Vulnerability index

Browse CVEs

1,354 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Certificate ValidationCWE-295 × clear
Nginx Controller MEDIUM 5.4
CVE-2020-5909

In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, when users run the command displayed in NGINX Controller user interface (UI) to fetch the agent inst…

Fix: after 3.5.0
Fix from $1,600 2020-07-02
Trojita MEDIUM 5.9
CVE-2020-15047

MSA/SMTP.cpp in Trojita before 0.8 ignores certificate-verification errors, which allows man-in-the-middle attackers to spoof SMTP servers.

Fix: 0.8+
Fix from $1,600 2020-06-25
Emc Unisphere For Powermax HIGH 8.1
CVE-2020-5367

Dell EMC Unisphere for PowerMax versions prior to 9.1.0.17, Dell EMC Unisphere for PowerMax Virtual Appliance versions prior to 9.1.0.17, and PowerMa…

Fix: 9.1.0.17+
Fix from $1,950 2020-06-23
Sophos Secure Email MEDIUM 5.9
CVE-2020-14980

The Sophos Secure Email application through 3.9.4 for Android has Missing SSL Certificate Validation.

Fix: after 3.9.4
Fix from $1,600 2020-06-22
Password Vault MEDIUM 5.9
CVE-2020-14981

The ThreatTrack VIPRE Password Vault app through 1.100.1090 for iOS has Missing SSL Certificate Validation.

Fix: after 1.100.1090
Fix from $1,600 2020-06-22
Mattermost Server MEDIUM 5.3
CVE-2016-11076

An issue was discovered in Mattermost Server before 3.0.0. It does not ensure that a cookie is used over SSL.

Fix: 3.0.0+
Fix from $1,600 2020-06-19
Mattermost Server HIGH 7.5
CVE-2017-18909

An issue was discovered in Mattermost Server before 3.9.0 when SAML is used. Encryption and signature verification are not mandatory.

Fix: 3.9.0+
Fix from $1,950 2020-06-19
Mattermost Server CRITICAL 9.1
CVE-2017-18911

An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. The X.509 certificate validation can be skipped for a TLS-based e-mail s…

Fix: 3.6.7 / 3.7.5+
Fix from $2,300 2020-06-19
Webex Meetings HIGH 8.8
CVE-2020-3342

A vulnerability in the software update feature of Cisco Webex Meetings Desktop App for Mac could allow an unauthenticated, remote attacker to execute…

Fix: 39.5.11+
Fix from $1,950 2020-06-18
Mq MEDIUM 6.5
CVE-2020-4320

IBM MQ Appliance and IBM MQ AMQP Channels 8.0, 9.0 LTS, 9.1 LTS, and 9.1 CD do not correctly block or allow clients based on the certificate distingu…

Fix: 8.0.0.15 / 9.0.0.10+
Fix from $1,600 2020-06-16
Nutfind MEDIUM 5.9
CVE-2019-16252

Missing SSL Certificate Validation in the Nutfind.com application through 3.9.12 for Android allows a man-in-the-middle attacker to sniff and manipul…

Fix: after 3.9.12
Fix from $1,600 2020-06-12
Globalprotect MEDIUM 5.3
CVE-2020-2033

When the pre-logon feature is enabled, a missing certification validation in Palo Alto Networks GlobalProtect app can disclose the pre-logon authenti…

Fix: 5.0.10 / 5.1.4+
Fix from $1,600 2020-06-10
Android MEDIUM 5.3
CVE-2020-0119

In addOrUpdateNetworkInternal and related functions of WifiConfigManager.java, there is a possible man in the middle attack due to improper certifica…

Patch available
Fix from $1,600 2020-06-10
Couchbase Server Java Sdk HIGH 7.5
CVE-2020-9040

Couchbase Server Java SDK before 2.7.1.1 allows a potential attacker to forge an SSL certificate and pose as the intended peer. An attacker can lever…

Fix: 2.7.1.1+
Fix from $1,950 2020-06-08
Node.js HIGH 7.4
CVE-2020-8172EPSS 6%

TLS session reuse can lead to host certificate verification bypass in node version < 12.18.0 and < 14.4.0.

