Vulnerability index

Browse CVEs

1,344 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Certificate ValidationCWE-295 × clear
Wolfssl HIGH 7.5
CVE-2026-6731

X.509 name constraint bypass via the Subject Common Name when treated as a DNS-type name. A certificate whose Subject CN violates an issuing CA's DNS…

Fix: 5.9.2+
Fix from $1,950 2026-06-25
Wolfssl MEDIUM 5.3
CVE-2026-6450

A CRL critical extension bypass exists in ParseCRL_Extensions where critical extensions are not properly enforced, allowing a crafted CRL with an unh…

Fix: 5.9.2+
Fix from $1,600 2026-06-25
Wolfssl HIGH 7.5
CVE-2026-55960

Un-negotiated Raw Public Key (RFC 7250) accepted in place of an X.509 certificate, bypassing chain validation. A raw public key has no chain, so Pars…

Fix: 5.9.2+
Fix from $1,950 2026-06-25
Wolfssl MEDIUM 5.3
CVE-2026-55964

Chain intermediate CA:TRUE without keyCertSign accepted as a signing CA. Intermediate CA certificates are required to have the keyCertSign key usage …

Fix: 5.9.2+
Fix from $1,600 2026-06-25
Wolfssl MEDIUM 5.3
CVE-2026-10592

Certificates with wildcard DNS SANs (e.g. *.example.com) bypassed CA name-constraint checks. A certificate with a wildcard DNS SAN that should be rej…

Fix: 5.9.2+
Fix from $1,600 2026-06-25
Wolfssl HIGH 7.5
CVE-2026-11310

X.509 trust-chain bypass in the OpenSSL compatibility certificate verifier (wolfSSL_X509_verify_cert()). This affects only builds with --enable-opens…

Fix: 5.9.2+
Fix from $1,950 2026-06-25
Wolfssl MEDIUM 6.5
CVE-2026-6091

Partial-chain certificate verification may accept chains that terminate at a peer-supplied, untrusted intermediate certificate rather than a trusted …

Fix: 5.9.2+
Fix from $1,600 2026-06-25
Wolfssl HIGH 7.5
CVE-2026-11999

X.509 trust-chain bypass (path-depth exhaustion) in the OpenSSL compatibility certificate verifier (wolfSSL_X509_verify_cert()). This affects only bu…

Fix: 5.9.2+
Fix from $1,950 2026-06-25
Display And Peripheral Manager HIGH 7.8
CVE-2026-46734

Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3, contain an Improper Certificate Validation vulnerability. A low privileged att…

Fix: 2.3.0+
Fix from $1,950 2026-06-25
Unclassified MEDIUM 5.9
CVE-2026-54323

Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. Prior to 0.185.0, the daemon's git clone …

Mitigation only
Fix from $1,600 2026-06-23
Openshift Container Platform HIGH 8.3
CVE-2026-54100

A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. WMCO establishes SSH connections to Windows …

Fix: after 4.22.1
Fix from $1,950 2026-06-22
Db2 MEDIUM 6.5
CVE-2025-2669

IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions 4.8, 5.0, 5.1, 5.2, 5.3 could allow a privileged user to perform opera…

Fix: 5.4+
Fix from $1,600 2026-06-22
Undici HIGH 7.4
CVE-2026-9697

Impact: undici's ProxyAgent silently drops the requestTls option when configured with a SOCKS5 proxy URI (socks5:// or socks://). The target HTTPS co…

Fix: 7.28.0 / 8.5.0+
Fix from $1,950 2026-06-17
Powerflex Manager MEDIUM 6.5
CVE-2024-47477

Dell PowerFlex Manager, versions prior to 4.5.1.1, contain an improper certificate validation vulnerability. A remote unauthenticated attacker could …

Fix: 4.5.1.1+
Fix from $1,600 2026-06-17
Unclassified HIGH 8.6
CVE-2025-71261

An attacker with network-level access between the SUSE Virtualization and Rancher Manager in SUSE Harvester before 1.8.0 could interfere with the TL…

