Vulnerability index

Browse CVEs

1,354 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Certificate ValidationCWE-295 × clear
Pulsar MEDIUM 5.9
CVE-2022-33683

Apache Pulsar Brokers and Proxies create an internal Pulsar Admin Client that does not verify peer TLS certificates, even when tlsAllowInsecureConnec…

Fix: 2.7.5 / 2.8.4+
Fix from $1,600 2022-09-23
View26 Test Reporting HIGH 8.1
CVE-2022-41244

Jenkins View26 Test-Reporting Plugin 1.0.7 and earlier does not perform hostname validation when connecting to the configured View26 server that coul…

Fix: after 1.0.7
Fix from $1,950 2022-09-21
Smalltest HIGH 8.1
CVE-2022-41243

Jenkins SmallTest Plugin 1.0.4 and earlier does not perform hostname validation when connecting to the configured View26 server that could be abused …

Fix: after 1.0.4
Fix from $1,950 2022-09-21
Fabasoft Cloud Enterprise Client HIGH 7.8
CVE-2022-29908

The folioupdate service in Fabasoft Cloud Enterprise Client 22.4.0043 allows Local Privilege Escalation.

No fix yet
Fix from $1,950 2022-09-19
Ejbca CRITICAL 9.8
CVE-2022-34831

An issue was discovered in Keyfactor PrimeKey EJBCA before 7.9.0, related to possible inconsistencies in DNS identifiers submitted in an ACME order a…

Fix: 7.9.0+
Fix from $2,300 2022-09-14
Freshservice Agent HIGH 8.1
CVE-2022-36173

FreshService macOS Agent < 4.4.0 and FreshServce Linux Agent < 3.4.0 are vulnerable to TLS Man-in-The-Middle via the FreshAgent client and scheduled …

Fix: 2.12.0 / 3.4.0+
Fix from $1,950 2022-09-12
Ansible Automation Platform MEDIUM 6.5
CVE-2022-1632

An Improper Certificate Validation attack was found in Openshift. A re-encrypt Route with destinationCACertificate explicitly set to the default serv…

Mitigation only
Fix from $1,600 2022-09-01
Python Scciclient HIGH 7.4
CVE-2022-2996

A flaw was found in the python-scciclient when making an HTTPS connection to a server where the server's certificate would not be verified. This issu…

Patch available
Fix from $1,950 2022-09-01
Odyssey HIGH 8.1
CVE-2021-43766

Odyssey passes to server unencrypted bytes from man-in-the-middle When Odyssey is configured to use certificate Common Name for client authentication…

Mitigation only
Fix from $1,950 2022-08-25
PostgreSQL MEDIUM 5.9
CVE-2021-43767

Odyssey passes to client unencrypted bytes from man-in-the-middle When Odyssey storage is configured to use the PostgreSQL server using 'trust' authe…

Fix: 9.6.24 / 10.19+
Fix from $1,600 2022-08-25
Keycloak MEDIUM 5.4
CVE-2020-35509

A flaw was found in keycloak affecting versions 11.0.3 and 12.0.0. An expired certificate would be accepted by the direct-grant authenticator because…

Mitigation only
Fix from $1,600 2022-08-23
Splunk CRITICAL 9.8
CVE-2022-37437

When using Ingest Actions to configure a destination that resides on Amazon Simple Storage Service (S3) in Splunk Web, TLS certificate validation is …

Mitigation only
Fix from $2,300 2022-08-16
Big Ip Access Policy Manager CRITICAL 9.1
CVE-2022-34865

In BIG-IP Versions 15.1.x before 15.1.6.1, 14.1.x before 14.1.5, and all versions of 13.1.x, Traffic Intelligence feeds, which use HTTPS, do not veri…

Fix: 14.1.5 / 15.1.6.1+
Fix from $2,300 2022-08-04
Fs2 CRITICAL 9.8
CVE-2022-31183

fs2 is a compositional, streaming I/O library for Scala. When establishing a server-mode `TLSSocket` using `fs2-io` on Node.js, the parameter `reques…

Fix: 3.2.11+
Fix from $2,300 2022-08-01
Tera2 Pcoip Zero Client Firmware HIGH 8.1
CVE-2022-1805

