Vulnerability index

Browse CVEs

1,344 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Certificate ValidationCWE-295 × clear
Unclassified HIGH 8.7
CVE-2026-47074

Improper Certificate Validation vulnerability in ex-aws ex_aws_sns (ExAws.SNS, ExAws.SNS.PublicKeyCache modules) allows Signature Spoofing by Imprope…

Patch available
Fix from $1,950 2026-05-28
Erlang\/otp HIGH 8.1
CVE-2026-42790

Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_cert and public_key modules) allows a DNS nameConstraints bypass via s…

Fix: 26.2.5.21 / 27.3.4.12+
Fix from $1,950 2026-05-27
Unclassified HIGH 8.1
CVE-2026-45574

epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. Prior to 1.2.2, an attacker on the network path between the e…

Patch available
Fix from $1,950 2026-05-26
Unclassified HIGH 8.2
CVE-2026-42013

A flaw was found in gnutls. When validating certificates, an oversized Subject Alternative Name (SAN) could cause the validation process to incorrect…

Mitigation only
Fix from $1,950 2026-05-26
Unclassified MEDIUM 6.5
CVE-2026-44213

The OpenTelemetry.Exporter.Instana exports telemetry to Instana backend. Prior to 1.1.0, the OpenTelemetry.Exporter.Instana NuGet package does not va…

Mitigation only
Fix from $1,600 2026-05-26
Unclassified HIGH 8.1
CVE-2026-44900

epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. Prior to 1.2.1, in SignedPublicKeysTrustValidatorImpl.isTrus…

Patch available
Fix from $1,950 2026-05-26
Unclassified HIGH 7.1
CVE-2026-42012

A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted certificate that contains Uniform Re…

Mitigation only
Fix from $1,950 2026-05-26
Fastnetmon HIGH 7.4
CVE-2026-48697

FastNetMon Community Edition through 1.2.9 does not verify TLS certificates on outbound HTTPS connections. The execute_web_request_secure() function …

Fix: after 1.2.9
Fix from $1,950 2026-05-26
Unclassified CRITICAL 9.3
CVE-2026-9058

For untrusted certificates that contain the "Authority Information Access - caIssuers URI" extension, Szafir SDK will automatically download the pare…

Mitigation only
Fix from $2,300 2026-05-25
Sunshine CRITICAL 9.8
CVE-2026-32253

Sunshine is a self-hosted game stream host for Moonlight. In versions prior to 2026.516.143833, the client-certificate authentication can be bypassed…

Fix: 2026.516.143833+
Fix from $2,300 2026-05-22
Secure Access Client HIGH 8.8
CVE-2026-8992

An improper certificate validation vulnerability in Ivanti Secure Access Client before 22.8R6 allows a remote unauthenticated attacker to execute arb…

Fix: after 22.7
Fix from $1,950 2026-05-22
Powerflex Appliance Intelligent Catalog MEDIUM 6.5
CVE-2025-32745

Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent ne…

Fix: 3.7.8.0 / 48.383.00+
Fix from $1,600 2026-05-22
Crypto CRITICAL 9.1
CVE-2026-42508

Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now, both the 'key' and 'key.SignatureKey' are check…

Fix: 0.52.0+
Fix from $2,300 2026-05-22
Crypto MEDIUM 5.3
CVE-2026-39835

SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be caused to panic by a client pr…

Fix: 0.52.0+
Fix from $1,600 2026-05-22
Crypto MEDIUM 6.3
CVE-2026-39828

When an SSH server authentication callback returned PartialSuccessError with non-nil Permissions, those permissions were silently discarded, potentia…

Fix: 0.52.0+
Fix from $1,600 2026-05-22
Unclassified MEDIUM 5.9
CVE-2026-48248

Open ISES Tickets before 3.44.2 disables TLS certificate verification in incs/login.inc.php by setting CURLOPT_SSL_VERIFYPEER to false (and not setti…

