Vulnerability index

Browse CVEs

1,354 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Certificate ValidationCWE-295 × clear
Sync Gateway CRITICAL 9.8
CVE-2022-32563

An issue was discovered in Couchbase Sync Gateway 3.x before 3.0.2. Admin credentials are not verified when using X.509 client-certificate authentica…

Fix: 3.0.2+
Fix from $2,300 2022-06-10
Saml Sp 2.0 Single Sign On HIGH 8.8
CVE-2022-26493

Xecurify's miniOrange Premium, Standard, and Enterprise Drupal SAML SP modules possess an authentication and authorization bypass vulnerability. An a…

Fix: after 8.x-2.24
Fix from $1,950 2022-06-03
Curl HIGH 7.5
CVE-2022-27782

libcurl would reuse a previously created connection even when a TLS or SSHrelated option had been changed that should have prohibited reuse.libcurl k…

Fix: 7.83.1 / 8.2.12+
Fix from $1,950 2022-06-02
Debian Linux MEDIUM 5.9
CVE-2022-26491

An issue was discovered in Pidgin before 2.14.9. A remote attacker who can spoof DNS responses can redirect a client connection to a malicious server…

Fix: 2.14.9+
Fix from $1,600 2022-06-02
HTTP Server HIGH 7.5
CVE-2020-26184

Dell BSAFE Micro Edition Suite, versions prior to 4.5.1, contain an Improper Certificate Validation vulnerability.

Fix: 4.5.1+
Fix from $1,950 2022-06-01
Ipados MEDIUM 5.5
CVE-2022-26766

A certificate parsing issue was addressed with improved checks. This issue is fixed in tvOS 15.5, iOS 15.5 and iPadOS 15.5, Security Update 2022-004 …

Fix: 8.6 / 10.15.7+
Fix from $1,600 2022-05-26
Fortios MEDIUM 5.3
CVE-2022-22306

An improper certificate validation vulnerability [CWE-295] in FortiOS 6.0.0 through 6.0.14, 6.2.0 through 6.2.10, 6.4.0 through 6.4.8, 7.0.0 may allo…

Fix: 6.4.9+
Fix from $1,600 2022-05-24
Dtls HIGH 7.5
CVE-2022-29222

Pion DTLS is a Go implementation of Datagram Transport Layer Security. Prior to version 2.1.5, a DTLS Client could provide a Certificate that it does…

Fix: 2.1.5+
Fix from $1,950 2022-05-21
Meetings HIGH 7.5
CVE-2022-22787

The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.10.0 fails to properly validate the hostname during a ser…

Fix: 5.10.0+
Fix from $1,950 2022-05-18
Secure External Authentication Server MEDIUM 5.3
CVE-2021-29726

IBM Sterling Secure Proxy 6.0.3 and IBM Secure External Authentication Server 6.0.3 does not properly ensure that a certificate is actually associate…

Patch available
Fix from $1,600 2022-05-17
Mail MEDIUM 5.9
CVE-2013-10001

A vulnerability was found in HTC One/Sense 4.x. It has been rated as problematic. Affected by this issue is the certification validation of the mail …

Mitigation only
Fix from $1,600 2022-05-17
Verse MEDIUM 5.9
CVE-2021-27768

Using the ability to perform a Man-in-the-Middle (MITM) attack, which indicates a lack of hostname verification, sensitive account information was ab…

Fix: 12.0.9+
Fix from $1,600 2022-05-12
Windows 10 1507 HIGH 8.8
CVE-2022-26923 KEVEPSS 83%

Active Directory Domain Services Elevation of Privilege Vulnerability

Fix: 10.0.10240.19297 / 10.0.14393.5850+
Fix from $1,950 2022-05-10
Parse Server HIGH 7.5
CVE-2022-24901

Improper validation of the Apple certificate URL in the Apple Game Center authentication adapter allows attackers to bypass authentication, making th…

Fix: 4.10.10 / 5.2.1+
Fix from $1,950 2022-05-04
OpenSSL MEDIUM 5.3
CVE-2022-1343

The function `OCSP_basic_verify` verifies the signer certificate on an OCSP response. In the case where the (non-default) flag OCSP_NOCHECKS is used …

