Vulnerability index

Browse CVEs

1,344 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Certificate ValidationCWE-295 × clear
Unclassified HIGH 7.5
CVE-2025-10495

A potential vulnerability was reported in the Lenovo PC Manager, Lenovo App Store, Lenovo Browser, and Lenovo Legion Zone client applications that, u…

Mitigation only
Fix from $1,950 2025-11-12
Unclassified HIGH 7.5
CVE-2025-40744

A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 11). Affected applications do not properly validate client cer…

Mitigation only
Fix from $1,950 2025-11-11
Rax30 Firmware HIGH 7.5
CVE-2025-12943

Improper certificate validation in firmware update logic in NETGEAR RAX30 (Nighthawk AX5 5-Stream AX2400 WiFi 6 Router) and RAXE300 (Nighthawk AXE780…

Fix: 1.0.9.82 / 1.0.14.108+
Fix from $1,950 2025-11-11
Youtrack HIGH 7.5
CVE-2025-64685

In JetBrains YouTrack before 2025.3.104432 missing TLS certificate validation enabled data disclosure

Fix: 2025.3.104432+
Fix from $1,950 2025-11-10
Internet Download Manager CRITICAL 9.1
CVE-2025-56231

Tonec Internet Download Manager 6.42.41.1 and earlier suffers from Missing SSL Certificate Validation, which allows attackers to bypass update protec…

Fix: after 6.42.41.1
Fix from $2,300 2025-11-05
Unclassified HIGH 8.6
CVE-2025-54470

This vulnerability affects NeuVector deployments only when the Report anonymous cluster data option is enabled. When this option is enabled, NeuVecto…

Mitigation only
Fix from $1,950 2025-10-30
Go HIGH 7.5
CVE-2025-58188

Validating certificate chains which contain DSA public keys can cause programs to panic, due to a interface cast that assumes they implement the Equa…

Fix: 1.24.8 / 1.25.2+
Fix from $1,950 2025-10-29
Unclassified MEDIUM 6.9
CVE-2025-62375

go-witness and witness are Go modules for generating attestations. In go-witness versions 0.8.6 and earlier and witness versions 0.9.2 and earlier th…

Patch available
Fix from $1,600 2025-10-15
Devolutions Server HIGH 8.8
CVE-2025-11619

Improper certificate validation when connecting to gateways in Devolutions Server 2025.3.2 and earlier allows attackers in MitM position to intercept…

Fix: 2025.2.15.0 / 2025.3.3.0+
Fix from $1,950 2025-10-15
Opensearch Data Prepper HIGH 7.4
CVE-2025-62371

OpenSearch Data Prepper as an open source data collector for observability data. In versions prior to 2.12.2, the OpenSearch sink and source plugins …

Fix: 2.12.2+
Fix from $1,950 2025-10-15
Unclassified MEDIUM 5.3
CVE-2025-10699

A vulnerability was reported in the Lenovo LeCloud client application that, under certain conditions, could allow information disclosure.

No fix yet
Fix from $1,600 2025-10-15
Rust Driver HIGH 7.5
CVE-2025-11695

When tlsInsecure=False appears in a connection string, certificate validation is disabled. This vulnerability affects MongoDB Rust Driver versions p…

Fix: 3.2.5+
Fix from $1,950 2025-10-13
Furbo Mini Firmware MEDIUM 5.9
CVE-2025-11633

A vulnerability was identified in Tomofun Furbo 360 and Furbo Mini. Affected by this issue is the function upload_file_to_s3 of the file collect_logs…

Fix: after 074
Fix from $1,600 2025-10-12
Unclassified CRITICAL 9.3
CVE-2025-61778

Akka.NET is a .NET port of the Akka project from the Scala / Java community. In all versions of Akka.Remote from v1.2.0 to v1.5.51, TLS could be enab…

Patch available
Fix from $2,300 2025-10-06
Virtual Appliance Application HIGH 7.8
CVE-2025-34235

Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.1.102 and Application prior to version 25.1.1413 (Windows client depl…

Fix: 25.1.102 / 25.1.1413+
Fix from $1,950 2025-09-29
Unclassified MEDIUM 6.5
CVE-2025-10548

The CleverControl employee monitoring software (v11.5.1041.6) fails to validate TLS server certificates during the installation process. The installe…

Mitigation only
Fix from $1,600 2025-09-23
Virtual Appliance Application HIGH 8.1
CVE-2025-34199

Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22.0.1049 and Application versions prior to 20.0.2786 (VA and SaaS depl…

Fix: 20.0.2786 / 22.0.1049+
Fix from $1,950 2025-09-19
Unclassified CRITICAL 9.3
CVE-2024-13990

MicroWorld eScan AV's update mechanism failed to ensure authenticity and integrity of updates: update packages were delivered and accepted without ro…

Mitigation only
Fix from $2,300 2025-09-19
Dragonfly HIGH 7.5
CVE-2025-59353

Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, a peer can obtain a valid TLS certificate for …

Fix: 2.1.0+
Fix from $1,950 2025-09-17
Dragonfly MEDIUM 6.5
CVE-2025-59347

Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, The Manager disables TLS certificate verificat…

Fix: 2.1.0+
Fix from $1,600 2025-09-17
Thorium CRITICAL 9.8
CVE-2025-35434

CISA Thorium does not validate TLS certificates when connecting to Elasticsearch. An unauthenticated attacker with access to a Thorium cluster could …

Fix: 1.1.2+
Fix from $2,300 2025-09-17
Unclassified MEDIUM 6.8
CVE-2025-9708

A vulnerability exists in the Kubernetes C# client where the certificate validation logic accepts properly constructed certificates from any Certific…

Mitigation only
Fix from $1,600 2025-09-16
Control M\/agent CRITICAL 9.0
CVE-2025-55109

An authentication bypass vulnerability exists in the out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 and potentially earlier unsupported ver…

Fix: after 9.0.22
Fix from $2,300 2025-09-16
Eagleeyes\(lite\) HIGH 8.8
CVE-2025-50944

An issue was discovered in the method push.lite.avtech.com.MySSLSocketFactoryNew.checkServerTrusted in AVTECH EagleEyes 2.0.0. The custom X509TrustMa…

No fix yet
Fix from $1,950 2025-09-15
Unclassified HIGH 7.7
CVE-2025-9785

PaperCut Print Deploy is an optional component that integrates with PaperCut NG/MF which simplifies printer deployment and management. When the compo…

Mitigation only
Fix from $1,950 2025-09-03
Concert MEDIUM 5.9
CVE-2025-33099

IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to perform unauthorized actions using man in the middle techniques due to impr…

Fix: 2.0.0+
Fix from $1,600 2025-09-01
Qsync Central HIGH 8.8
CVE-2025-30277

An improper certificate validation vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then …

Fix: 4.5.0.7+
Fix from $1,950 2025-08-29
Qsync Central HIGH 8.8
CVE-2025-30278

An improper certificate validation vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then …

Fix: 4.5.0.7+
Fix from $1,950 2025-08-29
Unclassified CRITICAL 9.1
CVE-2025-7390

A malicious client can bypass the client certificate trust check of an opc.https server when the server endpoint is configured to allow only secure c…

Mitigation only
Fix from $2,300 2025-08-21
Websphere Application Server HIGH 7.5
CVE-2025-33142

IBM WebSphere Application Server 8.5 and 9.0 could provide weaker than expected security for TLS connections.

Fix: 8.5.5.29 / 9.0.5.25+
Fix from $1,950 2025-08-14