Vulnerability index

Browse CVEs

1,344 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Certificate ValidationCWE-295 × clear
Unclassified HIGH 8.1
CVE-2026-1530

A flaw was found in fog-kubevirt. This vulnerability allows a remote attacker to perform a Man-in-the-Middle (MITM) attack due to disabled certificat…

Mitigation only
Fix from $1,950 2026-02-02
Unclassified HIGH 8.1
CVE-2026-1531

A flaw was found in foreman_kubevirt. When configuring the connection to OpenShift, the system disables SSL verification if a Certificate Authority (…

Mitigation only
Fix from $1,950 2026-02-02
Rbr20 Firmware HIGH 7.7
CVE-2022-40620

FunJSQ, a third-party module integrated on some NETGEAR routers and Orbi WiFi Systems, does not properly validate TLS certificates when downloading u…

Fix: 1.0.5.42 / 1.0.11.134+
Fix from $1,950 2026-01-28
Unclassified CRITICAL 9.3
CVE-2026-22696

dcap-qvl implements the quote verification logic for DCAP (Data Center Attestation Primitives). A vulnerability present in versions prior to 0.3.9 in…

Mitigation only
Fix from $2,300 2026-01-26
Builder CRITICAL 9.8
CVE-2025-67229

An improper certificate validation vulnerability exists in ToDesktop Builder v0.32.1 This vulnerability allows an unauthenticated, on-path attacker t…

Fix: 0.32.1+
Fix from $2,300 2026-01-23
Unclassified MEDIUM 6.5
CVE-2025-32057

The Infotainment ECU manufactured by Bosch which is installed in Nissan Leaf ZE1 – 2020 uses a Redbend service for over-the-air provisioning and upda…

Mitigation only
Fix from $1,600 2026-01-22
Designer MEDIUM 5.3
CVE-2025-27377

Altium Designer version 24.9.0 does not validate self-signed server certificates for cloud connections. An attacker capable of performing a man-in-th…

Fix: 25.2.0+
Fix from $1,600 2026-01-22
Graalvm HIGH 7.5
CVE-2026-21945

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supp…

Mitigation only
Fix from $1,950 2026-01-20
Unclassified HIGH 7.4
CVE-2025-11043

An Improper Certificate Validation vulnerability in the OPC-UA client and ANSL over TLS client used in Automation Studio versions before 6.5 could al…

Mitigation only
Fix from $1,950 2026-01-19
Wlc MEDIUM 5.5
CVE-2026-22250

wlc is a Weblate command-line client using Weblate's REST API. Prior to 1.17.0, the SSL verification would be skipped for some crafted URLs. This vul…

Fix: 1.17.0+
Fix from $1,600 2026-01-12
Botmanager CRITICAL 9.8
CVE-2025-46070

An issue in Automai BotManager v.25.2.0 allows a remote attacker to execute arbitrary code via the BotManager.exe component

Mitigation only
Fix from $2,300 2026-01-12
Errands HIGH 7.5
CVE-2025-71063

Errands before 46.2.10 does not verify TLS certificates for CalDAV servers.

Fix: 46.2.10+
Fix from $1,950 2026-01-12
Unclassified HIGH 8.8
CVE-2025-66001

NeuVector supports login authentication through OpenID Connect. However, the TLS verification (which verifies the remote server's authenticity and in…

Mitigation only
Fix from $1,950 2026-01-08
Curl MEDIUM 5.3
CVE-2025-14819

When doing TLS related transfers with reused easy or multi handles and altering the `CURLSSLOPT_NO_PARTIALCHAIN` option, libcurl could accidentally …

Fix: 8.18.0+
Fix from $1,600 2026-01-08
Curl MEDIUM 5.9
CVE-2025-13034

When using `CURLOPT_PINNEDPUBLICKEY` option with libcurl or `--pinnedpubkey` with the curl tool,curl should check the public key of the server certif…

Fix: 8.18.0+
Fix from $1,600 2026-01-08
Line MEDIUM 6.8
CVE-2025-14022

LINE client for iOS prior to 15.4 allows man-in-the-middle attacks due to improper SSL/TLS certificate validation in an integrated financial SDK. The…

