Vulnerability index

Browse CVEs

1,354 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Certificate ValidationCWE-295 × clear
Node.js MEDIUM 5.3
CVE-2021-44532EPSS 10%

Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 converts SANs (Subject Alternative Names) to a string format. It uses this string to check peer…

Fix: 12.22.9 / 14.18.3+
Fix from $1,600 2022-02-24
Node.js MEDIUM 5.3
CVE-2021-44533EPSS 9%

Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 did not handle multi-value Relative Distinguished Names correctly. Attackers could craft certif…

Fix: 8.0.29 / 12.22.9+
Fix from $1,600 2022-02-24
Wolfssl MEDIUM 6.5
CVE-2022-25638

In wolfSSL before 5.2.0, certificate validation may be bypassed during attempted authentication by a TLS 1.3 client to a TLS 1.3 server. This occurs …

Fix: 5.2.0+
Fix from $1,600 2022-02-24
Wolfssl HIGH 7.5
CVE-2022-25640

In wolfSSL before 5.2.0, a TLS 1.3 server cannot properly enforce a requirement for mutual authentication. A client can simply omit the certificate_v…

Fix: 5.2.0+
Fix from $1,950 2022-02-24
Fedora HIGH 7.5
CVE-2021-25636

LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occur…

Fix: 7.2.5+
Fix from $1,950 2022-02-24
Envoy CRITICAL 9.8
CVE-2022-21654

Envoy is an open source edge and service proxy, designed for cloud-native applications. Envoy's tls allows re-use when some cert validation settings …

Fix: 1.18.6 / 1.19.3+
Fix from $2,300 2022-02-22
Envoy MEDIUM 5.9
CVE-2022-21656

Envoy is an open source edge and service proxy, designed for cloud-native applications. The default_validator.cc implementation used to implement the…

Fix: 1.20.2+
Fix from $1,600 2022-02-22
Envoy MEDIUM 6.5
CVE-2022-21657

Envoy is an open source edge and service proxy, designed for cloud-native applications. In affected versions Envoy does not restrict the set of certi…

Fix: 1.18.6 / 1.19.3+
Fix from $1,600 2022-02-22
Infinity Connect CRITICAL 9.8
CVE-2021-29656

Pexip Infinity Connect before 1.8.0 mishandles TLS certificate validation. The allow list is not properly checked.

Fix: 1.8.0+
Fix from $2,300 2022-02-18
Traefik HIGH 7.5
CVE-2022-23632

Traefik is an HTTP reverse proxy and load balancer. Prior to version 2.6.1, Traefik skips the router transport layer security (TLS) configuration whe…

Fix: 2.6.1+
Fix from $1,950 2022-02-17
Hutool CRITICAL 9.8
CVE-2022-22885

Hutool v5.7.18's HttpRequest was discovered to ignore all TLS/SSL certificate validation.

No fix yet
Fix from $2,300 2022-02-16
Xmpp MEDIUM 5.9
CVE-2022-24968

In Mellium mellium.im/xmpp through 0.21.0, an attacker capable of spoofing DNS TXT records can redirect a WebSocket connection request to a server un…

Fix: 0.21.1+
Fix from $1,600 2022-02-11
Rv340 Firmware HIGH 8.0
CVE-2022-20703 KEVEPSS 9%

Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Ex…

Fix: after 1.0.03.24
Fix from $1,950 2022-02-10
Clearscada MEDIUM 5.9
CVE-2022-24319

A CWE-295: Improper Certificate Validation vulnerability exists that could allow a Man-in-theMiddle attack when communications between the client and…

Patch available
Fix from $1,600 2022-02-09
Clearscada MEDIUM 5.9
CVE-2022-24320

A CWE-295: Improper Certificate Validation vulnerability exists that could allow a Man-in-theMiddle attack when communications between the client and…

Patch available
Fix from $1,600 2022-02-09
Android MEDIUM 6.8
CVE-2022-20034

In Preloader XFLASH, there is a possible escalation of privilege due to an improper certificate validation. This could lead to local escalation of pr…

