Vulnerability index

Browse CVEs

1,354 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Certificate ValidationCWE-295 × clear
\ MEDIUM 5.9
CVE-2023-31485

GitLab::API::v4 through 0.26 does not verify TLS certificates when connecting to a GitLab server, enabling machine-in-the-middle attacks.

Fix: after 0.26
Fix from $1,600 2023-04-29
Perl HIGH 8.1
CVE-2023-31486

HTTP::Tiny before 0.083, a Perl core module since 5.13.9 and available standalone on CPAN, has an insecure default TLS configuration where users must…

Fix: 0.083 / 5.38.0+
Fix from $1,950 2023-04-29
Nanoleaf Firmware CRITICAL 9.8
CVE-2022-47758

Nanoleaf firmware v7.1.1 and below is missing TLS verification, allowing attackers to execute arbitrary code via a DNS hijacking attack.

Mitigation only
Fix from $2,300 2023-04-27
Libressl CRITICAL 9.8
CVE-2021-46880

x509/x509_verify.c in LibreSSL before 3.4.2, and OpenBSD before 7.0 errata 006, allows authentication bypass because an error for an unverified certi…

Fix: 3.4.2 / 7.0+
Fix from $2,300 2023-04-15
Strongswan CRITICAL 9.8
CVE-2023-26463

strongSwan 5.9.8 and 5.9.9 potentially allows remote code execution because it uses a variable named "public" for two different purposes within the s…

Mitigation only
Fix from $2,300 2023-04-15
Image Tag Parameter MEDIUM 6.5
CVE-2023-30516

Jenkins Image Tag Parameter Plugin 2.0 improperly introduces an option to opt out of SSL/TLS certificate validation when connecting to Docker registr…

Fix: 2.0+
Fix from $1,600 2023-04-12
Neuvector Vulnerability Scanner MEDIUM 5.3
CVE-2023-30517

Jenkins NeuVector Vulnerability Scanner Plugin 1.22 and earlier unconditionally disables SSL/TLS certificate and hostname validation when connecting …

Fix: after 1.22
Fix from $1,600 2023-04-12
Libressl MEDIUM 5.3
CVE-2022-48437

An issue was discovered in x509/x509_verify.c in LibreSSL before 3.6.1, and in OpenBSD before 7.2 errata 001. x509_verify_ctx_add_chain does not stor…

Fix: 3.6.1 / 7.2+
Fix from $1,600 2023-04-12
Fortianalyzer HIGH 8.1
CVE-2023-22642

An improper certificate validation vulnerability [CWE-295] in FortiAnalyzer and FortiManager 7.2.0 through 7.2.1, 7.0.0 through 7.0.5, 6.4.8 through …

Fix: 6.4.11 / 7.0.6+
Fix from $1,950 2023-04-11
Simatic Ipc647d Firmware MEDIUM 6.3
CVE-2023-23588

A vulnerability has been identified in SIMATIC IPC1047 (All versions), SIMATIC IPC1047E (All versions with maxView Storage Manager < 4.09.00.25611 on…

Fix: 4.09.00.25611+
Fix from $1,600 2023-04-11
Synchronization Engine MEDIUM 6.5
CVE-2023-28093

A user with a compromised configuration can start an unsigned binary as a service.

Fix: 3.1.30+
Fix from $1,600 2023-04-10
Bigflow MEDIUM 5.9
CVE-2023-25392

Allegro Tech BigFlow <1.6 is vulnerable to Missing SSL Certificate Validation.

Fix: 1.6+
Fix from $1,600 2023-04-10
Desktop MEDIUM 6.5
CVE-2023-29000

The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server. Starting with version 3.0.0 and prior to version 3.7.0, by trustin…

Fix: 3.7.0+
Fix from $1,600 2023-04-04
R6400 Firmware HIGH 8.8
CVE-2022-27644

This vulnerability allows network-adjacent attackers to compromise the integrity of downloaded information on affected installations of NETGEAR R6700…

Fix: 1.0.4.84 / 1.0.4.126+
Fix from $1,950 2023-03-29
OpenSSL MEDIUM 5.3
CVE-2023-0465

Applications that use a non-default option when verifying certificates may be vulnerable to an attack from a malicious CA to circumvent certain check…

Fix: 1.0.2zh / 1.1.1u+
Fix from $1,600 2023-03-28
OpenSSL MEDIUM 5.3
CVE-2023-0466