Patch available
Fix from $1,600 2026-05-21
Unclassified MEDIUM 5.9
CVE-2026-48249

Open ISES Tickets before 3.44.2 disables TLS certificate verification in rm/incs/mobile_login.inc.php by setting CURLOPT_SSL_VERIFYPEER to false (and…

Patch available
Fix from $1,600 2026-05-21
Unclassified MEDIUM 5.9
CVE-2026-48246

Open ISES Tickets before 3.44.2 disables TLS certificate verification in ajax/reports.php by setting CURLOPT_SSL_VERIFYPEER to false (and not setting…

Patch available
Fix from $1,600 2026-05-21
Unclassified MEDIUM 5.9
CVE-2026-48247

Open ISES Tickets before 3.44.2 disables TLS certificate verification in incs/functions.inc.php by setting CURLOPT_SSL_VERIFYPEER to false (and not s…

Patch available
Fix from $1,600 2026-05-21
Unclassified MEDIUM 6.8
CVE-2026-41119

Dell Live Optics Windows and Personal Edition collectors contain an improper certificate validation vulnerability. A remote unauthenticated attacker …

Mitigation only
Fix from $1,600 2026-05-18
Unclassified MEDIUM 5.3
CVE-2026-44309

Gitsign is a keyless Sigstore to signing tool for Git commits with your a GitHub / OIDC identity. Prior to 0.16.0, gitsign verify and gitsign verify-…

Mitigation only
Fix from $1,600 2026-05-15
Unclassified HIGH 8.7
CVE-2026-44700

Elixir WebRTC is an Elixir implementation of the W3C WebRTC API. Prior to 0.15.1 and 0.16.1, missing DTLS peer certificate fingerprint validation in …

Patch available
Fix from $1,950 2026-05-14
Fleet HIGH 7.5
CVE-2026-23998

Fleet is open source device management software. Prior to version 4.81.0, a vulnerability in Fleet’s Windows MDM management endpoint could allow requ…

Fix: 4.81.0+
Fix from $1,950 2026-05-14
Unclassified MEDIUM 5.8
CVE-2026-44312

css_parser is a Ruby CSS parser. Prior to 2.1.0 and 1.22.0, the CSS Parser gem does not validate HTTPS connections, allowing a Man-in-the-Middle (MIT…

Patch available
Fix from $1,600 2026-05-14
Wp Squared HIGH 8.2
CVE-2026-32992

SSL verification is disabled in the DNS Cluster system. This could allow for a malicious server to man-in-the-middle the request and capture credenti…

Fix: 126.0.59 / 130.0.23+
Fix from $1,950 2026-05-13
Unclassified MEDIUM 5.8
CVE-2026-44363

MISP modules are autonomous modules that can be used to extend MISP for new services. Prior to 3.0.7, an unsafe remote resource fetching vulnerabilit…

Patch available
Fix from $1,600 2026-05-13
Ckan HIGH 7.4
CVE-2026-41132

CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Prior to 2.10.10 and 2.11.5, the configured SMTP server …

Fix: 2.10.10 / 2.11.5+
Fix from $1,950 2026-05-13
Globalprotect MEDIUM 6.5
CVE-2026-0249

Multiple improper certificate validation vulnerabilities in the Palo Alto Networks GlobalProtect™ app enables an attacker to intercept encrypted comm…

Fix: 6.0.13 / 6.0.14+
Fix from $1,600 2026-05-13
Prisma Sd Wan HIGH 8.1
CVE-2026-0244

An improper certificate validation vulnerability in the Palo Alto Networks Prisma SD-WAN ION enables man-in-the-middle (MitM) attacker to impersonate…

Fix: 6.3.6 / 6.4.3+
Fix from $1,950 2026-05-13
Prisma Access Agent MEDIUM 5.9
CVE-2026-0248

An improper certificate validation vulnerability in the Prisma Access Agent® for Android and Chrome OS enables an attacker to perform a man-in-the-mi…

Fix: 26.2.1+
Fix from $1,600 2026-05-13