Fix: 15.4.0+
Fix from $1,600 2025-12-15
Data Master MEDIUM 5.9
CVE-2025-13052

When the user set the Notification's sender to send emails to the SMTP server via msmtp, an improper validated TLS/SSL certificates allows an attacke…

Fix: 4.3.3.ROF1 / 5.1.1.RCI1+
Fix from $1,600 2025-12-12
Hub M2 Firmware HIGH 7.4
CVE-2025-65290

Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 fail to validate server certificates during HTTPS firm…

No fix yet
Fix from $1,950 2025-12-10
Hub M2 Firmware HIGH 7.4
CVE-2025-65291

Aqara Hub devices including Hub M2 4.3.6_0027, Hub M3 4.3.6_0025, Camera Hub G3 4.1.9_0027 fail to validate server certificates in TLS connections fo…

No fix yet
Fix from $1,950 2025-12-10
Meatmeet CRITICAL 9.1
CVE-2025-65830

Due to a lack of certificate validation, all traffic from the mobile application can be intercepted. As a result, an adversary located "upstream" can…

Mitigation only
Fix from $2,300 2025-12-10
Unclassified HIGH 7.4
CVE-2025-40800

A vulnerability has been identified in COMOS V10.6 (All versions < V10.6.1), COMOS V10.6 (All versions < V10.6.1), NX V2412 (All versions < V2412.870…

Mitigation only
Fix from $1,950 2025-12-09
Unclassified HIGH 8.1
CVE-2025-40801

A vulnerability has been identified in COMOS V10.6 (All versions < V10.6.1), COMOS V10.6 (All versions < V10.6.1), JT Bi-Directional Translator for S…

Mitigation only
Fix from $1,950 2025-12-09
Traefik MEDIUM 5.9
CVE-2025-66491

Traefik is an HTTP reverse proxy and load balancer. Versions 3.5.0 through 3.6.2 have inverted TLS verification logic in the nginx.ingress.kubernetes…

Fix: 3.6.3+
Fix from $1,600 2025-12-09
Go MEDIUM 6.5
CVE-2025-61727

An excluded subdomain constraint in a certificate chain does not restrict the usage of wildcard SANs in the leaf certificate. For example a constrain…

Fix: 1.24.11 / 1.25.5+
Fix from $1,600 2025-12-03
Go HIGH 7.5
CVE-2025-61729

Within HostnameError.Error(), when constructing an error string, there is no limit to the number of hosts that will be printed out. Furthermore, the …

Fix: 1.24.11 / 1.25.5+
Fix from $1,950 2025-12-02
MongoDB MEDIUM 5.4
CVE-2025-12893

Clients may successfully perform a TLS handshake with a MongoDB server despite presenting a client certificate not aligning with the documented Exten…

Fix: 7.0.26 / 8.0.16+
Fix from $1,600 2025-11-25
Unclassified HIGH 8.3
CVE-2025-44018

A firmware downgrade vulnerability exists in the OTA Update functionality of GL-Inet GL-AXT1800 4.7.0. A specially crafted .tar file can lead to a fi…

Mitigation only
Fix from $1,950 2025-11-24
Meeting Software Development Kit MEDIUM 6.5
CVE-2025-30669

Improper certificate validation in certain Zoom Clients may allow an unauthenticated user to conduct a disclosure of information via adjacent access.

Fix: 6.3.14 / 6.4.12+
Fix from $1,600 2025-11-13
Pgadmin 4 HIGH 7.4
CVE-2025-12765

pgAdmin <= 9.9  is affected by a vulnerability in the LDAP authentication mechanism allows bypassing TLS certificate verification.

Fix: 9.10+
Fix from $1,950 2025-11-13
Unclassified MEDIUM 5.3
CVE-2025-12047

A vulnerability was reported in the Lenovo Scanner pro application during an internal security assessment that, under certain circumstances, could al…

Mitigation only
Fix from $1,600 2025-11-12