Fix: 12.18.0 / 14.4.0+
Fix from $1,950 2020-06-08
Django MEDIUM 5.9
CVE-2020-13254EPSS 6%

An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. In cases where a memcached backend does not perform key validation, passing…

Fix: 2.2.13 / 3.0.7+
Fix from $1,600 2020-06-03
R6120 Firmware MEDIUM 5.9
CVE-2020-13245

Certain NETGEAR devices are affected by Missing SSL Certificate Validation. This affects R7000 1.0.9.6_1.2.19 through 1.0.11.100_10.2.10, and possibl…

No fix yet
Fix from $1,600 2020-05-28
Ubuntu Linux MEDIUM 6.5
CVE-2020-13645

In GNOME glib-networking through 2.64.2, the implementation of GTlsClientConnection skips hostname verification of the server's TLS certificate if th…

Fix: 2.5.11 / 2.62.4+
Fix from $1,600 2020-05-28
Pichi MEDIUM 5.9
CVE-2020-13616

The boost ASIO wrapper in net/asio.cpp in Pichi before 1.3.0 lacks TLS hostname verification.

Fix: 1.3.0+
Fix from $1,600 2020-05-26
Fedora MEDIUM 5.9
CVE-2020-13614

An issue was discovered in ssl.c in Axel before 2.17.8. The TLS implementation lacks hostname verification.

Fix: 2.17.8+
Fix from $1,600 2020-05-26
Qore MEDIUM 5.9
CVE-2020-13615

lib/QoreSocket.cpp in Qore before 0.9.4.2 lacks hostname verification for X.509 certificates.

Fix: 0.9.4.2+
Fix from $1,600 2020-05-26
Fedora HIGH 7.4
CVE-2020-13482

EM-HTTP-Request 1.1.5 uses the library eventmachine in an insecure way that allows an attacker to perform a man-in-the-middle attack against users of…

Patch available
Fix from $1,950 2020-05-25
Windows 10 MEDIUM 5.3
CVE-2020-1113EPSS 7%

A security feature bypass vulnerability exists in Microsoft Windows when the Task Scheduler service fails to properly verify client connections over …

Patch available
Fix from $1,600 2020-05-21
Em Imap HIGH 7.4
CVE-2020-13163

em-imap 0.5 uses the library eventmachine in an insecure way that allows an attacker to perform a man-in-the-middle attack against users of the libra…

No fix yet
Fix from $1,950 2020-05-19
Keycloak MEDIUM 5.9
CVE-2020-1758

A flaw was found in Keycloak in versions before 10.0.0, where it does not perform the TLS hostname verification while sending emails using the SMTP s…

Fix: 10.0.0+
Fix from $1,600 2020-05-15
Mail HIGH 7.0
CVE-2020-8156

A missing verification of the TLS host in Nextcloud Mail 1.1.3 allowed a man in the middle attack.

Fix: 1.1.4+
Fix from $1,950 2020-05-12
Zulip Desktop CRITICAL 9.8
CVE-2020-12637

Zulip Desktop before 5.2.0 has Missing SSL Certificate Validation because all validation was inadvertently disabled during an attempt to recognize th…

Fix: 5.2.0+
Fix from $2,300 2020-05-09
Java Websocket HIGH 8.1
CVE-2020-11050

In Java-WebSocket less than or equal to 1.4.1, there is an Improper Validation of Certificate with Host Mismatch where WebSocketClient does not perfo…

Fix: after 1.4.1
Fix from $1,950 2020-05-07
Amazon Ec2 MEDIUM 5.6
CVE-2020-2187

Jenkins Amazon EC2 Plugin 1.50.1 and earlier unconditionally accepts self-signed certificates and does not perform hostname validation, enabling man-…

Fix: after 1.50.1
Fix from $1,600 2020-05-06
Automation Studio MEDIUM 5.9
CVE-2019-19101

A missing secure communication definition and an incomplete TLS validation in the upgrade service in B&R Automation Studio versions 4.0.x, 4.1.x, 4.2…

Fix: 4.3.11 / 4.4.9+
Fix from $1,600 2020-04-29