Fix: 3.0.3+
Fix from $1,600 2022-05-03
Device Help MEDIUM 6.5
CVE-2021-3898

Versions of Motorola Ready For and Motorola Device Help Android applications prior to 2021-04-08 do not properly verify the server certificate which …

Fix: 2021-04-08+
Fix from $1,600 2022-04-22
Go HIGH 7.5
CVE-2022-27536

Certificate.Verify in crypto/x509 in Go 1.18.x before 1.18.1 can be caused to panic on macOS when presented with certain malformed certificates. This…

Fix: 1.18.1+
Fix from $1,950 2022-04-20
Emc Powerscale Onefs HIGH 8.1
CVE-2022-22549

Dell PowerScale OneFS, 8.2.x-9.3.x, contains a Improper Certificate Validation. A unauthenticated remote attacker could potentially exploit this vuln…

Fix: after 9.3.0
Fix from $1,950 2022-04-12
Android MEDIUM 6.7
CVE-2022-20071

In ccu, there is a possible escalation of privilege due to a missing certificate validation. This could lead to local escalation of privilege with Sy…

Mitigation only
Fix from $1,600 2022-04-11
Android MEDIUM 5.9
CVE-2022-20081

In A-GPS, there is a possible man in the middle attack due to improper certificate validation. This could lead to remote information disclosure with …

Mitigation only
Fix from $1,600 2022-04-11
Proxmox HIGH 7.5
CVE-2022-28142

Jenkins Proxmox Plugin 0.6.0 and earlier disables SSL/TLS certificate validation globally for the Jenkins controller JVM when configured to ignore SS…

Fix: after 0.6.0
Fix from $1,950 2022-03-29
GitLab MEDIUM 6.8
CVE-2022-0123

An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. GitLab does not val…

Fix: 14.4.5 / 14.5.3+
Fix from $1,600 2022-03-28
3cx CRITICAL 9.1
CVE-2021-45490

The client applications in 3CX on Windows, the 3CX app for iOS, and the 3CX application for Android through 2022-03-17 lack SSL certificate validatio…

Fix: after 2022-03-17
Fix from $2,300 2022-03-28
Kubeclient HIGH 8.1
CVE-2022-0759

A flaw was found in all versions of kubeclient up to (but not including) v4.9.3, the Ruby client for Kubernetes REST API, in the way it parsed kubeco…

Fix: 4.9.3+
Fix from $1,950 2022-03-25
Nginx HIGH 7.4
CVE-2021-3618

ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocols but using compatible certif…

Fix: 1.21.0 / 3.0.4+
Fix from $1,950 2022-03-23
Vault MEDIUM 6.5
CVE-2022-25243

"Vault and Vault Enterprise 1.8.0 through 1.8.8, and 1.9.3 allowed the PKI secrets engine under certain configurations to issue wildcard certificates…

Fix: 1.8.9 / 1.9.4+
Fix from $1,600 2022-03-10
Enterprise Linux HIGH 7.5
CVE-2021-3698

A flaw was found in Cockpit in versions prior to 260 in the way it handles the certificate verification performed by the System Security Services Dae…

Fix: 260+
Fix from $1,950 2022-03-10
Ruggedcom Ros MEDIUM 5.9
CVE-2021-42017

A vulnerability has been identified in RUGGEDCOM i800, RUGGEDCOM i801, RUGGEDCOM i802, RUGGEDCOM i803, RUGGEDCOM M2100, RUGGEDCOM M2100F, RUGGEDCOM M…

Fix: 5.6.0+
Fix from $1,600 2022-03-08
Spring Cloud Gateway MEDIUM 5.5
CVE-2022-22946

In spring cloud gateway versions prior to 3.1.1+ , applications that are configured to enable HTTP2 and no key store or trusted certificates are set …

Patch available
Fix from $1,600 2022-03-04
Node.js HIGH 7.4
CVE-2021-44531EPSS 8%

Accepting arbitrary Subject Alternative Name (SAN) types, unless a PKI is specifically defined to use a particular SAN type, can result in bypassing …

Fix: 12.22.9 / 14.18.3+
Fix from $1,950 2022-02-24