Vulnerability index

Browse CVEs

1,344 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Certificate ValidationCWE-295 × clear
Go HIGH 7.5
CVE-2026-32281

Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a very large number of policy map…

Fix: 1.25.9 / 1.26.2+
Fix from $1,950 2026-04-08
Go HIGH 8.2
CVE-2026-33810

When verifying a certificate chain containing excluded DNS constraints, these constraints are not correctly applied to wildcard DNS SANs which use a …

Fix: 1.26.2+
Fix from $1,950 2026-04-08
Botan HIGH 7.5
CVE-2026-34580

Botan is a C++ cryptography library. In 3.11.0, the function Certificate_Store::certificate_known had a misleading name; it would return true if any …

Mitigation only
Fix from $1,950 2026-04-07
Advanced Cluster Management For Kubernetes HIGH 8.2
CVE-2026-4740

A flaw was found in Open Cluster Management (OCM), the technology underlying Red Hat Advanced Cluster Management (ACM). Improper validation of Kubern…

No fix yet
Fix from $1,950 2026-04-07
Erlang\/otp HIGH 7.4
CVE-2026-32144

Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_ocsp module) allows OCSP designated-responder authorization bypass via…

Fix: 1.17.1.2 / 1.20.3+
Fix from $1,950 2026-04-07
Webmail HIGH 7.5
CVE-2026-35389

Bulwark Webmail is a self-hosted webmail client for Stalwart Mail Server. Prior to 1.4.11, S/MIME signature verification did not validate the certifi…

Fix: 1.4.11+
Fix from $1,950 2026-04-06
Athena Odbc MEDIUM 5.9
CVE-2026-35560

Improper certificate validation in the identity provider connection components in Amazon Athena ODBC driver before 2.1.0.0 might allow a man-in-the-m…

Fix: 2.1.0.0+
Fix from $1,600 2026-04-03
Secure Email Gateway MEDIUM 5.3
CVE-2026-29140

SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to cause attacker-controlled certificates to be used for future encryption to …

Fix: 15.0.3+
Fix from $1,600 2026-04-02
Mbed Tls MEDIUM 6.5
CVE-2026-25834

Mbed TLS v3.3.0 up to 3.6.5 and 4.0.0 allows Algorithm Downgrade.

Fix: 3.6.6+
Fix from $1,600 2026-04-01
Nexus Dashboard MEDIUM 6.5
CVE-2026-20042

A vulnerability in the configuration backup feature of Cisco Nexus Dashboard could allow an attacker who has the encryption password and access to Fu…

Fix: 4.2.1+
Fix from $1,600 2026-04-01
Juju CRITICAL 10.0
CVE-2026-4370

A vulnerability was identified in Juju from version 3.2.0 until 3.6.19 and from version 4.0 until 4.0.4, where the internal Dqlite database cluster f…

Fix: 3.6.20 / 4.0.5+
Fix from $2,300 2026-04-01
Cryptography MEDIUM 5.3
CVE-2026-34073

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to version 46.0.6, DNS name constraints…

Fix: 46.0.6+
Fix from $1,600 2026-03-31
Botan MEDIUM 5.9
CVE-2026-32884

Botan is a C++ cryptography library. Prior to version 3.11.0, during processing of an X.509 certificate path using name constraints which restrict th…

Fix: 3.11.0+
Fix from $1,600 2026-03-30
Unclassified HIGH 7.5
CVE-2019-25652

UniFi Network Controller before version 5.10.22 and 5.11.x before 5.11.18 contains an improper certificate verification vulnerability that allows adj…

Mitigation only
Fix from $1,950 2026-03-27
Forge CRITICAL 9.1
CVE-2026-33896

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, `pki.verifyCertificate…

Fix: after 1.3.3
Fix from $2,300 2026-03-27
Wazuh HIGH 8.1
CVE-2025-15612

Wazuh provisioning scripts and Dockerfiles contain an insecure transport vulnerability where curl is invoked with the -k/--insecure flag, disabling S…

Fix: 4.14.0+
Fix from $1,950 2026-03-27
Mod Gnutls MEDIUM 5.9
CVE-2026-33308

Mod_gnutls is a TLS module for Apache HTTPD based on GnuTLS. Prior to version 0.13.0, code for client certificate verification did not check the key …

Fix: 0.13.0+
Fix from $1,600 2026-03-24
Devolutions Server HIGH 8.1
CVE-2026-4434

Improper certificate validation in the PAM propagation WinRM connections allows a network attacker to perform a man-in-the-middle attack via disabl…

Fix: 2026.1.6.0+
Fix from $1,950 2026-03-20
Step Ca CRITICAL 10.0
CVE-2026-30836

Step CA is an online certificate authority for secure, automated certificate management for DevOps. Versions 0.30.0-rc6 and below do not safeguard ag…

Fix: 0.30.0+
Fix from $2,300 2026-03-19
Hub Reporting Service HIGH 8.1
CVE-2026-4396

Improper certificate validation in Devolutions Hub Reporting Service 2025.3.1.1 and earlier allows a network attacker to perform a man-in-the-middl…

Fix: 2026.1.1.0+
Fix from $1,950 2026-03-18
Cpp Httplib HIGH 8.1
CVE-2026-32627

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.37.2, when a cpp-httplib client is configured with a pro…

Fix: 0.37.2+
Fix from $1,950 2026-03-16
Jumpserver MEDIUM 5.0
CVE-2026-31798

JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to v4.10.16-lts, JumpServer improperly valida…

Fix: 4.10.16+
Fix from $1,600 2026-03-13
Unclassified HIGH 7.1
CVE-2026-2368

An improper certificate validation vulnerability was reported in the Lenovo Filez application that could allow a user capable of intercepting network…

Mitigation only
Fix from $1,950 2026-03-11
Unclassified MEDIUM 5.3
CVE-2026-1068

An improper certificate validation vulnerability was reported in the Lenovo Filez application that could allow a user capable of intercepting network…

Mitigation only
Fix from $1,600 2026-03-11
Alienware Command Center MEDIUM 5.5
CVE-2026-24508

Dell Alienware Command Center (AWCC), versions prior to 6.12.24.0, contain an Improper Certificate Validation vulnerability. A low privileged attacke…

Fix: 6.12.24.0+
Fix from $1,600 2026-03-11
Video Station MEDIUM 6.7
CVE-2024-14024

An improper certificate validation vulnerability has been reported to affect Video Station. If an attacker gains local network access who have also g…

Fix: 5.8.2+
Fix from $1,600 2026-03-11
Acrobat Dc MEDIUM 5.5
CVE-2026-27221

Acrobat Reader versions 24.001.30307, 24.001.30308, 25.001.21265 and earlier are affected by an Improper Certificate Validation vulnerability that co…

Fix: 24.001.30356 / 25.001.21288+
Fix from $1,600 2026-03-10
Fortimanager MEDIUM 5.9
CVE-2025-68482

A improper certificate validation vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.8, FortiAnalyzer 7.2 a…

Fix: 7.4.9 / 7.6.5+
Fix from $1,600 2026-03-10
Zookeeper HIGH 7.4
CVE-2026-24281

Hostname verification in Apache ZooKeeper ZKTrustManager falls back to reverse DNS (PTR) when IP SAN validation fails, allowing attackers who control…

Fix: 3.8.6 / 3.9.5+
Fix from $1,950 2026-03-07
Wallos HIGH 8.8
CVE-2026-30840

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, there is a server-side request forgery vulnerability i…

Fix: 4.6.2+
Fix from $1,950 2026-03-07