Vulnerability index

Browse CVEs

1,344 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Certificate ValidationCWE-295 × clear
Curl MEDIUM 5.3
CVE-2026-7009

When curl is told to use the Certificate Status Request TLS extension, often referred to as *OCSP stapling*, to verify that the server certificate is…

Fix: 8.20.0+
Fix from $1,600 2026-05-13
Curl MEDIUM 5.9
CVE-2026-4873

A vulnerability exists where a connection requiring TLS incorrectly reuses an existing unencrypted connection from the same connection pool. If an in…

Fix: 8.20.0+
Fix from $1,600 2026-05-13
Unclassified MEDIUM 6.8
CVE-2026-44305

Lemur manages TLS certificate creation. Prior to 1.9.0, when LDAP TLS is enabled (LDAP_USE_TLS = True), Lemur's LDAP authentication module unconditio…

Mitigation only
Fix from $1,600 2026-05-12
Unclassified HIGH 7.4
CVE-2026-41872

"Kura Sushi Official App" provided by EPG, Inc. is vulnerable to improper certificate validation. A man-in-the-middle attack may allow eavesdropping …

Mitigation only
Fix from $1,950 2026-05-12
Pyload Ng MEDIUM 6.8
CVE-2026-42312

pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the set_config_value() API method (@permission(Perms.SE…

Fix: 0.5.0b3.dev100+
Fix from $1,600 2026-05-11
Unclassified MEDIUM 5.1
CVE-2026-42213

SolidCAM-GPPL-IDE is an unofficial, independently developed extension, Postprocessor IDE for SolidCAM. From version 1.0.0 to before version 1.0.2, th…

Patch available
Fix from $1,600 2026-05-08
Pjsip MEDIUM 5.9
CVE-2026-42225

PJSIP is a free and open source multimedia communication library written in C. Prior to version 2.17, on GnuTLS builds, the SIP TLS transport (sip_tr…

Fix: 2.17+
Fix from $1,600 2026-05-07
Endpoint Manager Mobile CRITICAL 9.1
CVE-2026-7821

Improper certificate validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to enroll a …

Fix: 12.6.1.1+
Fix from $2,300 2026-05-07
Endpoint Manager Mobile CRITICAL 9.1
CVE-2026-5787

An Improper Certificate Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to impers…

Fix: 12.6.1.1+
Fix from $2,300 2026-05-07
Unclassified HIGH 7.4
CVE-2026-42011

A flaw was found in gnutls. This vulnerability occurs because permitted name constraints were incorrectly ignored when previous Certificate Authoriti…

Mitigation only
Fix from $1,950 2026-05-07
Vert.x MEDIUM 5.3
CVE-2026-6860

A TCP client can perform a TLS handshake and present the server name extension with a server name that is accepted by a server wildcard name, e.g. if…

Fix: after 5.0.11
Fix from $1,600 2026-05-06
Unclassified MEDIUM 6.5
CVE-2025-42611

RouterOS provides various services that rely on correct verification of client and server certificates to secure confidentiality and integrity of com…

Mitigation only
Fix from $1,600 2026-05-05
Thrift HIGH 7.3
CVE-2026-43869

Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are re…

Fix: 0.23.0+
Fix from $1,950 2026-05-05
Airflow MEDIUM 5.9
CVE-2026-41016

Apache Airflow's SMTP provider `SmtpHook` called Python's `smtplib.SMTP.starttls()` without an SSL context, so no certificate validation was performe…

Fix: 3.0.0+
Fix from $1,600 2026-04-30
Thrift HIGH 7.4
CVE-2026-41603

Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are re…

Fix: 0.23.0+
Fix from $1,950 2026-04-28
Spring Boot CRITICAL 9.8
CVE-2026-40974

Spring Boot's Cassandra auto-configuration does not perform hostname verification when establishing an SSL connection to Cassandra. Affected: Spring…

Fix: 2.7.33 / 3.3.19+
Fix from $2,300 2026-04-28
Spring Boot CRITICAL 9.1
CVE-2026-40971

When configured to use an SSL bundle, Spring Boot's RabbitMQ auto-configuration does not perform hostname verification when connecting to the RabbitM…

Fix: 3.5.14 / 4.0.6+
Fix from $2,300 2026-04-27
Spring Boot MEDIUM 6.8
CVE-2026-40970

When configured to use an SSL bundle, Spring Boot's Elasticsearch auto-configuration does not perform hostname verification when connecting to the El…

Fix: 4.0.6+
Fix from $1,600 2026-04-27
Spring Security HIGH 8.1
CVE-2026-22747

Vulnerability in Spring Spring Security. SubjectX500PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which…

Fix: 7.0.5+
Fix from $1,950 2026-04-22
Unclassified MEDIUM 6.9
CVE-2026-40944

Oxia is a metadata store and coordination system. Prior to 0.16.2, the trustedCertPool() function in the TLS configuration only parses the first PEM …

Mitigation only
Fix from $1,600 2026-04-21
Powerprotect Dp Series Appliance HIGH 8.8
CVE-2026-23776

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.…

Fix: 2.7.9 / 7.13.1.70+
Fix from $1,950 2026-04-17
Unclassified CRITICAL 9.8
CVE-2026-20184

A vulnerability in the integration of single sign-on (SSO) with Control Hub in Cisco Webex Services could have allowed an unauthenticated, remote att…

Mitigation only
Fix from $2,300 2026-04-15
Sigstore Timestamp Authority MEDIUM 5.5
CVE-2026-39984

Sigstore Timestamp Authority is a service for issuing RFC 3161 timestamps. Versions 2.0.5 and below contain an authorization bypass vulnerability in …

Fix: 2.0.6+
Fix from $1,600 2026-04-15
Autonomous Digital Experience Manager HIGH 8.8
CVE-2026-0233

A certificate validation vulnerability in Palo Alto Networks Autonomous Digital Experience Manager on Windows allows an unauthenticated attacker with…

Fix: 5.10.14+
Fix from $1,950 2026-04-13
Log4j MEDIUM 5.9
CVE-2026-34477

The fix for CVE-2025-68161 https://logging.apache.org/security.html#CVE-2025-68161 was incomplete: it addressed hostname verification only when ena…

Fix: 2.25.4+
Fix from $1,600 2026-04-10
Wolfssl HIGH 8.1
CVE-2026-5501

wolfSSL_X509_verify_cert in the OpenSSL compatibility layer accepts a certificate chain in which the leaf's signature is not checked, if the attacker…

Fix: after 5.9.0
Fix from $1,950 2026-04-10
Wolfssl MEDIUM 6.5
CVE-2026-5263

URI nameConstraints from constrained intermediate CAs are parsed but not enforced during certificate chain verification in wolfcrypt/src/asn.c. A com…

Fix: 5.9.1+
Fix from $1,600 2026-04-09
Wolfssl CRITICAL 9.1
CVE-2026-5194

Missing hash/digest size and OID checks allow digests smaller than allowed when verifying ECDSA certificates, or smaller than is appropriate for the …

Fix: 5.9.1+
Fix from $2,300 2026-04-09
Unclassified MEDIUM 5.4
CVE-2026-35207

dde-control-center is the control panel of DDE, the Deepin Desktop Environment. plugin-deepinid is a plugin in dde-control-center, which provides the…

Patch available
Fix from $1,600 2026-04-09
Rfc3161 Client HIGH 7.5
CVE-2026-33753

rfc3161-client is a Python library implementing the Time-Stamp Protocol (TSP) described in RFC 3161. Prior to 1.0.6, an Authorization Bypass vulnerab…

Fix: 1.0.6+
Fix from $1,950 2026-04-08