Vulnerability index

Browse CVEs

1,354 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Certificate ValidationCWE-295 × clear
Nexpose MEDIUM 5.3
CVE-2022-3913

Rapid7 Nexpose and InsightVM versions 6.6.82 through 6.6.177 fail to validate the certificate of the update server when downloading updates. This fai…

Fix: 6.6.178+
Fix from $1,600 2023-02-01
Selfwealth HIGH 7.5
CVE-2023-23131

Selfwealth iOS mobile App 3.3.1 is vulnerable to Insecure App Transport Security (ATS) Settings.

Mitigation only
Fix from $1,950 2023-02-01
Emc Powerscale Onefs CRITICAL 9.8
CVE-2022-45100

Dell PowerScale OneFS, versions 8.2.x-9.3.x, contains an Improper Certificate Validation vulnerability. An remote unauthenticated attacker could pote…

Fix: 9.1.0.25 / 9.2.1.18+
Fix from $2,300 2023-02-01
Ecostruxure Cybersecurity Admin Expert HIGH 8.3
CVE-2022-32748

A CWE-295: Improper Certificate Validation vulnerability exists that could cause the CAE software to give wrong data to end users when using CAE to c…

Fix: 2.4+
Fix from $1,950 2023-01-30
Apache\ HIGH 8.1
CVE-2020-36659

In Apache::Session::Browseable before 1.3.6, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backends, bec…

Fix: 1.3.6+
Fix from $1,950 2023-01-27
Apache\ HIGH 8.1
CVE-2020-36658

In Apache::Session::LDAP before 0.5, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backends, because the…

Fix: 0.5+
Fix from $1,950 2023-01-27
Pyload Ng HIGH 7.4
CVE-2023-0509

Improper Certificate Validation in GitHub repository pyload/pyload prior to 0.5.0b3.dev44.

Fix: 0.5.0b3.dev44 / 2023-01-25+
Fix from $1,950 2023-01-26
Cloud Mobility For Dell Emc Storage HIGH 7.0
CVE-2023-23690

Cloud Mobility for Dell EMC Storage, versions 1.3.0.X and below contains an Improper Check for Certificate Revocation vulnerability. A threat actor d…

Fix: 1.3.4.0+
Fix from $1,950 2023-01-19
Ryde HIGH 8.8
CVE-2022-42979EPSS 24%

Information disclosure due to an insecure hostname validation in the RYDE application 5.8.43 for Android and iOS allows attackers to take over an acc…

Mitigation only
Fix from $1,950 2023-01-06
Slixmpp HIGH 7.5
CVE-2022-45197

Slixmpp before 1.8.3 lacks SSL Certificate hostname validation in XMLStream, allowing an attacker to pose as any server in the eyes of Slixmpp.

Fix: 1.8.3+
Fix from $1,950 2022-12-25
Firefox MEDIUM 6.5
CVE-2022-45419

If the user added a security exception for an invalid TLS certificate, opened an ongoing TLS connection with a server that used that certificate, and…

Fix: 107.0+
Fix from $1,600 2022-12-22
Firefox HIGH 8.1
CVE-2022-34469

When a TLS Certificate error occurs on a domain protected by the HSTS header, the browser should not allow the user to bypass the certificate error. …

Fix: 102.0+
Fix from $1,950 2022-12-22
Firefox MEDIUM 6.5
CVE-2022-22747

After accepting an untrusted certificate, handling an empty pkcs7 sequence as part of the certificate data could have lead to a crash. This crash is …

Fix: 91.5 / 96.0+
Fix from $1,600 2022-12-22
Thunderbird MEDIUM 5.4
CVE-2022-1197

When importing a revoked key that specified key compromise as the revocation reason, Thunderbird did not update the existing copy of the key that was…

Fix: 91.8+
Fix from $1,600 2022-12-22
Thunderbird MEDIUM 6.5
CVE-2022-1834

When displaying the sender of an email, and the sender name contained the Braille Pattern Blank space character multiple times, Thunderbird would hav…

