Vulnerability index

Browse CVEs

1,354 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Certificate ValidationCWE-295 × clear
Nim HIGH 7.5
CVE-2021-29495

Nim is a statically typed compiled systems programming language. In Nim standard library before 1.4.2, httpClient SSL/TLS certificate verification wa…

Fix: 1.4.2+
Fix from $1,950 2021-05-07
Paxstore MEDIUM 6.5
CVE-2020-36127

Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by an information disclosure vulnerability. Through the PUK signature functionali…

Fix: after 7.0.8_20200511171508
Fix from $1,600 2021-05-07
Dap 1880ac Firmware HIGH 8.8
CVE-2021-20695

Improper following of a certificate's chain of trust vulnerability in DAP-1880AC firmware version 1.21 and earlier allows a remote authenticated atta…

Fix: after 1.21
Fix from $1,950 2021-04-26
Xmlhttprequest Ssl CRITICAL 9.4
CVE-2021-31597

The xmlhttprequest-ssl package before 1.6.1 for Node.js disables SSL certificate validation by default, because rejectUnauthorized (when the property…

Fix: 1.6.1+
Fix from $2,300 2021-04-23
Vault HIGH 7.5
CVE-2021-27400

HashiCorp Vault and Vault Enterprise Cassandra integrations (storage backend and database secrets engine plugin) did not validate TLS certificates wh…

Fix: 1.6.4 / 1.7.1+
Fix from $1,950 2021-04-22
Vault HIGH 7.5
CVE-2021-29653

HashiCorp Vault and Vault Enterprise 1.5.1 and newer, under certain circumstances, may exclude revoked but unexpired certificates from the CRL. Fixed…

Fix: 1.5.8 / 1.6.4+
Fix from $1,950 2021-04-22
Home Center 2 Firmware MEDIUM 5.9
CVE-2021-20989

Fibaro Home Center 2 and Lite devices with firmware version 4.600 and older initiate SSH connections to the Fibaro cloud to provide remote access and…

Fix: after 4.600
Fix from $1,600 2021-04-19
Mh702x Firmware CRITICAL 9.8
CVE-2021-3460

The Motorola MH702x devices, prior to version 2.0.0.301, do not properly verify the server certificate during communication with the support server w…

Fix: 2.0.0.301+
Fix from $2,300 2021-04-13
Database Tools MEDIUM 6.5
CVE-2020-7924

Usage of specific command line parameter in MongoDB Tools which was originally intended to just skip hostname checks, may result in MongoDB skipping …

Fix: 0.6.0 / 3.6.21+
Fix from $1,600 2021-04-12
Application Automation Tools MEDIUM 6.5
CVE-2021-22511

Improper Certificate Validation vulnerability in Micro Focus Application Automation Tools Plugin - Jenkins plugin. The vulnerability affects version …

Fix: after 6.7
Fix from $1,600 2021-04-08
Insider Threat Management HIGH 7.4
CVE-2021-27899

The Proofpoint Insider Threat Management Agents (formerly ObserveIT Agent) for MacOS and Linux perform improper validation of the ITM Server's certif…

Fix: 7.9.3 / 7.10.3+
Fix from $1,950 2021-04-06
Nim MEDIUM 5.9
CVE-2021-21373

Nimble is a package manager for the Nim programming language. In Nim release versions before versions 1.2.10 and 1.4.4, "nimble refresh" fetches a li…

Fix: 1.2.10 / 1.4.4+
Fix from $1,600 2021-03-26
Nim HIGH 8.1
CVE-2021-21374

Nimble is a package manager for the Nim programming language. In Nim release versions before versions 1.2.10 and 1.4.4, "nimble refresh" fetches a li…

Fix: 1.2.10 / 1.4.4+
Fix from $1,950 2021-03-26
OpenSSL HIGH 7.4
CVE-2021-3450EPSS 18%

The X509_V_FLAG_X509_STRICT flag enables additional security checks of the certificates present in a certificate chain. It is not set by default. Sta…

Fix: 1.1.1k / 10.24.1+
Fix from $1,950 2021-03-25
Mifos Mobile HIGH 7.4
CVE-2021-21385

Mifos-Mobile Android Application for MifosX is an Android Application built on top of the MifosX Self-Service platform. Mifos-Mobile before commit e5…