Mitigation only
Fix from $1,950 2026-06-16
Eos Network Setting Tool CRITICAL 9.8
CVE-2026-9258

Improper validation of SSH host keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier

Fix: 1.5.1+
Fix from $2,300 2026-06-16
Eos Network Setting Tool CRITICAL 9.8
CVE-2026-9259

Improper validation of server certificates in Canon EOS Network Setting Tool Version 1.5.0 or earlier

Fix: 1.5.1+
Fix from $2,300 2026-06-16
Unclassified CRITICAL 9.1
CVE-2026-45388

In OCaml-TLS before 2.1.0, the client implementation does insufficient checks of the certificate provided by the server, which allows impersonation w…

Mitigation only
Fix from $2,300 2026-06-15
Unclassified HIGH 7.4
CVE-2026-45389

In OCaml-TLS before 2.1.0, the server implementation does insufficient checks of the certificate provided by the client (when doing client authentica…

Mitigation only
Fix from $1,950 2026-06-15
Idira Privilege Cloud Connector HIGH 8.8
CVE-2026-45170

Idira Vendor PAM - Self-Hosted Connector versions prior 1.1.100504 under specific conditions and configuration scenarios, TLS certificate validation …

Fix: 1.1.100504+
Fix from $1,950 2026-06-12
Idira Endpoint Privilege Manager HIGH 7.8
CVE-2026-45175

Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within internal agent validation processes. A local att…

Fix: 26.5.0+
Fix from $1,950 2026-06-11
Unclassified MEDIUM 5.0
CVE-2026-40992

Spring Boot's Mail auto-configuration does not enable hostname verification. Applications that set the relevant JavaMail property, such as spring.mai…

Mitigation only
Fix from $1,600 2026-06-11
Assisted Migration Agent HIGH 7.4
CVE-2026-53475

A flaw was found in assisted-migration-agent. The application hardcodes insecure Transport Layer Security (TLS) connections when communicating with v…

Fix: 2026-06-10+
Fix from $1,950 2026-06-10
Unclassified HIGH 7.3
CVE-2026-9758

Improper comparison with the certificates trusted list in S2OPC allows an attacker well-formed untrusted certificate to be considered trusted

Mitigation only
Fix from $1,950 2026-06-10
OpenSSL MEDIUM 5.3
CVE-2026-42769

Issue Summary: An error in the callback used to verify the certificate provided in a Root CA key update Certificate Management Protocol (CMP) message…

Fix: 3.4.6 / 3.5.7+
Fix from $1,600 2026-06-09
Unclassified HIGH 7.4
CVE-2026-50752

A weakness in the certificate validation logic of the deprecated IKEv1 key exchange may allow an unauthenticated attacker positioned as a man-in-the-…

Mitigation only
Fix from $1,950 2026-06-08
Termix HIGH 8.0
CVE-2026-45745

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Starting in version 1.7.0, Termix Deskt…

No fix yet
Fix from $1,950 2026-06-05
Unclassified HIGH 7.4
CVE-2026-44393

An issue was discovered in OpenStack oslo.messaging 1.0.0 through 17.3.0. The oslo.messaging RabbitMQ driver does not perform TLS hostname verificati…

Mitigation only
Fix from $1,950 2026-06-04
Unclassified HIGH 7.8
CVE-2026-41859

A network man-in-the-middle between nats-sync and the BOSH director can steal the director credentials (Basic auth header or UAA client secret) and c…

Mitigation only
Fix from $1,950 2026-06-04
Airflow MEDIUM 5.9
CVE-2026-49267

Apache Airflow's EmailOperator and the underlying `airflow.utils.email` helpers established SMTP STARTTLS connections without verifying the remote ce…

Fix: 3.2.2+
Fix from $1,600 2026-06-01