Vulnerability index

Browse CVEs

1,344 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Certificate ValidationCWE-295 × clear
Botan MEDIUM 5.3
CVE-2024-39312

Botan is a C++ cryptography library. X.509 certificates can identify elliptic curves using either an object identifier or using explicit encoding of …

Fix: 2.19.5 / 3.5.0+
Fix from $1,600 2024-07-08
Yocto CRITICAL 9.8
CVE-2024-20080

In gnss service, there is a possible escalation of privilege due to improper certificate validation. This could lead to remote escalation of privileg…

Mitigation only
Fix from $2,300 2024-07-01
Cognos Analytics MEDIUM 5.9
CVE-2024-25053

IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, and 12.0.2 is vulnerable to improper certificate validation when using t…

Mitigation only
Fix from $1,600 2024-06-28
Libreoffice CRITICAL 9.8
CVE-2024-5261

Improper Certificate Validation vulnerability in LibreOffice "LibreOfficeKit" mode disables TLS certification verification LibreOfficeKit can be use…

Fix: 24.2.4+
Fix from $2,300 2024-06-25
Foxman Un HIGH 7.4
CVE-2024-28021

A vulnerability exists in the FOXMAN-UN/UNEM server that affects the message queueing mechanism’s certificate validation. If exploited an attacker c…

Mitigation only
Fix from $1,950 2024-06-11
Security Verify Access Docker HIGH 7.8
CVE-2024-35140

IBM Security Verify Access Docker 10.0.0 through 10.0.6 could allow a local user to escalate their privileges due to improper certificate validation.…

Fix: 10.0.7+
Fix from $1,950 2024-05-31
Pdf Editor HIGH 8.2
CVE-2024-29072

A privilege escalation vulnerability exists in the Foxit Reader 2024.2.0.25138. The vulnerability occurs due to improper certification validation of …

Fix: after 2024.2.1.25153
Fix from $1,950 2024-05-28
Youtrack HIGH 7.5
CVE-2024-35299

In JetBrains YouTrack before 2024.1.29548 the SMTPS protocol communication lacked proper certificate hostname validation

Fix: 2024.1.29548+
Fix from $1,950 2024-05-16
Windows 10 1507 HIGH 8.1
CVE-2024-30020

Windows Cryptographic Services Remote Code Execution Vulnerability

Fix: 10.0.10240.20651 / 10.0.14393.6981+
Fix from $1,950 2024-05-14
Unclassified HIGH 8.8
CVE-2022-32509

An issue was discovered on certain Nuki Home Solutions devices. Lack of certificate validation on HTTP communications allows attackers to intercept a…

Mitigation only
Fix from $1,950 2024-05-14
Big Ip Next Central Manager MEDIUM 6.8
CVE-2024-33612

An improper certificate validation vulnerability exists in BIG-IP Next Central Manager and may allow an attacker to impersonate an Instance Provider …

Fix: 20.2.0+
Fix from $1,600 2024-05-08
Android HIGH 7.8
CVE-2024-0042

In TBD of TBD, there is a possible confusion of OEM and DRM certificates due to improperly used crypto. This could lead to local bypass of DRM conten…

No fix yet
Fix from $1,950 2024-05-07
Rax50 Firmware HIGH 8.8
CVE-2023-35721

NETGEAR Multiple Routers curl_post Improper Certificate Validation Remote Code Execution Vulnerability. This vulnerability allows network-adjacent at…

Fix: 1.0.15.128+
Fix from $1,950 2024-05-03
Nginxwebui CRITICAL 9.8
CVE-2024-3738

A vulnerability classified as critical has been found in cym1102 nginxWebUI up to 3.9.9. This affects the function handlePath of the file /adminPage/…

Fix: 4.2.4+
Fix from $2,300 2024-04-13
Qradar Security Information And Event Manager HIGH 8.1
CVE-2023-50949

IBM QRadar SIEM 7.5 could allow an unauthorized user to perform unauthorized actions due to improper certificate validation. IBM X-Force ID: 275706.