The function X509_VERIFY_PARAM_add0_policy() is documented to implicitly enable the certificate policy check when doing certificate verification. How…

Fix: 1.0.2zh / 1.1.1u+
Fix from $1,600 2023-03-28
Saml CRITICAL 9.8
CVE-2022-45597

ComponentSpace.Saml2 4.4.0 Missing SSL Certificate Validation. NOTE: the vendor does not consider this a vulnerability because the report is only abo…

Mitigation only
Fix from $2,300 2023-03-24
Android HIGH 7.8
CVE-2023-20963 KEV

In WorkSource, there is a possible parcel mismatch. This could lead to local escalation of privilege with no additional execution privileges needed. …

Patch available
Fix from $1,950 2023-03-24
OpenSSL HIGH 7.5
CVE-2023-0464

A security vulnerability has been identified in all supported versions of OpenSSL related to the verification of X.509 certificate chains that inclu…

Fix: 1.0.2zh / 1.1.1u+
Fix from $1,950 2023-03-22
Emc Unisphere For Powermax HIGH 7.4
CVE-2021-21548

Dell EMC Unisphere for PowerMax versions before 9.1.0.27, Dell EMC Unisphere for PowerMax Virtual Appliance versions before 9.1.0.27, and PowerMax OS…

Fix: 9.1.0.27+
Fix from $1,950 2023-03-17
Infrastructure Analytics Advisor HIGH 8.1
CVE-2022-4895

Improper Certificate Validation vulnerability in Hitachi Infrastructure Analytics Advisor on Linux (Analytics probe component), Hitachi Ops Center An…

Fix: 10.9.1-00+
Fix from $1,950 2023-02-28
Directory Server MEDIUM 5.5
CVE-2023-1055

A flaw was found in RHDS 11 and RHDS 12. While browsing entries LDAP tries to decode the userPassword attribute instead of the userCertificate attrib…

Mitigation only
Fix from $1,600 2023-02-27
Fortiproxy HIGH 7.4
CVE-2022-39948

An improper certificate validation vulnerability [CWE-295] in FortiOS 7.2.0 through 7.2.3, 7.0.0 through 7.0.7, 6.4 all versions, 6.2 all versions, 6…

Fix: 7.0.7 / 7.0.8+
Fix from $1,950 2023-02-16
Gotham Chat Irc MEDIUM 6.8
CVE-2022-48306

Improper Validation of Certificate with Host Mismatch vulnerability in Gotham Chat IRC helper of Palantir Gotham allows A malicious attacker in a pri…

Fix: 30221005.210011.9242+
Fix from $1,600 2023-02-16
Atlasdb HIGH 7.4
CVE-2022-27890

It was discovered that the sls-logging was not verifying hostnames in TLS certificates due to a misuse of the javax.net.ssl.SSLSocketFactory API. A m…

Fix: 0.730.0+
Fix from $1,950 2023-02-16
Add On Builder MEDIUM 5.3
CVE-2023-22943

In Splunk Add-on Builder (AoB) versions below 4.1.2 and the Splunk CloudConnect SDK versions below 3.1.3, requests to third-party APIs through the RE…

Fix: 3.1.3 / 4.1.2+
Fix from $1,600 2023-02-14
Ichiran MEDIUM 5.9
CVE-2023-22367

Ichiran App for iOS versions prior to 3.1.0 and Ichiran App for Android versions prior to 3.1.0 improperly verify server certificates, which may allo…

Fix: 3.1.0+
Fix from $1,600 2023-02-13
System Update MEDIUM 6.0
CVE-2022-34404

Dell System Update, version 2.0.0 and earlier, contains an Improper Certificate Validation in data parser module. A local attacker with high privileg…

Fix: 2.0.1.0+
Fix from $1,600 2023-02-11
Door Entry For Hometouch MEDIUM 5.9
CVE-2022-46496

BTicino Door Entry HOMETOUCH for iOS 1.4.2 was discovered to be missing an SSL certificate.

Fix: 1.5.1+
Fix from $1,600 2023-02-06
Cf Deployment CRITICAL 9.1
CVE-2022-31733

Starting with diego-release 2.55.0 and up to 2.69.0, and starting with CF Deployment 17.1 and up to 23.2.0, apps are accessible via another port on d…

Fix: after 23.2.0
Fix from $2,300 2023-02-03