Vulnerability index

Browse CVEs

1,344 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Certificate ValidationCWE-295 × clear
Anbox Cloud HIGH 7.5
CVE-2024-8287

Anbox Management Service, in versions 1.17.0 through 1.23.0, does not validate the TLS certificate provided to it by the Anbox Stream Agent. An attac…

Fix: 1.23.1+
Fix from $1,950 2024-09-18
Curl MEDIUM 6.5
CVE-2024-8096

When curl is told to use the Certificate Status Request TLS extension, often referred to as OCSP stapling, to verify that the server certificate is v…

Fix: 8.10.0+
Fix from $1,600 2024-09-11
Forticlient HIGH 8.1
CVE-2024-31489

AAn improper certificate validation vulnerability [CWE-295] in FortiClientWindows 7.2.0 through 7.2.2, 7.0.0 through 7.0.11, FortiClientLinux 7.2.0,…

Fix: 7.0.12 / 7.2.3+
Fix from $1,950 2024-09-10
Forticlient MEDIUM 5.9
CVE-2022-45856

An improper certificate validation vulnerability [CWE-295] in FortiClientWindows 6.4 all versions, 7.0.0 through 7.0.7, FortiClientMac 6.4 all versio…

Fix: 7.0.7 / 7.0.8+
Fix from $1,600 2024-09-10
Veeam Backup \& Replication HIGH 8.3
CVE-2024-40714

An improper certificate validation vulnerability in TLS certificate validation allows an attacker on the same network to intercept sensitive credenti…

Fix: 12.2.0.334+
Fix from $1,950 2024-09-07
Qumagie HIGH 7.8
CVE-2024-38642

An improper certificate validation vulnerability has been reported to affect QuMagie. If exploited, the vulnerability could allow local network users…

Mitigation only
Fix from $1,950 2024-09-06
Mbed Tls CRITICAL 9.8
CVE-2024-45159

An issue was discovered in Mbed TLS 3.x before 3.6.1. With TLS 1.3, when a server enables optional authentication of the client, if the client-provid…

Fix: 3.6.1+
Fix from $2,300 2024-09-05
Kroxylicious MEDIUM 5.9
CVE-2024-8285

A flaw was found in Kroxylicious. When establishing the connection with the upstream Kafka server using a TLS secured connection, Kroxylicious fails …

Mitigation only
Fix from $1,600 2024-08-30
Qbic Cloud Cc 2\/2l Firmware MEDIUM 6.8
CVE-2024-39771

QBiC CLOUD CC-2L v1.1.30 and earlier and Safie One v1.8.2 and earlier do not properly validate certificates, which may allow a network-adjacent unaut…

Fix: after 1.8.2
Fix from $1,600 2024-08-28
Unclassified HIGH 7.5
CVE-2024-41996

Validating the order of the public keys in the Diffie-Hellman Key Agreement Protocol, when an approved safe prime is used, allows remote attackers (f…

Mitigation only
Fix from $1,950 2024-08-26
Fort Validator HIGH 7.5
CVE-2024-45234

An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) a…

Fix: 1.6.3+
Fix from $1,950 2024-08-24
Unclassified HIGH 8.2
CVE-2024-37311

Collabora Online is a collaborative online office suite based on LibreOffice. In affected versions of Collabora Online, https connections from coolws…

Mitigation only
Fix from $1,950 2024-08-23
Openstack Platform HIGH 8.1
CVE-2024-8007

A flaw was found in the openstack-tripleo-common component of the Red Hat OpenStack Platform (RHOSP) director. This vulnerability allows an attacker …

Mitigation only
Fix from $1,950 2024-08-21
Nest Mini Firmware MEDIUM 5.9
CVE-2024-32928

The libcurl CURLOPT_SSL_VERIFYPEER option was disabled on a subset of requests made by Nest production devices which enabled a potential man-in-the-m…

Mitigation only
Fix from $1,600 2024-08-19
Websphere Application Server HIGH 7.5
CVE-2023-50314

IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.8 could allow an attacker with access to the network to conduct spoofing attacks. A…

