Vulnerability index

Browse CVEs

1,354 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Certificate ValidationCWE-295 × clear
Amazon Web Services Aws C Io HIGH 7.2
CVE-2021-40831

The AWS IoT Device SDK v2 for Java, Python, C++ and Node.js appends a user supplied Certificate Authority (CA) to the root CAs instead of overriding …

Fix: 1.5.0 / 1.6.0+
Fix from $1,950 2021-11-23
Enterprise Linux HIGH 8.1
CVE-2021-3935

When PgBouncer is configured to use "cert" authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first e…

Fix: 1.16.1+
Fix from $1,950 2021-11-22
Command Centre Mobile Client MEDIUM 6.8
CVE-2021-23155

Improper validation of the cloud certificate chain in Mobile Client allows man-in-the-middle attack to impersonate the legitimate Command Centre Serv…

Fix: 8.60.065+
Fix from $1,600 2021-11-18
Command Centre Mobile Connect HIGH 8.1
CVE-2021-23162

Improper validation of the cloud certificate chain in Mobile Connect allows man-in-the-middle attack to impersonate the legitimate Command Centre Ser…

Fix: 15.04.040+
Fix from $1,950 2021-11-18
Command Centre MEDIUM 6.8
CVE-2021-23167

Improper certificate validation vulnerability in SMTP Client allows man-in-the-middle attack to retrieve sensitive information from the Command Centr…

Fix: 8.30.1454 / 8.40.2063+
Fix from $1,600 2021-11-18
Epyc 7601 Firmware MEDIUM 5.5
CVE-2021-26320

Insufficient validation of the AMD SEV Signing Key (ASK) in the SEND_START command in the SEV Firmware may allow a local authenticated attacker to pe…

Mitigation only
Fix from $1,600 2021-11-16
Fortios MEDIUM 6.5
CVE-2021-41019

An improper validation of certificate with host mismatch [CWE-297] vulnerability in FortiOS versions 6.4.6 and below may allow the connection to a ma…

Fix: after 6.4.6
Fix from $1,600 2021-11-02
Infosphere Information Server HIGH 7.5
CVE-2021-29737

IBM InfoSphere Data Flow Designer Engine (IBM InfoSphere Information Server 11.7 ) component has improper validation of the REST API server certifica…

Patch available
Fix from $1,950 2021-11-02
Update Manager MEDIUM 6.7
CVE-2021-22278

A certificate validation vulnerability in PCM600 Update Manager allows attacker to get unwanted software packages to be installed on computer which h…

Fix: after 2.10
Fix from $1,600 2021-10-28
Cfengine MEDIUM 6.5
CVE-2021-36756

CFEngine Enterprise 3.15.0 through 3.15.4 has Missing SSL Certificate Validation.

Fix: after 3.15.4
Fix from $1,600 2021-10-27
Fedora HIGH 7.5
CVE-2021-41611

An issue was discovered in Squid 5.0.6 through 5.1.x before 5.2. When validating an origin server or peer certificate, Squid may incorrectly classify…

Fix: 5.2+
Fix from $1,950 2021-10-18
Snkrdunk HIGH 7.4
CVE-2021-20833

The SNKRDUNK Market Place App for iOS versions prior to 2.2.0 does not verify server certificate properly, which allows man-in-the-middle attackers t…

Fix: 2.2.0+
Fix from $1,950 2021-10-13
Debian Linux HIGH 7.5
CVE-2021-25634

LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occur…

Fix: 7.0.6 / 7.1.2+
Fix from $1,950 2021-10-12
Debian Linux HIGH 7.5
CVE-2021-25633

LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occur…

Fix: 7.0.6 / 7.1.2+
Fix from $1,950 2021-10-11
Activespaces HIGH 7.5
CVE-2021-35497

The FTL Server (tibftlserver) and Docker images containing tibftlserver components of TIBCO Software Inc.'s TIBCO ActiveSpaces - Community Edition, T…

Mitigation only
Fix from $1,950 2021-10-05
Experience Manager MEDIUM 5.9
CVE-2021-40713