When connecting to Amazon Workspaces, the SHA256 presented by AWS connection provisioner is not fully verified by Zero Clients. The issue could be ex…

Fix: 22.01.5+
Fix from $1,950 2022-07-28
Git Client HIGH 8.1
CVE-2022-36881

Jenkins Git client Plugin 3.11.0 and earlier does not perform SSH host key verification when connecting to Git repositories via SSH, enabling man-in-…

Fix: after 3.11.0
Fix from $1,950 2022-07-27
Libreoffice HIGH 7.5
CVE-2022-26305

An Improper Certificate Validation vulnerability in LibreOffice existed where determining if a macro was signed by a trusted author was done by only …

Fix: 7.2.7 / 7.3.2+
Fix from $1,950 2022-07-25
Nexus Dashboard HIGH 7.4
CVE-2022-20860

A vulnerability in the SSL/TLS implementation of Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to alter communications with a…

Fix: 2.2+
Fix from $1,950 2022-07-21
Qradar Security Information And Event Manager HIGH 7.5
CVE-2021-29755

IBM QRadar SIEM 7.3, 7.4, and 7.5 does not preform proper certificate validation for some inter-host communications. IBM X-Force ID: 202015.

Fix: 7.3.3 / 7.4.3+
Fix from $1,950 2022-07-20
Fortitoken Mobile MEDIUM 5.4
CVE-2021-22131

A improper validation of certificate with host mismatch in Fortinet FortiTokenAndroid version 5.0.3 and below, Fortinet FortiTokeniOS version 5.2.0 a…

Patch available
Fix from $1,600 2022-07-18
Debian Linux HIGH 7.5
CVE-2020-16093

In LemonLDAP::NG (aka lemonldap-ng) through 2.0.8, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backend…

Fix: after 2.0.8
Fix from $1,950 2022-07-18
Undici MEDIUM 6.5
CVE-2022-32210

`Undici.ProxyAgent` never verifies the remote server's certificate, and always exposes all request & response data to the proxy. This unexpectedly me…

Fix: 5.5.1+
Fix from $1,600 2022-07-14
Argo Cd CRITICAL 9.6
CVE-2022-31105

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo CD starting with version 0.4.0 and prior to 2.2.11, 2.3.6, and 2.4.5 i…

Fix: 2.2.11 / 2.3.6+
Fix from $2,300 2022-07-12
Expressway MEDIUM 5.9
CVE-2022-20813

Multiple vulnerabilities in the API and in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication S…

Mitigation only
Fix from $1,600 2022-07-06
Cloudforms Management Engine CRITICAL 9.1
CVE-2014-8164

A insecure configuration for certificate verification (http.verify_mode = OpenSSL::SSL::VERIFY_NONE) may lead to verification bypass in Red Hat Cloud…

Mitigation only
Fix from $2,300 2022-07-06
Parse Server HIGH 7.5
CVE-2022-31083

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 4.10.11 and 5.2.2, the cert…

Fix: 4.10.11 / 5.2.2+
Fix from $1,950 2022-06-17
Splunk HIGH 8.1
CVE-2022-32156

In Splunk Enterprise and Universal Forwarder versions before 9.0, the Splunk command-line interface (CLI) did not validate TLS certificates while con…

Fix: 9.0+
Fix from $1,950 2022-06-15
Splunk CRITICAL 9.1
CVE-2022-32151

The httplib and urllib Python libraries that Splunk shipped with Splunk Enterprise did not validate certificates using the certificate authority (CA)…

Fix: 8.2.2203 / 9.0+
Fix from $2,300 2022-06-15
Splunk HIGH 7.2
CVE-2022-32152

Splunk Enterprise peers in Splunk Enterprise versions before 9.0 and Splunk Cloud Platform versions before 8.2.2203 did not validate the TLS certific…

Fix: 8.2.2203 / 9.0+
Fix from $1,950 2022-06-15
Splunk HIGH 8.1
CVE-2022-32153

Splunk Enterprise peers in Splunk Enterprise versions before 9.0 and Splunk Cloud Platform versions before 8.2.2203 did not validate the TLS certific…

Fix: 8.2.2203 / 9.0+
Fix from $1,950 2022-06-15