Vulnerability index

Browse CVEs

1,354 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Certificate ValidationCWE-295 × clear
Evolution Rss MEDIUM 5.9
CVE-2021-39361

In GNOME evolution-rss through 0.3.96, network-soup.c does not enable TLS certificate verification on the SoupSessionSync objects it creates, leaving…

Fix: after 0.3.96
Fix from $1,600 2021-08-22
Debian Linux HIGH 7.5
CVE-2021-37698

Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for repor…

Fix: 2.11.10 / 2.12.6+
Fix from $1,950 2021-08-19
Desktop MEDIUM 6.5
CVE-2021-32728

The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with a computer. Clients using the Nextcloud end-to-end encryption …

Fix: 3.3.0+
Fix from $1,600 2021-08-18
Node.js MEDIUM 5.3
CVE-2021-22939EPSS 15%

If the Node.js https API was used incorrectly and "undefined" was in passed for the "rejectUnauthorized" parameter, no error was returned and connect…

Fix: 1.0.1.1 / 12.22.5+
Fix from $1,600 2021-08-16
Access Unit 2.0 Firmware MEDIUM 5.9
CVE-2021-31399

On 2N Access Unit 2.0 2.31.0.40.5 devices, an attacker can pose as the web relay for a man-in-the-middle attack.

No fix yet
Fix from $1,600 2021-08-13
Curl HIGH 7.5
CVE-2021-22926EPSS 10%

libcurl-using applications can ask for a specific client certificate to be used in a transfer. This is done with the `CURLOPT_SSLCERT` option (`--cer…

Fix: 7.78.0+
Fix from $1,950 2021-08-05
Cyber Protect Cloud HIGH 8.1
CVE-2021-32581

Acronis True Image prior to 2021 Update 4 for Windows, Acronis True Image prior to 2021 Update 5 for Mac, Acronis Agent prior to build 26653, Acronis…

Fix: 15.0.26653 / 15.0.27009+
Fix from $1,950 2021-08-05
Eaglesoft HIGH 7.5
CVE-2021-35193

Patterson Application Service in Patterson Eaglesoft 18 through 21 accepts the same certificate authentication across different customers' installati…

Fix: after 21.0
Fix from $1,950 2021-07-30
Infinias Eidc32 Firmware HIGH 7.5
CVE-2020-12681

Missing TLS certificate validation on 3xLogic Infinias eIDC32 devices through 3.4.125 allows an attacker to intercept/control the channel by which do…

Fix: after 3.4.125
Fix from $1,950 2021-07-26
Debian Linux MEDIUM 5.3
CVE-2020-36425

An issue was discovered in Arm Mbed TLS before 2.24.0. It incorrectly uses a revocationDate check when deciding whether to honor certificate revocati…

Fix: 2.7.17 / 2.16.8+
Fix from $1,600 2021-07-19
Consul HIGH 7.5
CVE-2021-32574

HashiCorp Consul and Consul Enterprise 1.3.0 through 1.10.0 Envoy proxy TLS configuration does not validate destination service identity in the encod…

Fix: 1.8.14 / 1.9.8+
Fix from $1,950 2021-07-17
Go MEDIUM 6.5
CVE-2021-34558EPSS 7%

The crypto/tls package of Go through 1.16.5 does not properly assert that the type of public key in an X.509 certificate matches the expected type wh…

Fix: 1.15.14 / 1.16.6+
Fix from $1,600 2021-07-15
Sinumerik Analyse Mycondition Firmware HIGH 7.4
CVE-2021-31892

A vulnerability has been identified in SINUMERIK Analyse MyCondition (All versions), SINUMERIK Analyze MyPerformance (All versions), SINUMERIK Analyz…

Fix: 2.00.18 / 3.00.18+
Fix from $1,950 2021-07-13
Nextcloud HIGH 7.5
CVE-2021-32727

Nextcloud Android Client is the Android client for Nextcloud. Clients using the Nextcloud end-to-end encryption feature download the public and priva…

Fix: 3.16.1+
Fix from $1,950 2021-07-12
Fedora HIGH 7.5
CVE-2021-36377

Fossil before 2.14.2 and 2.15.x before 2.15.2 often skips the hostname check during TLS certificate validation.