Mitigation only
Fix from $1,600 2022-02-09
Seaconnect 370w Firmware HIGH 8.1
CVE-2021-21959

A misconfiguration exists in the MQTTS functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. This misconfiguration significantly simplifie…

No fix yet
Fix from $1,950 2022-02-04
Technical Specifications For Digital Covid Certificates CRITICAL 9.8
CVE-2021-40855

The EU Technical Specifications for Digital COVID Certificates before 1.1 mishandle certificate governance. A non-production public key certificate c…

Fix: 1.1+
Fix from $2,300 2022-01-21
Junos HIGH 7.4
CVE-2022-22156

An Improper Certificate Validation weakness in the Juniper Networks Junos OS allows an attacker to perform Person-in-the-Middle (PitM) attacks when a…

Fix: after 18.3
Fix from $1,950 2022-01-19
Windows 10 HIGH 7.8
CVE-2022-21836

Windows Certificate Spoofing Vulnerability

No fix yet
Fix from $1,950 2022-01-11
E2guardian HIGH 7.4
CVE-2021-44273

e2guardian v5.4.x <= v5.4.3r is affected by missing SSL certificate validation in the SSL MITM engine. In standalone mode (i.e., acting as a proxy or…

Fix: after 5.4.3r
Fix from $1,950 2021-12-23
Forticlient HIGH 7.5
CVE-2021-41028

A combination of a use of hard-coded cryptographic key vulnerability [CWE-321] in FortiClientEMS 7.0.1 and below, 6.4.6 and below and an improper cer…

Fix: after 6.4.6
Fix from $1,950 2021-12-16
Defender For Iot CRITICAL 9.8
CVE-2021-43882

Microsoft Defender for IoT Remote Code Execution Vulnerability

Fix: 10.5.3+
Fix from $2,300 2021-12-15
Sling Commons Messaging Mail HIGH 7.4
CVE-2021-44549

Apache Sling Commons Messaging Mail provides a simple layer on top of JavaMail/Jakarta Mail for OSGi to send mails via SMTPS. To reduce the risk of "…

Mitigation only
Fix from $1,950 2021-12-14
Sinumerik Edge HIGH 7.4
CVE-2021-42027

A vulnerability has been identified in SINUMERIK Edge (All versions < V3.2). The affected software does not properly validate the server certificate …

Fix: 3.2+
Fix from $1,950 2021-12-14
Spectrum Protect Plus MEDIUM 5.9
CVE-2020-4496

The IBM Spectrum Protect Plus 10.1.0.0 through 10.1.8.x server connection to an IBM Spectrum Protect Plus workload agent is subject to a man-in-the-m…

Fix: after 10.1.8.1
Fix from $1,600 2021-12-13
Git HIGH 7.4
CVE-2021-34599

Affected versions of CODESYS Git in Versions prior to V1.1.0.0 lack certificate validation in HTTPS handshakes. CODESYS Git does not implement certif…

Fix: 1.1.0.0+
Fix from $1,950 2021-12-01
Amazon Web Services Aws C Io HIGH 8.8
CVE-2021-40828

Connections initialized by the AWS IoT Device SDK v2 for Java (versions prior to 1.3.3), Python (versions prior to 1.5.18), C++ (versions prior to 1.…

Fix: 0.9.13 / 1.3.3+
Fix from $1,950 2021-11-23
Amazon Web Services Internet Of Things Device Software Development Kit V2 HIGH 8.8
CVE-2021-40829

Connections initialized by the AWS IoT Device SDK v2 for Java (versions prior to 1.4.2), Python (versions prior to 1.6.1), C++ (versions prior to 1.1…

Fix: 1.4.2 / 1.5.3+
Fix from $1,950 2021-11-23
Amazon Web Services Aws C Io HIGH 8.8
CVE-2021-40830

The AWS IoT Device SDK v2 for Java, Python, C++ and Node.js appends a user supplied Certificate Authority (CA) to the root CAs instead of overriding …

Fix: 1.5.0 / 1.5.3+
Fix from $1,950 2021-11-23