Fix: 2021-03-14+
Fix from $1,950 2021-03-24
Jabber MEDIUM 5.6
CVE-2021-1471

Multiple vulnerabilities in Cisco Jabber for Windows, Cisco Jabber for MacOS, and Cisco Jabber for mobile platforms could allow an attacker to execut…

Fix: 12.1.5 / 12.5.4+
Fix from $1,600 2021-03-24
Urllib3 MEDIUM 6.5
CVE-2021-28363

The urllib3 library 1.26.x before 1.26.4 for Python omits SSL certificate validation in some cases involving HTTPS to HTTPS proxies. The initial conn…

Fix: 1.26.4+
Fix from $1,600 2021-03-15
Pjsip MEDIUM 6.8
CVE-2020-15260

PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, S…

Fix: after 2.10
Fix from $1,600 2021-03-10
Br200 Firmware MEDIUM 6.5
CVE-2021-27257

This vulnerability allows network-adjacent attackers to compromise the integrity of downloaded information on affected installations of NETGEAR R7800…

Fix: 1.0.0.134 / 1.0.1.60+
Fix from $1,600 2021-03-05
Spire HIGH 8.1
CVE-2021-27098

In SPIRE 0.8.1 through 0.8.4 and before versions 0.9.4, 0.10.2, 0.11.3 and 0.12.1, specially crafted requests to the FetchX509SVID RPC of SPIRE Serve…

Fix: 0.9.4 / 0.10.2+
Fix from $1,950 2021-03-05
GitLab HIGH 7.2
CVE-2021-22189

Starting with version 13.7 the Gitlab CE/EE editions were affected by a security issue related to the validation of the certificates for the Fortinet…

Fix: 13.6.7 / 13.7.7+
Fix from $1,950 2021-03-04
Fedora MEDIUM 5.9
CVE-2020-28972

In SaltStack Salt before 3002.5, authentication to VMware vcenter, vsphere, and esxi servers (in the vmware.py files) does not always validate the SS…

Fix: 2015.8.10 / 2015.8.13+
Fix from $1,600 2021-02-27
Fedora HIGH 7.4
CVE-2020-35662

In SaltStack Salt before 3002.5, when authenticating to services using certain modules, the SSL certificate is not always validated.

Fix: 2015.8.10 / 2015.8.13+
Fix from $1,950 2021-02-27
Fedora CRITICAL 9.8
CVE-2021-3406

A flaw was found in keylime 5.8.1 and older. The issue in the Keylime agent and registrar code invalidates the cryptographic chain of trust from the …

Fix: after 5.8.1
Fix from $2,300 2021-02-25
Libmongocrypt MEDIUM 6.8
CVE-2021-20327

A specific version of the Node.js mongodb-client-encryption module does not perform correct validation of the KMS server’s certificate. This vulnerab…

Mitigation only
Fix from $1,600 2021-02-25
Java Driver MEDIUM 6.8
CVE-2021-20328

Specific versions of the Java driver that support client-side field level encryption (CSFLE) fail to perform correct host name verification on the KM…

Fix: 1.13.3 / 3.11.3+
Fix from $1,600 2021-02-25
Stunnel HIGH 7.5
CVE-2021-20230

A flaw was found in stunnel before 5.57, where it improperly validates client certificates when it is configured to use both redirect and verifyChain…

Fix: 5.57+
Fix from $1,950 2021-02-23
Canadian Shield MEDIUM 5.9
CVE-2021-27189

The CIRA Canadian Shield app before 4.0.13 for iOS lacks SSL Certificate Validation.

Fix: 4.0.13+
Fix from $1,600 2021-02-23
Twitter Stream MEDIUM 5.9
CVE-2020-24392

In voloko twitter-stream 0.1.10, missing TLS hostname validation allows an attacker to perform a man-in-the-middle attack against users of the librar…

No fix yet
Fix from $1,600 2021-02-19
Tweetstream MEDIUM 5.9
CVE-2020-24393

TweetStream 2.6.1 uses the library eventmachine in an insecure way that does not have TLS hostname validation. This allows an attacker to perform a m…

No fix yet
Fix from $1,600 2021-02-19