Fix: 2.14.2 / 2.15.2+
Fix from $1,950 2021-07-12
Openvpn HIGH 7.4
CVE-2021-3547

OpenVPN 3 Core Library version 3.6 and 3.6.1 allows a man-in-the-middle attacker to bypass the certificate authentication by issuing an unrelated ser…

Patch available
Fix from $1,950 2021-07-12
Catalyst Center HIGH 7.4
CVE-2021-1134

A vulnerability in the Cisco Identity Services Engine (ISE) integration feature of the Cisco DNA Center Software could allow an unauthenticated, remo…

Fix: 2.2.2.1+
Fix from $1,950 2021-06-29
Alienware M15 R6 Firmware MEDIUM 6.5
CVE-2021-21571

Dell UEFI BIOS https stack leveraged by the Dell BIOSConnect feature and Dell HTTPS Boot feature contains an improper certificate validation vulnerab…

Fix: 1.3.3 / 1.4.0+
Fix from $1,600 2021-06-24
Antivirus Plus HIGH 7.5
CVE-2020-15732

Improper Certificate Validation vulnerability in the Online Threat Prevention module as used in Bitdefender Total Security allows an attacker to pote…

Fix: 25.0.7.29+
Fix from $1,950 2021-06-22
Email Security Appliance HIGH 7.4
CVE-2021-1566

A vulnerability in the Cisco Advanced Malware Protection (AMP) for Endpoints integration of Cisco AsyncOS for Cisco Email Security Appliance (ESA) an…

Fix: 11.8.3-021 / 12.0.3-005+
Fix from $1,950 2021-06-16
Desktop MEDIUM 5.9
CVE-2021-22895

Nextcloud Desktop Client before 3.3.1 is vulnerable to improper certificate validation due to lack of SSL certificate verification when using the "Re…

Fix: 3.1.3+
Fix from $1,600 2021-06-11
Smart Life MEDIUM 5.9
CVE-2021-20732

The ATOM (ATOM - Smart life App for Android versions prior to 1.8.1 and ATOM - Smart life App for iOS versions prior to 1.8.2) does not verify server…

Fix: 1.8.1 / 1.8.2+
Fix from $1,600 2021-06-09
Emc Networker MEDIUM 5.3
CVE-2021-21559

Dell EMC NetWorker, versions 18.x, 19.1.x, 19.2.x 19.3.x, 19.4, and 19.4.0.1 contain an Improper Certificate Validation vulnerability in the client (…

Fix: 19.4.0.2+
Fix from $1,600 2021-06-08
Wp Cli HIGH 7.4
CVE-2021-29504

WP-CLI is the command-line interface for WordPress. An improper error handling in HTTPS requests management in WP-CLI version 0.12.0 and later allows…

Fix: 2.5.0+
Fix from $1,950 2021-06-07
Fortios HIGH 7.3
CVE-2021-24012

An improper following of a certificate's chain of trust vulnerability in FortiGate versions 6.4.0 to 6.4.4 may allow an LDAP user to connect to SSLVP…

Fix: 6.4.5+
Fix from $1,950 2021-06-02
Edgemax Edgerouter Firmware HIGH 7.5
CVE-2021-22909

A vulnerability found in EdgeMAX EdgeRouter V2.0.9 and earlier could allow a malicious actor to execute a man-in-the-middle (MitM) attack during a fi…

Fix: after 2.0.9
Fix from $1,950 2021-05-27
Libgrss HIGH 7.5
CVE-2016-20011

libgrss through 0.7.0 fails to perform TLS certificate verification when downloading feeds, allowing remote attackers to manipulate the contents of f…

Fix: after 0.7.0
Fix from $1,950 2021-05-25
Fusion CRITICAL 9.8
CVE-2020-28907

Incorrect SSL certificate validation in Nagios Fusion 4.1.8 and earlier allows for Escalation of Privileges or Code Execution as root via vectors rel…

Fix: after 4.1.8
Fix from $2,300 2021-05-24
Firefox MEDIUM 6.5
CVE-2007-5967

A flaw in Mozilla's embedded certificate code might allow web sites to install root certificates on devices without user approval.

Mitigation only
Fix from $1,600 2021-05-17
Debian Linux HIGH 7.5
CVE-2021-32919

An issue was discovered in Prosody before 0.11.9. The undocumented dialback_without_dialback option in mod_dialback enables an experimental feature f…

Fix: 0.11.9+
Fix from $1,950 2021-05-13