Fix: after 24.0.0.8
Fix from $1,950 2024-08-14
Websphere Application Server MEDIUM 5.9
CVE-2023-50315

IBM WebSphere Application Server 8.5 and 9.0 could allow an attacker with access to the network to conduct spoofing attacks. An attacker could explo…

Mitigation only
Fix from $1,600 2024-08-14
Neurons For Itsm HIGH 8.1
CVE-2024-7570

Improper certificate validation in Ivanti ITSM on-prem and Neurons for ITSM Versions 2023.4 and earlier allows a remote attacker in a MITM position t…

Patch available
Fix from $1,950 2024-08-13
Arubaos CRITICAL 9.8
CVE-2024-42395

There is a vulnerability in the AP Certificate Management Service which could allow a threat actor to execute an unauthenticated RCE attack. Successf…

Fix: 8.10.0.13 / 8.12.0.2+
Fix from $2,300 2024-08-06
Unclassified HIGH 7.4
CVE-2024-7383

A flaw was found in libnbd. The client did not always correctly verify the NBD server's certificate when using TLS to connect to an NBD server. This …

Mitigation only
Fix from $1,950 2024-08-05
Libreoffice HIGH 7.8
CVE-2024-6472

Certificate Validation user interface in LibreOffice allows potential vulnerability. Signed macros are scripts that have been digitally signed by…

Fix: 24.2.5.1+
Fix from $1,950 2024-08-05
Exacqvision Server HIGH 7.3
CVE-2024-32865

Under certain circumstances the exacqVision Server will not properly validate TLS certificates provided by connected devices.

Fix: 24.06+
Fix from $1,950 2024-08-01
Casdoor HIGH 7.5
CVE-2024-41264

An issue discovered in casdoor v1.636.0 allows attackers to obtain sensitive information via the ssh.InsecureIgnoreHostKey() method.

Mitigation only
Fix from $1,950 2024-08-01
Filestash MEDIUM 5.9
CVE-2024-41256

Default configurations in the ShareProofVerifier function of filestash v0.4 causes the application to skip the TLS certificate verification process w…

Fix: after 0.4
Fix from $1,600 2024-07-31
Filestash MEDIUM 5.3
CVE-2024-41258

An issue was discovered in filestash v0.4. The usage of the ssh.InsecureIgnoreHostKey() disables host key verification, possibly allowing attackers t…

Fix: after 0.4
Fix from $1,600 2024-07-31
Beego HIGH 8.8
CVE-2024-40464

An issue in beego v.2.2.0 and before allows a remote attacker to escalate privileges via the sendMail function located in beego/core/logs/smtp.go file

Fix: 2.2.1+
Fix from $1,950 2024-07-31
Stork HIGH 8.1
CVE-2024-28872

The TLS certificate validation code is flawed. An attacker can obtain a TLS certificate from the Stork server and use it to connect to the Stork agen…

Fix: 1.15.1+
Fix from $1,950 2024-07-11
S3 Browser MEDIUM 5.9
CVE-2024-37865

An issue in S3Browser v.11.4.5 and v.10.9.9 and fixed in v.11.5.7 allows a remote attacker to obtain sensitive information via the S3 compatible stor…

Fix: 11.7.5+
Fix from $1,600 2024-07-09
Electron Builder HIGH 7.5
CVE-2024-39698

electron-updater allows for automatic updates for Electron apps. The file `packages/electron-updater/src/windowsExecutableCodeSignatureVerifier.ts` i…

Fix: 6.3.0+
Fix from $1,950 2024-07-09
Fortiadc HIGH 7.4
CVE-2023-50178

An improper certificate validation vulnerability [CWE-295] in FortiADC 7.4.0, 7.2.0 through 7.2.3, 7.1 all versions, 7.0 all versions, 6.2 all versio…

Fix: after 7.2.3
Fix from $1,950 2024-07-09
Fortiadc MEDIUM 5.9
CVE-2023-50179

An improper certificate validation vulnerability [CWE-295] in FortiADC 7.4.0, 7.2 all versions, 7.1 all versions, 7.0 all versions may allow a remote…

Fix: 7.4.1+
Fix from $1,600 2024-07-09