Vulnerability index

Browse CVEs

1,354 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Certificate ValidationCWE-295 × clear
Iotdb CRITICAL 9.8
CVE-2020-1952

An issue was found in Apache IoTDB .9.0 to 0.9.1 and 0.8.0 to 0.8.2. When starting IoTDB, the JMX port 31999 is exposed with no certification.Then, c…

Fix: after 0.9.1
Fix from $2,300 2020-04-27
Nginx Controller HIGH 7.4
CVE-2020-5864

In versions of NGINX Controller prior to 3.2.0, communication between NGINX Controller and NGINX Plus instances skip TLS verification by default.

Fix: 3.3.0+
Fix from $1,950 2020-04-23
Mailstore Server MEDIUM 5.9
CVE-2020-11806

In MailStore Outlook Add-in (and Email Archive Outlook Add-in) through 12.1.2, the login process does not validate the validity of the certificate pr…

Fix: after 12.1.2
Fix from $1,600 2020-04-23
R8900 Firmware HIGH 7.5
CVE-2020-11792

NETGEAR R8900, R9000, RAX120, and XR700 devices before 2020-01-20 are affected by Transport Layer Security (TLS) certificate private key disclosure.

Mitigation only
Fix from $1,950 2020-04-15
Mongodb Enterprise Kubernetes Operator MEDIUM 6.5
CVE-2020-7922

X.509 certificates generated by the MongoDB Enterprise Kubernetes Operator may allow an attacker with access to the Kubernetes cluster improper acces…

Fix: after 1.4.4
Fix from $1,600 2020-04-09
Pulse Connect Secure CRITICAL 9.1
CVE-2020-11580

An issue was discovered in Pulse Secure Pulse Connect Secure (PCS) through 2020-04-06. The applet in tncc.jar, executed on macOS, Linux, and Solaris …

Fix: after 2020-04-06
Fix from $2,300 2020-04-06
Netbeans CRITICAL 9.1
CVE-2019-17560

The "Apache NetBeans" autoupdate system does not validate SSL certificates and hostnames for https based downloads. This allows an attacker to interc…

Fix: after 11.2
Fix from $2,300 2020-03-30
Emc Data Protection Central HIGH 7.5
CVE-2019-3762

Data Protection Central versions 1.0, 1.0.1, 18.1, 18.2, and 19.1 contains an Improper Certificate Chain of Trust Vulnerability. A remote unauthentic…

Mitigation only
Fix from $1,950 2020-03-18
Exfat Driver HIGH 7.4
CVE-2019-11688

An issue was discovered in ASUSTOR exFAT Driver through 1.0.0.r20. When conducting license validation, exfat.cgi and exfatctl accept any certificate …

No fix yet
Fix from $1,950 2020-03-18
Citrix Sd Wan Center MEDIUM 5.9
CVE-2020-6175

Citrix SD-WAN 10.2.x before 10.2.6 and 11.0.x before 11.0.3 has Missing SSL Certificate Validation.

Fix: 10.2.6 / 11.0.3+
Fix from $1,600 2020-03-16
Go HIGH 7.5
CVE-2020-7919

Go before 1.12.16 and 1.13.x before 1.13.7 (and the crypto/cryptobyte package before 0.0.0-20200124225646-8b5121be2f68 for Go) allows attacks on clie…

Fix: 1.12.6 / 1.13.7+
Fix from $1,950 2020-03-16
Traefik HIGH 7.5
CVE-2020-9321

configurationwatcher.go in Traefik 2.x before 2.1.4 and TraefikEE 2.0.0 mishandles the purging of certificate contents from providers before logging.

Fix: after 2.1.4
Fix from $1,950 2020-03-16
Geode HIGH 7.4
CVE-2019-10091

When TLS is enabled with ssl-endpoint-identification-enabled set to true, Apache Geode fails to perform hostname verification of the entries in the c…

Mitigation only
Fix from $1,950 2020-03-16
Osquery CRITICAL 9.1
CVE-2020-1887

Incorrect validation of the TLS SNI hostname in osquery versions after 2.9.0 and before 4.2.0 could allow an attacker to MITM osquery traffic in the …

Fix: 4.2.0+
Fix from $2,300 2020-03-13
Debian Linux MEDIUM 5.5
CVE-2012-1096

NetworkManager 0.9 and earlier allows local users to use other users' certificates or private keys when making a connection via the file path when ad…

