
CVE-2024-52510

The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with your computer. The Desktop client did not stop with an error b…

Fix: 3.14.2+
Fix from $1,950 2024-11-15
Telepresence Video Communication Server HIGH 7.4
CVE-2022-20814

A vulnerability in the certificate validation of Cisco Expressway-C and Cisco TelePresence VCS could allow an unauthenticated, remote attac…

Mitigation only
Fix from $1,950 2024-11-15
Debian Linux CRITICAL 9.8
CVE-2024-49369

Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for repor…

Fix: 2.11.12 / 2.12.11+
Fix from $2,300 2024-11-12
Unclassified CRITICAL 9.8
CVE-2019-20461

An issue was discovered on Alecto IVM-100 2019-11-12 devices. The device uses a custom UDP protocol to start and control video and audio services. Th…

Mitigation only
Fix from $2,300 2024-11-07
Qbittorrent HIGH 8.1
CVE-2024-51774

qBittorrent before 5.0.1 proceeds with use of https URLs even after certificate validation errors.

Fix: 5.0.1+
Fix from $1,950 2024-11-02
Appscan Source MEDIUM 6.5
CVE-2024-30149

HCL AppScan Source <= 10.6.0 does not properly validate a TLS/SSL certificate for an executable.

Fix: 10.7.0+
Fix from $1,600 2024-10-31
Concert CRITICAL 9.8
CVE-2024-43177

IBM Concert 1.0.0 and 1.0.1 vulnerable to attacks that rely on the use of cookies without the SameSite attribute.

Mitigation only
Fix from $2,300 2024-10-22
Secure Connect Gateway HIGH 8.1
CVE-2024-47241

Dell Secure Connect Gateway (SCG) 5.0 Appliance - SRS, version(s) 5.24, contains an Improper Certificate Validation vulnerability. A low privileged a…

Mitigation only
Fix from $1,950 2024-10-18
Total Security HIGH 7.4
CVE-2023-49570

A vulnerability has been identified in Bitdefender Total Security HTTPS scanning functionality where the software trusts a certificate issued by an e…

Fix: 27.0.25.115+
Fix from $1,950 2024-10-18
Total Security MEDIUM 6.8
CVE-2023-49567

A vulnerability has been identified in the Bitdefender Total Security HTTPS scanning functionality where the product incorrectly checks the site's ce…

Fix: 27.0.25.115+
Fix from $1,600 2024-10-18
Total Security HIGH 7.4
CVE-2023-6055

A vulnerability has been identified in Bitdefender Total Security HTTPS scanning functionality where the software fails to properly validate website …

Fix: 27.0.25.115+
Fix from $1,950 2024-10-18
Total Security HIGH 7.4
CVE-2023-6056

A vulnerability has been discovered in Bitdefender Total Security HTTPS scanning functionality that results in the improper trust of self-signed cert…

Fix: 27.0.25.115+
Fix from $1,950 2024-10-18
Total Security HIGH 7.4
CVE-2023-6057

A vulnerability has been discovered in Bitdefender Total Security HTTPS scanning functionality that results in the improper trust of certificates iss…

Fix: 27.0.25.115+
Fix from $1,950 2024-10-18
Total Security MEDIUM 6.8
CVE-2023-6058

A vulnerability has been identified in Bitdefender Safepay's handling of HTTPS connections. The issue arises when the product blocks a connection due…

Fix: 27.0.25.115+
Fix from $1,600 2024-10-18
Unclassified HIGH 8.0
CVE-2024-22030

A vulnerability has been identified within Rancher that can be exploited in narrow circumstances through a man-in-the-middle (MITM) attack. An atta…

Mitigation only
Fix from $1,950 2024-10-16
Unclassified HIGH 8.7
CVE-2024-48915

Agent Dart is an agent library built for Internet Computer for Dart and Flutter apps. Prior to version 1.0.0-dev.29, certificate verification in `lib…

Patch available
Fix from $1,950 2024-10-15
Windows 10 1507 HIGH 7.4
CVE-2024-43550

Windows Secure Channel Spoofing Vulnerability

Fix: 10.0.10240.20796 / 10.0.14393.7428+
Fix from $1,950 2024-10-08
Unclassified HIGH 7.0
CVE-2024-7206

SSL Pinning Bypass in eWeLink Some hardware products allows local ATTACKER to Decrypt TLS communication and Extract secrets to clone the device via F…

Mitigation only
Fix from $1,950 2024-10-08
Nexus Dashboard Orchestrator MEDIUM 5.9
CVE-2024-20385

A vulnerability in the SSL/TLS implementation of Cisco Nexus Dashboard Orchestrator (NDO) could allow an unauthenticated, remote attacker to intercep…

Fix: 4.2 / 4.4+
Fix from $1,600 2024-10-02
Unclassified MEDIUM 5.4
CVE-2024-9160

In versions of the PEADM Forge Module prior to 3.24.0 a security misconfiguration was discovered.

No fix yet
Fix from $1,600 2024-09-27
Mikrotik HIGH 7.4
CVE-2024-38861

Improper Certificate Validation in Checkmk Exchange plugin MikroTik allows attackers in MitM position to intercept traffic. This issue affects MikroT…

Fix: after 2.5.5
Fix from $1,950 2024-09-27
Traveler For Microsoft Outlook HIGH 7.5
CVE-2024-30134

The HCL Traveler for Microsoft Outlook executable (HTMO.exe) is being flagged as potentially Malicious Software or an Unrecognized Application.

Fix: 3.0.9+
Fix from $1,950 2024-09-26
Storage Defender MEDIUM 6.5
CVE-2024-38324

IBM Storage Defender 2.0.0 through 2.0.7 on-prem defender-sensor-cmd CLI does not validate server name during registration and unregistration operati…

Fix: 2.0.8+
Fix from $1,600 2024-09-25
Planet Fitness Workouts MEDIUM 5.9
CVE-2024-43201

The Planet Fitness Workouts iOS and Android mobile apps fail to properly validate TLS certificates, allowing an attacker with appropriate network acc…

Fix: 9.8.12+
Fix from $1,600 2024-09-23