Adobe Experience Manager version 6.5.9.0 (and earlier) is affected by a improper certificate validation vulnerability in the cold storage component. …

Fix: after 6.5.9.0
Fix from $1,600 2021-09-27
Meetings CRITICAL 9.8
CVE-2021-33907

The Zoom Client for Meetings for Windows in all versions before 5.3.0 fails to properly validate the certificate information used to sign .msi files …

Fix: 5.3.0+
Fix from $2,300 2021-09-27
Security Verify Bridge HIGH 7.5
CVE-2021-38864

IBM Security Verify Bridge 1.0.5.0 could allow a user to obtain sensitive information due to improper certificate validation. IBM X-Force ID: 208155.

Fix: 1.0.7+
Fix from $1,950 2021-09-23
Security Verify Bridge MEDIUM 5.5
CVE-2021-20435

IBM Security Verify Bridge 1.0.5.0 does not properly validate a certificate which could allow a local attacker to obtain sensitive information that c…

Fix: 1.0.7+
Fix from $1,600 2021-09-23
Cloud Connector CRITICAL 9.1
CVE-2021-33695

Potentially, SAP Cloud Connector, version - 2.0 communication with the backend is accepted without sufficient validation of the certificate.

Patch available
Fix from $2,300 2021-09-15
Ipados MEDIUM 5.3
CVE-2021-1837

A certificate validation issue was addressed. This issue is fixed in iOS 14.5 and iPadOS 14.5. An attacker in a privileged network position may be ab…

Fix: 14.5+
Fix from $1,600 2021-09-08
Nomad HIGH 8.8
CVE-2021-37218

HashiCorp Nomad and Nomad Enterprise Raft RPC layer allows non-server agents with a valid certificate signed by the same CA to access server-only fun…

Fix: 1.0.10 / 1.1.4+
Fix from $1,950 2021-09-07
Consul HIGH 8.8
CVE-2021-37219

HashiCorp Consul and Consul Enterprise 1.10.1 Raft RPC layer allows non-server agents with a valid certificate signed by the same CA to access server…

Fix: 1.8.15 / 1.9.9+
Fix from $1,950 2021-09-07
Remediate HIGH 7.5
CVE-2021-27018

The mechanism which performs certificate validation was discovered to have a flaw that resulted in certificates signed by an internal certificate aut…

Fix: 2.0.1+
Fix from $1,950 2021-08-30
Mbed Tls MEDIUM 5.9
CVE-2020-36477

An issue was discovered in Mbed TLS before 2.24.0. The verification of X.509 certificates when matching the expected common name (the cn argument of …

Fix: 2.24.0+
Fix from $1,600 2021-08-23
Debian Linux HIGH 7.5
CVE-2020-36478

An issue was discovered in Mbed TLS before 2.25.0 (and before 2.16.9 LTS and before 2.7.18 LTS). A NULL algorithm parameters entry looks identical to…

Fix: 2.2 / 2.7.18+
Fix from $1,950 2021-08-23
Debian Linux MEDIUM 5.9
CVE-2021-39365

In GNOME grilo though 0.3.13, grl-net-wc.c does not enable TLS certificate verification on the SoupSessionAsync objects it creates, leaving users vul…

Fix: after 0.3.13
Fix from $1,600 2021-08-22
Fedora MEDIUM 5.9
CVE-2021-39358

In GNOME libgfbgraph through 0.2.4, gfbgraph-photo.c does not enable TLS certificate verification on the SoupSessionSync objects it creates, leaving …

Fix: after 0.2.4
Fix from $1,600 2021-08-22
Fedora MEDIUM 5.9
CVE-2021-39359

In GNOME libgda through 6.0.0, gda-web-provider.c does not enable TLS certificate verification on the SoupSessionSync objects it creates, leaving use…

Fix: after 6.0.0
Fix from $1,600 2021-08-22
Fedora MEDIUM 5.9
CVE-2021-39360

In GNOME libzapojit through 0.0.3, zpj-skydrive.c does not enable TLS certificate verification on the SoupSessionSync objects it creates, leaving use…

Fix: after 0.0.3
Fix from $1,600 2021-08-22