Vulnerability index

Browse CVEs

1,354 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Certificate ValidationCWE-295 × clear
Nifi Minifi C\+\+ MEDIUM 5.9
CVE-2023-41180

Incorrect certificate validation in InvokeHTTP on Apache NiFi MiNiFi C++ versions 0.13 to 0.14 allows an intermediary to present a forged certificate…

Fix: after 0.14.0
Fix from $1,600 2023-09-03
Airflow MEDIUM 5.9
CVE-2023-39441

Apache Airflow SMTP Provider before 1.3.0, Apache Airflow IMAP Provider before 3.3.0, and Apache Airflow before 2.7.0 are affected by the Validation …

Fix: 1.3.0 / 2.7.0+
Fix from $1,600 2023-08-23
MongoDB HIGH 7.5
CVE-2023-1409

If the MongoDB Server running on Windows or macOS is configured to use TLS with a specific set of configuration options that are already known to wor…

Fix: 4.4.23 / 6.0.7+
Fix from $1,950 2023-08-23
Android HIGH 7.5
CVE-2023-21265

In multiple locations, there are root CA certificates which need to be disabled. This could lead to remote information disclosure with no additional …

Patch available
Fix from $1,950 2023-08-14
Netbackup Snapshot Manager CRITICAL 9.8
CVE-2023-40256

A vulnerability was discovered in Veritas NetBackup Snapshot Manager before 10.2.0.1 that allowed untrusted clients to interact with the RabbitMQ ser…

Fix: after 8.3.0.2
Fix from $2,300 2023-08-11
Sydent MEDIUM 5.3
CVE-2023-38686

Sydent is an identity server for the Matrix communications protocol. Prior to version 2.5.6, if configured to send emails using TLS, Sydent does not …

Fix: 2.5.6+
Fix from $1,600 2023-08-04
Device Manager HIGH 8.1
CVE-2023-34143

Improper Validation of Certificate with Host Mismatch vulnerability in Hitachi Device Manager on Windows, Linux (Device Manager Server, Device Manage…

Fix: 8.8.5-02+
Fix from $1,950 2023-07-18
Wolfssl HIGH 8.8
CVE-2023-3724

If a TLS 1.3 client gets neither a PSK (pre shared key) extension nor a KSE (key share extension) when connecting to a malicious server, a default pr…

Fix: 5.6.2+
Fix from $1,950 2023-07-17
Mattermost HIGH 8.1
CVE-2023-3615

Mattermost iOS app fails to properly validate the server certificate while initializing the TLS connection allowing a network attacker to intercept t…

Fix: 2.5.1+
Fix from $1,950 2023-07-17
Cryptography HIGH 7.5
CVE-2023-38325

The cryptography package before 41.0.2 for Python mishandles SSH certificates that have critical options.

Fix: 41.0.2+
Fix from $1,950 2023-07-14
Dronescout Ds230 Firmware HIGH 8.1
CVE-2023-31190

DroneScout ds230 Remote ID receiver from BlueMark Innovations is affected by an Improper Authentication vulnerability during the firmware update proc…

Fix: after 20230329-1042
Fix from $1,950 2023-07-11
Ur32l Firmware HIGH 8.1
CVE-2023-23546

A misconfiguration vulnerability exists in the urvpn_client functionality of Milesight UR32L v32.3.0.5. A specially-crafted man-in-the-middle attack …

No fix yet
Fix from $1,950 2023-07-06
Bc Java MEDIUM 5.3
CVE-2023-33201

Bouncy Castle For Java before 1.74 is affected by an LDAP injection vulnerability. The vulnerability only affects applications that use an LDAP CertS…

Fix: 1.74+
Fix from $1,600 2023-07-05
Server HIGH 7.5
CVE-2023-30222

An information disclosure vulnerability in 4D SAS 4D Server Application v17, v18, v19 R7 and earlier allows attackers to retrieve password hashes for…

No fix yet
Fix from $1,950 2023-06-16
Checkmarx HIGH 8.1
CVE-2023-35142

Jenkins Checkmarx Plugin 2022.4.3 and earlier disables SSL/TLS validation for connections to the Checkmarx server by default.