Fix: 91.10+
Fix from $1,600 2022-12-22
Bookkeeper MEDIUM 5.9
CVE-2022-32531

The Apache Bookkeeper Java Client (before 4.14.6 and also 4.15.0) does not close the connection to the bookkeeper server when TLS hostname verificati…

Fix: 4.14.6+
Fix from $1,600 2022-12-15
Traefik MEDIUM 6.5
CVE-2022-46153

Traefik is an open source HTTP reverse proxy and load balancer. In affected versions there is a potential vulnerability in Traefik managing TLS conne…

Fix: 2.9.6+
Fix from $1,600 2022-12-08
Botan CRITICAL 9.1
CVE-2022-43705

In Botan before 2.19.3, it is possible to forge OCSP responses due to a certificate verification error. This issue was introduced in Botan 1.11.34 (N…

Fix: 2.19.3+
Fix from $2,300 2022-11-27
Ns Nd Integration Performance Publisher HIGH 7.5
CVE-2022-45391

Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.143 and earlier globally and unconditionally disables SSL/TLS certificate and hostname v…

Fix: 4.8.0.146+
Fix from $1,950 2022-11-15
Ns Nd Integration Performance Publisher HIGH 7.5
CVE-2022-38666

Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.146 and earlier unconditionally disables SSL/TLS certificate and hostname validation for…

Fix: after 4.8.0.146
Fix from $1,950 2022-11-15
Email Security Appliance HIGH 7.5
CVE-2022-20960

A vulnerability in Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated remote attacker to cause a denial o…

Fix: 14.2.1-015 / 14.3.0-020+
Fix from $1,950 2022-11-04
Pulsar HIGH 8.1
CVE-2022-33684

The Apache Pulsar C++ Client does not verify peer TLS certificates when making HTTPS calls for the OAuth2.0 Client Credential Flow, even when tlsAllo…

Fix: 2.7.5 / 2.8.4+
Fix from $1,950 2022-11-04
Ipados CRITICAL 9.8
CVE-2022-42813

A certificate validation issue existed in the handling of WKWebView. This issue was addressed with improved validation. This issue is fixed in tvOS 1…

Fix: 9.1 / 13.0+
Fix from $2,300 2022-11-01
Vault MEDIUM 5.3
CVE-2022-41316

HashiCorp Vault and Vault Enterprise’s TLS certificate auth method did not initially load the optionally configured CRL issued by the role's CA into …

Fix: 1.9.10 / 1.10.7+
Fix from $1,600 2022-10-12
Industrial Edge Management HIGH 7.4
CVE-2022-40147

A vulnerability has been identified in Industrial Edge Management (All versions < V1.5.1). The affected software does not properly validate the serve…

Fix: 1.5.1+
Fix from $1,950 2022-10-11
Apex One HIGH 7.8
CVE-2022-41747

An improper certification validation vulnerability in Trend Micro Apex One agents could allow a local attacker to load a DLL file with system service…

Patch available
Fix from $1,950 2022-10-10
Fedora MEDIUM 5.9
CVE-2022-39264

nheko is a desktop client for the Matrix communication application. All versions below 0.10.2 are vulnerable homeservers inserting malicious secrets,…

Fix: 0.10.2+
Fix from $1,600 2022-09-28
Vclient MEDIUM 5.9
CVE-2021-45035

Velneo vClient on its 28.1.3 version, does not correctly check the certificate of authenticity by default. This could allow an attacker that has acce…

Mitigation only
Fix from $1,600 2022-09-23
Pulsar MEDIUM 5.9
CVE-2022-33681

Delayed TLS hostname verification in the Pulsar Java Client and the Pulsar Proxy make each client vulnerable to a man in the middle attack. Connectio…

Fix: 2.7.5 / 2.8.4+
Fix from $1,600 2022-09-23
Pulsar MEDIUM 5.9
CVE-2022-33682

TLS hostname verification cannot be enabled in the Pulsar Broker's Java Client, the Pulsar Broker's Java Admin Client, the Pulsar WebSocket Proxy's J…

Fix: 2.7.5 / 2.8.4+
Fix from $1,600 2022-09-23