Mitigation only
Fix from $1,950 2024-04-11
Security Verify Access HIGH 8.1
CVE-2024-31871

IBM Security Verify Access Appliance 10.0.0 through 10.0.7 could allow a malicious actor to conduct a man in the middle attack when deploying Python …

Fix: after 10.0.7
Fix from $1,950 2024-04-10
Security Verify Access HIGH 8.1
CVE-2024-31872

IBM Security Verify Access Appliance 10.0.0 through 10.0.7 could allow a malicious actor to conduct a man in the middle attack when deploying Open So…

Fix: after 10.0.7
Fix from $1,950 2024-04-10
Windows 10 1507 HIGH 7.8
CVE-2024-29050

Windows Cryptographic Services Remote Code Execution Vulnerability

Fix: 10.0.10240.20596 / 10.0.14393.6897+
Fix from $1,950 2024-04-09
Pdf Tools HIGH 7.5
CVE-2024-27323

PDF-XChange Editor Updater Improper Certificate Validation Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers …

Mitigation only
Fix from $1,950 2024-04-01
Serverpod HIGH 7.4
CVE-2024-29887

Serverpod is an app and web server, built for the Flutter and Dart ecosystem. This bug bypassed the validation of TSL certificates on all none web HT…

Fix: 1.2.6+
Fix from $1,950 2024-03-27
Curl MEDIUM 6.3
CVE-2024-2379

libcurl skips the certificate verification for a QUIC connection under certain conditions, when built to use wolfSSL. If told to use an unknown/bad c…

Fix: 12.7.6 / 13.6.8+
Fix from $1,600 2024-03-27
MongoDB CRITICAL 9.8
CVE-2024-1351

Under certain configurations of --tlsCAFile and tls.CAFile, MongoDB Server may skip peer certificate validation which may result in untrusted connect…

Fix: 4.4.29 / 5.0.25+
Fix from $2,300 2024-03-07
Delphix MEDIUM 5.3
CVE-2024-28161

In Jenkins Delphix Plugin 3.0.1, a global option for administrators to enable or disable SSL/TLS certificate validation for Data Control Tower (DCT) …

Mitigation only
Fix from $1,600 2024-03-06
Vault CRITICAL 9.8
CVE-2024-2048

Vault and Vault Enterprise (“Vault”) TLS certificate auth method did not correctly validate client certificates when configured with a non-CA certifi…

Fix: 1.14.10 / 1.15.5+
Fix from $2,300 2024-03-04
Cloud Pak For Security MEDIUM 5.9
CVE-2023-47742

IBM QRadar Suite Products 1.10.12.0 through 1.10.18.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 could disclose sensitive information …

Fix: after 1.10.18.0
Fix from $1,600 2024-03-03
Apache Airflow Providers Mongo CRITICAL 9.1
CVE-2024-25141

When ssl was enabled for Mongo Hook, default settings included "allow_insecure" which caused that certificates were not validated. This was unexpecte…

Fix: 4.0.0+
Fix from $2,300 2024-02-20
Dolphinscheduler HIGH 7.3
CVE-2023-49250

Because the HttpUtils class did not verify certificates, an attacker that could perform a Man-in-the-Middle (MITM) attack on outgoing https connectio…

Fix: 3.2.1+
Fix from $1,950 2024-02-20
Android HIGH 7.5
CVE-2023-40104

In ca-certificates, there is a possible way to read encrypted TLS data due to untrusted cryptographic certificates. This could lead to remote informa…

Patch available
Fix from $1,950 2024-02-15
Cloud Connector HIGH 7.4
CVE-2024-25642

Due to improper validation of certificate in SAP Cloud Connector - version 2.0, attacker can impersonate the genuine servers to interact with SCC bre…

Mitigation only
Fix from $1,950 2024-02-13
Security Verify Access HIGH 7.2
CVE-2023-43017

IBM Security Verify Access 10.0.0.0 through 10.0.6.1 could allow a privileged user to install a configuration file that could allow remote access. I…

Fix: after 10.0.6.1
Fix from $1,950 2024-02-07