Fix: after 2023.4.3
Fix from $1,950 2023-06-14
Debian Linux MEDIUM 5.3
CVE-2023-34410

An issue was discovered in Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.2. Certificate validation for TLS does not always …

Fix: 5.15.15 / 6.2.9+
Fix from $1,600 2023-06-05
Thunderbird MEDIUM 6.5
CVE-2023-0430

Certificate OCSP revocation status was not checked when verifying S/Mime signatures. Mail signed with a revoked certificate would be displayed as hav…

Fix: 102.7.1+
Fix from $1,600 2023-06-02
Thunderbird MEDIUM 6.5
CVE-2023-0547

OCSP revocation status of recipient certificates was not checked when sending S/Mime encrypted email, and revoked certificates would be accepted. Thu…

Fix: 102.10+
Fix from $1,600 2023-06-02
Curl MEDIUM 5.9
CVE-2023-28321

An improper certificate validation vulnerability exists in curl <v8.1.0 in the way it supports matching of wildcard patterns when listed as "Subject …

Fix: 8.1.0+
Fix from $1,600 2023-05-26
Build Of Quarkus MEDIUM 6.5
CVE-2023-1664

A flaw was found in Keycloak. This flaw depends on a non-default configuration "Revalidate Client Certificate" to be enabled and the reverse proxy is…

Mitigation only
Fix from $1,600 2023-05-26
Capi Release HIGH 8.1
CVE-2023-20881

Cloud foundry instances having CAPI version between 1.140 and 1.152.0 along with loggregator-agent v7+ may override other users syslog drain credenti…

Fix: after 29.0.0
Fix from $1,950 2023-05-19
Agent HIGH 7.5
CVE-2022-45457

Sensitive information disclosure and manipulation due to improper certification validation. The following products are affected: Acronis Agent (Windo…

Fix: 15+
Fix from $1,950 2023-05-18
Agent HIGH 7.5
CVE-2022-45458

Sensitive information disclosure and manipulation due to improper certification validation. The following products are affected: Acronis Agent (Windo…

Fix: 15+
Fix from $1,950 2023-05-18
1080pstx CRITICAL 9.8
CVE-2023-27823EPSS 53%

An authentication bypass in Optoma 1080PSTX C02 allows an attacker to access the administration console without valid credentials.

Mitigation only
Fix from $2,300 2023-05-12
Skybridge Basic Mb A130 Firmware MEDIUM 6.5
CVE-2023-23901

Improper following of a certificate's chain of trust exists in SkyBridge MB-A200 firmware Ver. 01.00.05 and earlier, and SkyBridge BASIC MB-A130 firm…

Fix: after 1.4.1
Fix from $1,600 2023-05-10
Websphere Application Server MEDIUM 5.3
CVE-2022-39161

IBM WebSphere Application Server 7.0, 8.0, 8.5, 9.0, and IBM WebSphere Application Server Liberty, when configured to communicate with the Web Server…

Mitigation only
Fix from $1,600 2023-05-03
Big Ip Access Policy Manager MEDIUM 5.9
CVE-2023-24461

An improper certificate validation vulnerability exists in the BIG-IP Edge Client for Windows and macOS and may allow an attacker to impersonate a BI…

Fix: 7.2.4.1+
Fix from $1,600 2023-05-03
Bizmanager CRITICAL 9.8
CVE-2022-35898

OpenText BizManager before 16.6.0.1 does not perform proper validation during the change-password operation. This allows any authenticated user to ch…

Fix: 16.6.0.1+
Fix from $2,300 2023-05-01
Baiying MEDIUM 6.2
CVE-2022-48186

A certificate validation vulnerability exists in the Baiying Android application which could lead to information disclosure.

Fix: 1.1.4+
Fix from $1,600 2023-05-01
Perl HIGH 8.1
CVE-2023-31484

CPAN.pm before 2.35 does not verify TLS certificates when downloading distributions over HTTPS.

Fix: 2.35 / 5.38.0+
Fix from $1,950 2023-04-29