Vulnerability index

Browse CVEs

1,354 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Certificate ValidationCWE-295 × clear
Curl MEDIUM 6.3
CVE-2024-2379

libcurl skips the certificate verification for a QUIC connection under certain conditions, when built to use wolfSSL. If told to use an unknown/bad c…

Fix: 12.7.6 / 13.6.8+
Fix from $1,600 2024-03-27
MongoDB CRITICAL 9.8
CVE-2024-1351

Under certain configurations of --tlsCAFile and tls.CAFile, MongoDB Server may skip peer certificate validation which may result in untrusted connect…

Fix: 4.4.29 / 5.0.25+
Fix from $2,300 2024-03-07
Delphix MEDIUM 5.3
CVE-2024-28161

In Jenkins Delphix Plugin 3.0.1, a global option for administrators to enable or disable SSL/TLS certificate validation for Data Control Tower (DCT) …

Mitigation only
Fix from $1,600 2024-03-06
Vault CRITICAL 9.8
CVE-2024-2048

Vault and Vault Enterprise (“Vault”) TLS certificate auth method did not correctly validate client certificates when configured with a non-CA certifi…

Fix: 1.14.10 / 1.15.5+
Fix from $2,300 2024-03-04
Cloud Pak For Security MEDIUM 5.9
CVE-2023-47742

IBM QRadar Suite Products 1.10.12.0 through 1.10.18.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 could disclose sensitive information …

Fix: after 1.10.18.0
Fix from $1,600 2024-03-03
Apache Airflow Providers Mongo CRITICAL 9.1
CVE-2024-25141

When ssl was enabled for Mongo Hook, default settings included "allow_insecure" which caused that certificates were not validated. This was unexpecte…

Fix: 4.0.0+
Fix from $2,300 2024-02-20
Dolphinscheduler HIGH 7.3
CVE-2023-49250

Because the HttpUtils class did not verify certificates, an attacker that could perform a Man-in-the-Middle (MITM) attack on outgoing https connectio…

Fix: 3.2.1+
Fix from $1,950 2024-02-20
Android HIGH 7.5
CVE-2023-40104

In ca-certificates, there is a possible way to read encrypted TLS data due to untrusted cryptographic certificates. This could lead to remote informa…

Patch available
Fix from $1,950 2024-02-15
Cloud Connector HIGH 7.4
CVE-2024-25642

Due to improper validation of certificate in SAP Cloud Connector - version 2.0, attacker can impersonate the genuine servers to interact with SCC bre…

Mitigation only
Fix from $1,950 2024-02-13
Security Verify Access HIGH 7.2
CVE-2023-43017

IBM Security Verify Access 10.0.0.0 through 10.0.6.1 could allow a privileged user to install a configuration file that could allow remote access. I…

Fix: after 10.0.6.1
Fix from $1,950 2024-02-07
Storage Virtualize HIGH 7.5
CVE-2023-47700

IBM SAN Volume Controller, IBM Storwize, IBM FlashSystem and IBM Storage Virtualize 8.6 products could allow a remote attacker to spoof a trusted sys…

Mitigation only
Fix from $1,950 2024-02-07
Security Verify Access CRITICAL 9.8
CVE-2023-32330

IBM Security Verify Access 10.0.0.0 through 10.0.6.1 uses insecure calls that could allow an attacker on the network to take control of the server. …

Fix: after 10.0.6.1
Fix from $2,300 2024-02-07
Rustdesk CRITICAL 9.8
CVE-2024-25140

A default installation of RustDesk 1.2.3 on Windows places a WDKTestCert certificate under Trusted Root Certification Authorities with Enhanced Key U…

No fix yet
Fix from $2,300 2024-02-06
Boundary HIGH 8.0
CVE-2024-1052

Boundary and Boundary Enterprise (“Boundary”) is vulnerable to session hijacking through TLS certificate tampering. An attacker with privileges to en…

Fix: 0.15.0+
Fix from $1,950 2024-02-05
Curl MEDIUM 5.3
CVE-2024-0853

curl inadvertently kept the SSL session ID for connections in its cache even when the verify status (*OCSP stapling*) test failed. A subsequent trans…

