Vulnerability index

Browse CVEs

1,354 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Certificate ValidationCWE-295 × clear
Zammad MEDIUM 5.9
CVE-2023-50454

An issue was discovered in Zammad before 6.2.0. In several subsystems, SSL/TLS was used to establish connections to external services without proper …

Mitigation only
Fix from $1,600 2023-12-10
Emui HIGH 7.5
CVE-2023-49247

Permission verification vulnerability in distributed scenarios. Successful exploitation of this vulnerability may affect service confidentiality.

No fix yet
Fix from $1,950 2023-12-06
Industrial Gateway Server HIGH 7.5
CVE-2023-5909

KEPServerEX does not properly validate certificates from clients which may allow unauthenticated users to connect.

Fix: after 7.614
Fix from $1,950 2023-11-30
Precision Bridge CRITICAL 9.1
CVE-2023-49312

Precision Bridge PrecisionBridge.exe (aka the thick client) before 7.3.21 allows an integrity violation in which the same license key is used on mult…

Fix: 7.3.21+
Fix from $2,300 2023-11-26
Unity Operating Environment MEDIUM 5.9
CVE-2023-43082

Dell Unity prior to 5.3 contains a 'man in the middle' vulnerability in the vmadapter component. If a customer has a certificate signed by a third-pa…

Fix: 5.3.0.0.5.120+
Fix from $1,600 2023-11-22
Httpie HIGH 7.4
CVE-2023-48052

Missing SSL certificate validation in HTTPie v3.2.2 allows attackers to eavesdrop on communications between the host and server via a man-in-the-midd…

Mitigation only
Fix from $1,950 2023-11-16
Localstack HIGH 7.4
CVE-2023-48054

Missing SSL certificate validation in localstack v2.3.2 allows attackers to eavesdrop on communications between the host and server via a man-in-the-…

Mitigation only
Fix from $1,950 2023-11-16
Android HIGH 7.5
CVE-2023-42532

Improper Certificate Validation in FotaAgent prior to SMR Nov-2023 Release1 allows remote attacker to intercept the network traffic including Firmwar…

Mitigation only
Fix from $1,950 2023-11-07
Squid HIGH 7.5
CVE-2023-46724

Squid is a caching proxy for the Web. Due to an Improper Validation of Specified Index bug, Squid versions 3.3.0.1 through 5.9 and 6.0 prior to 6.4 c…

Fix: 6.4+
Fix from $1,950 2023-11-01
Edge\+ Evc5fd Firmware CRITICAL 9.8
CVE-2023-42425

An issue in Turing Video Turing Edge+ EVC5FD v.1.38.6 allows remote attacker to execute arbitrary code and obtain sensitive information via the cloud…

Mitigation only
Fix from $2,300 2023-10-31
Android HIGH 7.8
CVE-2023-21358

In UWB Google, there is a possible way for a malicious app to masquerade as system app com.android.uwb.resources due to improperly used crypto. This …

Mitigation only
Fix from $1,950 2023-10-30
Elastic Beats HIGH 7.5
CVE-2023-31421

It was discovered that when acting as TLS clients, Beats, Elastic Agent, APM Server, and Fleet Server did not verify whether the server certificate i…

Fix: after 8.9.2
Fix from $1,950 2023-10-26
Light Oauth2 MEDIUM 5.9
CVE-2023-31580

light-oauth2 before version 2.1.27 obtains the public key without any verification. This could allow attackers to authenticate to the application wit…

Fix: 2.1.27+
Fix from $1,600 2023-10-25
Connect MEDIUM 5.9
CVE-2022-3761

OpenVPN Connect versions before 3.4.0.4506 (macOS) and OpenVPN Connect before 3.4.0.3100 (Windows) allows man-in-the-middle attackers to intercept co…

Fix: 3.4.0.3121 / 3.4.0.4506+
Fix from $1,600 2023-10-17
Security Verify Privilege On Premises MEDIUM 5.3
CVE-2022-43892