Fix: after 0.9.0
Fix from $1,600 2020-03-10
Antitrack HIGH 7.4
CVE-2020-8987

Avast AntiTrack before 1.5.1.172 and AVG Antitrack before 2.0.0.178 proxies traffic to HTTPS sites but does not validate certificates, and thus a man…

Fix: 1.5.1.172 / 2.0.0.178+
Fix from $1,950 2020-03-09
Intelligence Proximity HIGH 7.4
CVE-2020-3155

A vulnerability in the SSL implementation of the Cisco Intelligent Proximity solution could allow an unauthenticated, remote attacker to view or alte…

Mitigation only
Fix from $1,950 2020-03-04
Lua Openssl CRITICAL 9.1
CVE-2020-9432

openssl_x509_check_host in lua-openssl 0.7.7-1 mishandles X.509 certificate validation because it uses lua_pushboolean for certain non-boolean return…

Patch available
Fix from $2,300 2020-02-27
Lua Openssl CRITICAL 9.1
CVE-2020-9433

openssl_x509_check_email in lua-openssl 0.7.7-1 mishandles X.509 certificate validation because it uses lua_pushboolean for certain non-boolean retur…

Patch available
Fix from $2,300 2020-02-27
Lua Openssl CRITICAL 9.1
CVE-2020-9434

openssl_x509_check_ip_asc in lua-openssl 0.7.7-1 mishandles X.509 certificate validation because it uses lua_pushboolean for certain non-boolean retu…

Patch available
Fix from $2,300 2020-02-27
Fedora MEDIUM 5.3
CVE-2020-7041

An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL 1.0.2 or later. tunnel.c mishandles certificate validation because an X509_chec…

Fix: 1.12.0+
Fix from $1,600 2020-02-27
Fedora MEDIUM 5.3
CVE-2020-7042

An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL 1.0.2 or later. tunnel.c mishandles certificate validation because the hostname…

Fix: 1.12.0+
Fix from $1,600 2020-02-27
Fedora CRITICAL 9.1
CVE-2020-7043

An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL before 1.0.2. tunnel.c mishandles certificate validation because hostname compa…

Fix: 1.12.0+
Fix from $2,300 2020-02-27
Puppet MEDIUM 6.5
CVE-2020-7942

Previously, Puppet operated on a model that a node with a valid certificate was entitled to all information in the system and that a compromised cert…

Fix: 5.5.19 / 6.13.0+
Fix from $1,600 2020-02-19
Php Sdk MEDIUM 5.9
CVE-2019-20455

Gateways/Gateway.php in Heartland & Global Payments PHP SDK before 2.0.0 does not enforce SSL certificate validations.

Fix: 2.0.0+
Fix from $1,600 2020-02-14
Node.js HIGH 7.5
CVE-2019-15604EPSS 20%

Improper Certificate Validation in Node.js 10, 12, and 13 causes the process to abort when sending a crafted X.509 certificate

Fix: 10.19.0 / 12.15.0+
Fix from $1,950 2020-02-07
Nomad CRITICAL 9.8
CVE-2020-7956

HashiCorp Nomad and Nomad Enterprise up to 0.10.2 incorrectly validated role/region associated with TLS certificates used for mTLS RPC, and were susc…

Fix: 0.10.3+
Fix from $2,300 2020-01-31
Apeosware Management Suite MEDIUM 5.9
CVE-2020-5526

The AWMS Mobile App for Android 2.0.0 to 2.0.5 and for iOS 2.0.0 to 2.0.8 does not verify X.509 certificates from servers, which allows man-in-the-mi…

Fix: after 2.0.8
Fix from $1,600 2020-01-31
Intellij Idea HIGH 7.4
CVE-2020-7904

In JetBrains IntelliJ IDEA before 2019.3, some Maven repositories were accessed via HTTP instead of HTTPS.

Fix: 2019.3.0+
Fix from $1,950 2020-01-30
\ MEDIUM 5.9
CVE-2014-3230

The libwww-perl LWP::Protocol::https module 6.04 through 6.06 for Perl, when using IO::Socket::SSL as the SSL socket class, allows attackers to disab…

Fix: after 6.06
Fix from $1,600 2020-01-28