Vulnerability index

Browse CVEs

1,344 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Certificate ValidationCWE-295 × clear
Unclassified MEDIUM 5.6
CVE-2026-18257

Improper validity period check for root issuer certificate in CycloneCrypto cryptographic wrapper of S2OPC allows a certificate issued by this root i…

No fix yet
Fix from $1,600 2026-07-29
Traffic Server CRITICAL 10.0
CVE-2026-58162

The Apache Traffic Server certifier plugin generates certificates based on attacker-controlled client SNI. This issue affects Apache Traffic Server:…

Fix: 9.2.15 / 10.1.4+
Fix from $2,300 2026-07-29
Unclassified MEDIUM 5.9
CVE-2026-16107

IBM TS4500 CLI tool Versions:  0.1.31 through 1.12.0.0 does not validate or improperly validates TLS certificate validation, which could allow an att…

No fix yet
Fix from $1,600 2026-07-28
Unclassified HIGH 8.1
CVE-2026-54342

In epa4all, prior to version 2026-05-20, an attacker on the network path between epa4all and any backend (ePA Aktensystem, Konnektor, IDP, TSS) can p…

No fix yet
Fix from $1,950 2026-07-24
Unclassified CRITICAL 9.1
CVE-2026-48021

In epa4all, prior to version 2026-05-20, an attacker who can intercept the TLS connection between epa4all and the ePA backend can complete the VAU ha…

No fix yet
Fix from $2,300 2026-07-24
Unclassified HIGH 7.5
CVE-2026-52688

RRSIGs with too few labels can lead to bypass of DNSSEC wildcard validation

No fix yet
Fix from $1,950 2026-07-23
Netty CRITICAL 9.1
CVE-2026-56820

Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and prior to 4…

Fix: 4.1.136 / 4.2.16+
Fix from $2,300 2026-07-21
Webcenter Content HIGH 8.0
CVE-2026-60648

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are a…

No fix yet
Fix from $1,950 2026-07-21
Mina Sshd HIGH 7.3
CVE-2026-56624

Improper certificate validation in Apache MINA SSHD (server-side). Apache MINA SSHD is a Java library for client-side and server-side SSH. Server…

Fix: 2.19.0+
Fix from $1,950 2026-07-20
Unclassified CRITICAL 9.1
CVE-2026-46428

lettre is a a mailer library for Rust. Starting in version 0.10.1 and prior to version 0.11.22, an inverted-boolean bug in lettre's `boring-tls` inte…

No fix yet
Fix from $2,300 2026-07-20
Unclassified HIGH 8.2
CVE-2026-13410

Dancer::Plugin::Auth::Google versions before 0.08 for Perl have TLS verification disabled. The default user agent is initialised with SSL_verify_mod…

No fix yet
Fix from $1,950 2026-07-17
Unclassified MEDIUM 5.3
CVE-2026-38974

Dulwich through 1.1.0 was found to be missing SSH host key verification in contrib/paramiko_vendor.py.

Mitigation only
Fix from $1,600 2026-07-15
Unclassified CRITICAL 9.5
CVE-2026-13385

An Improper Validation of Integrity Check Value and Improper Certificate Validation in certain ASUS router models allows a remote man-in-the-middle(M…

Mitigation only
Fix from $2,300 2026-07-15
Windows 10 21h2 MEDIUM 6.5
CVE-2026-50302

Improper certificate validation in Windows Cryptographic Services allows an unauthorized attacker to bypass a security feature over a network.

Fix: 10.0.19044.7548 / 10.0.19045.7548+
Fix from $1,600 2026-07-14
Windows 10 1607 HIGH 7.8
CVE-2026-55001

Improper certificate validation in Windows Active Directory allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,950 2026-07-14
Azure Connected Machine Agent HIGH 8.8
CVE-2026-47632

Improper certificate validation in Azure Connected Machine Agent allows an unauthorized attacker to elevate privileges over an adjacent network.

Mitigation only
Fix from $1,950 2026-07-14
Forticlientems CRITICAL 9.8
CVE-2026-59836

A improper certificate validation vulnerability in Fortinet FortiClientEMS 7.4.3 through 7.4.5, FortiClientEMS 7.4.0 through 7.4.1, FortiClientEMS 7.…

Fix: 7.4.6+
Fix from $2,300 2026-07-14
Unclassified HIGH 7.5
CVE-2026-15683

Lorex 2K Indoor Wi-Fi Security Camera Device Management Server Improper Certificate Validation Vulnerability. This vulnerability allows network-adjac…

Mitigation only
Fix from $1,950 2026-07-13
Unclassified CRITICAL 9.5
CVE-2026-22093

The EVbee Service Android app uses TLS encrypted communication (HTTPS), but does not validate the certificate provided by the server. This allows an …

Mitigation only
Fix from $2,300 2026-07-13
Cpp Httplib HIGH 7.4
CVE-2026-54919

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. In affected Mbed TLS backend versions from 0.31.0 through 0.46.1 an…

Fix: 0.47.0+
Fix from $1,950 2026-07-10
Prisma Access Agent MEDIUM 5.9
CVE-2026-0277

An improper certificate validation vulnerability in the Prisma® Access Agent for iOS enables an attacker to perform a man-in-the-middle (MitM) attack…

Fix: 26.2.1+
Fix from $1,600 2026-07-09
Etcd HIGH 8.1
CVE-2026-59818

etcd is a distributed key-value store for the data of a distributed system. Prior to 3.5.32 and 3.6.13, when etcd is configured with --listen-client-…

Fix: 3.5.32 / 3.6.13+
Fix from $1,950 2026-07-08
Coder HIGH 7.4
CVE-2026-55436

Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.30.0 and prior to versions 2.32.7, 2.33.…

Fix: 2.32.7 / 2.33.8+
Fix from $1,950 2026-07-08
Unclassified HIGH 7.4
CVE-2026-6900

Improper certificate validation vulnerability in B&R Industrial Automation GmbH APROL. This issue affects APROL: before R 4.4-01P5.

Mitigation only
Fix from $1,950 2026-07-06
Curl HIGH 7.5
CVE-2026-12064

When a user invokes curl using a schemeless URL combined with `--proto-default` sftp (or scp), a disconnect occurs between the tool layer and libcurl…

Fix: 8.21.0+
Fix from $1,950 2026-07-03
Curl HIGH 8.1
CVE-2026-8286

A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS …

Fix: 8.21.0+
Fix from $1,950 2026-07-03
Curl CRITICAL 9.1
CVE-2026-11564

libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. An easy handle th…

Fix: 8.21.0+
Fix from $2,300 2026-07-03
Unclassified MEDIUM 6.4
CVE-2026-12374

Improper certificate validation and a time-of-check time-of-use (TOCTOU) race condition in the PrivilegedHelperTool XPC service in Cato Client before…

Mitigation only
Fix from $1,600 2026-07-01
Wolfssl HIGH 7.5
CVE-2026-7532

iPAddress name constraints bypass when WOLFSSL_IP_ALT_NAME is not defined. IP address name constraints are not enforced in that configuration, allowi…

Fix: 5.9.2+
Fix from $1,950 2026-06-25
Wolfssl MEDIUM 5.3
CVE-2026-10098

OCSP CertID serial-number length-confusion in wolfSSL_OCSP_resp_find_status allows a same-issuer SingleResponse whose serial is a prefix of the targe…

Fix: 5.9.2+
Fix from $1,600 2026-06-25