IBM Security Verify Privilege On-Premises 11.5 does not validate, or incorrectly validates, a certificate which could disclose sensitive information …

Fix: 11.5+
Fix from $1,600 2023-10-17
Otrs CRITICAL 9.1
CVE-2023-5422

The functions to fetch e-mail via POP3 or IMAP as well as sending e-mail via SMTP use OpenSSL for static SSL or TLS based communication. As the SSL_…

Fix: 7.0.47 / 8.0.37+
Fix from $2,300 2023-10-16
Thinupdate HIGH 7.5
CVE-2023-4499

A potential security vulnerability has been identified in the HP ThinUpdate utility (also known as HP Recovery Image and Software Download Tool) whic…

Fix: 2.7.15+
Fix from $1,950 2023-10-13
Line CRITICAL 9.8
CVE-2023-5554

Lack of TLS certificate verification in log transmission of a financial module within LINE client for iOS prior to 13.16.0.

Fix: 13.16.0+
Fix from $2,300 2023-10-12
Ktor CRITICAL 9.1
CVE-2023-45613

In JetBrains Ktor before 2.3.5 server certificates were not verified

Fix: 2.3.5+
Fix from $2,300 2023-10-09
Keycloak HIGH 7.1
CVE-2023-2422

A flaw was found in Keycloak. A Keycloak server configured to support mTLS authentication for OAuth/OpenID clients does not properly verify the clien…

Mitigation only
Fix from $1,950 2023-10-04
Data Grid HIGH 7.4
CVE-2023-4586

A vulnerability was found in the Hot Rod client. This security issue occurs as the Hot Rod client does not enable hostname validation when using TLS,…

Mitigation only
Fix from $1,950 2023-10-04
Ipados MEDIUM 5.5
CVE-2023-41991 KEV

A certificate validation issue was addressed. This issue is fixed in macOS Ventura 13.6, iOS 16.7 and iPadOS 16.7. A malicious app may be able to byp…

Fix: 13.6 / 16.7+
Fix from $1,600 2023-09-21
Movie Maker HIGH 8.1
CVE-2023-38355

MiniTool Movie Maker 7.0 contains an insecure installation process that allows attackers to achieve remote code execution through a man in the middle…

Mitigation only
Fix from $1,950 2023-09-19
Power Data Recovery HIGH 8.1
CVE-2023-38356

MiniTool Power Data Recovery 11.6 contains an insecure installation process that allows attackers to achieve remote code execution through a man in t…

Mitigation only
Fix from $1,950 2023-09-19
Partition Wizard HIGH 8.1
CVE-2023-38352

MiniTool Partition Wizard 12.8 contains an insecure update mechanism that allows attackers to achieve remote code execution through a man in the midd…

Mitigation only
Fix from $1,950 2023-09-19
Power Data Recovery MEDIUM 5.9
CVE-2023-38353

MiniTool Power Data Recovery version 11.6 and before contains an insecure in-app payment system that allows attackers to steal highly sensitive infor…

Fix: after 11.6
Fix from $1,600 2023-09-19
Shadowmaker HIGH 8.1
CVE-2023-38354

MiniTool Shadow Maker version 4.1 contains an insecure installation process that allows attackers to achieve remote code execution through a man in t…

Mitigation only
Fix from $1,950 2023-09-19
Partition Wizard HIGH 8.1
CVE-2023-38351

MiniTool Partition Wizard 12.8 contains an insecure installation mechanism that allows attackers to achieve remote code execution through a man in th…

Mitigation only
Fix from $1,950 2023-09-19
Insider Threat Management HIGH 7.5
CVE-2023-4801

An improper certification validation vulnerability in the Insider Threat Management (ITM) Agent for MacOS could be used by an anonymous actor on an a…

Fix: 7.14.3.69+
Fix from $1,950 2023-09-13
Email HIGH 7.5
CVE-2023-30729

Improper Certificate Validation in Samsung Email prior to version 6.1.82.0 allows remote attacker to intercept the network traffic including sensitiv…

Fix: 6.1.82.0+
Fix from $1,950 2023-09-06