No fix yet
Fix from $1,600 2024-02-03
Bsafe Crypto C Micro Edition CRITICAL 9.8
CVE-2020-29504

Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.5.2, contain a Missing Required Crypt…

Fix: 4.1.5 / 4.5.2+
Fix from $2,300 2024-02-02
Secure Internet And Saas Access HIGH 7.5
CVE-2023-28807

In Zscaler Internet Access (ZIA) a mismatch between Connect Host and Client Hello's Server Name Indication (SNI) enables attackers to evade network s…

Fix: 6.2r.290+
Fix from $1,950 2024-01-31
Vision Server MEDIUM 6.5
CVE-2023-50356

SSL connections to some LDAP servers are vulnerable to a man-in-the-middle attack due to improper certificate validation in AREAL Topkapi Vision (Ser…

Fix: 6.2.4719+
Fix from $1,600 2024-01-31
Meshcentral CRITICAL 9.8
CVE-2023-51837

Ylianst MeshCentral 1.1.16 is vulnerable to Missing SSL Certificate Validation.

No fix yet
Fix from $2,300 2024-01-30
Ipcs MEDIUM 5.9
CVE-2023-33757

A lack of SSL certificate validation in Splicecom iPCS (iOS App) v1.3.4, iPCS2 (iOS App) v2.8 and before, and iPCS (Android App) v1.8.5 and before al…

Fix: after 2.8
Fix from $1,600 2024-01-25
Maximiser Soft Pbx MEDIUM 5.3
CVE-2023-33760

SpliceCom Maximiser Soft PBX v1.5 and before was discovered to utilize a default SSL certificate. This issue can allow attackers to eavesdrop on comm…

Fix: after 1.5
Fix from $1,600 2024-01-25
Vantage HIGH 7.8
CVE-2023-6043

A privilege escalation vulnerability was reported in Lenovo Vantage that could allow a local attacker to bypass integrity checks and execute arbitrar…

Fix: 4.0.49.0+
Fix from $1,950 2024-01-19
Cohesity Dataplatform MEDIUM 6.5
CVE-2023-33295

Cohesity DataProtect prior to 6.8.1_u5 or 7.1 was discovered to have a incorrect access control vulnerability due to a lack of TLS Certificate Valida…

Fix: after 7.0.1
Fix from $1,600 2024-01-19
Snowflake Connector HIGH 7.5
CVE-2023-51662

The Snowflake .NET driver provides an interface to the Microsoft .NET open source software framework for developing applications. Snowflake recently …

Fix: 2.1.5+
Fix from $1,950 2023-12-22
Endpoint Antivirus HIGH 8.6
CVE-2023-5594

Improper validation of the server’s certificate chain in secure traffic scanning feature considered intermediate certificate signed using the MD5 or …

Mitigation only
Fix from $1,950 2023-12-21
Rtu500 Scripting Interface HIGH 7.5
CVE-2023-1514

A vulnerability exists in the component RTU500 Scripting interface. When a client connects to a server using TLS, the server presents a certificate. …

Mitigation only
Fix from $1,950 2023-12-19
GitLab HIGH 8.1
CVE-2023-6680

An improper certificate validation issue in Smartcard authentication in GitLab EE affecting all versions from 11.6 prior to 16.4.4, 16.5 prior to 16.…

Fix: 16.4.4 / 16.5.4+
Fix from $1,950 2023-12-15
Jruby Openssl HIGH 7.5
CVE-2009-4123

The jruby-openssl gem before 0.6 for JRuby mishandles SSL certificate validation.

Fix: 0.6+
Fix from $1,950 2023-12-12
Privilege Management For Windows HIGH 7.8
CVE-2020-12614

An issue was discovered in BeyondTrust Privilege Management for Windows through 5.6. If the publisher criteria is selected, it defines the name of a …

Fix: after 5.6
Fix from $1,950 2023-12-12
Sinec Ins CRITICAL 9.8
CVE-2023-48427

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). Affected products do not properly validate the certificate of th…

Fix: 1.0+
Fix from $2,300 2023-12-12