Vulnerability index

Browse CVEs

1,344 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Certificate ValidationCWE-295 × clear
MEDIUM 5.1 CVE-2026-63336 The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.0, com.rabbitmq… Fix unknown Fix from $4,0002026-08-18 CRITICAL 9.1 CVE-2026-52723 ePA 3.x Integration implements the authorization workflow and writes Medical Information Objects to Germany's electronic patient record. Prior to 1.3… Fix unknown Fix from $5,7502026-08-18 HIGH 7.5 CVE-2026-50578 ePA 3.x Integration implements the authorization workflow and writes Medical Information Objects to Germany's electronic patient record. Prior to 1.3… Fix unknown Fix from $4,9002026-08-18 HIGH 7.4 CVE-2026-59825 Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.19 and from 4.5.0 until 4.5.12, Mastodon's app/models/concer… Fix unknown Fix from $4,9002026-08-18 CRITICAL 9.1 CVE-2026-66795 A flaw was found in the managedcluster-import-controller. The Certificate Signing Request (CSR) auto-approval logic improperly validates incoming CSR… Fix unknown Fix from $5,7502026-08-17 CRITICAL 9.1 CVE-2026-49457 erlang_quic is a pure Erlang QUIC implementation. Prior to version 1.4.4, the QUIC client did not authenticate the server during the TLS 1.3 handshak… No fix yet Fix from $5,7502026-08-14 HIGH 7.5 CVE-2026-54481 Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override (CWE-295) No fix yet Fix from $4,9002026-08-13 HIGH 8.0 CVE-2026-70454 rsync 3.2.0 through 3.2.3 (openssl mode) and rsync-ssl through 3.4.4 (stunnel mode) contain a TLS certificate validation vulnerability that allows on… No fix yet Fix from $4,9002026-08-13 MEDIUM 5.8 CVE-2026-18679 When kuma-dp is started against an HTTPS control plane and the operator did not pass a CA certificate, the data plane connects with TLS peer verifica… No fix yet Fix from $4,0002026-08-12 MEDIUM 5.5 CVE-2026-18678 When an operator adds an HTTPS control plane profile to kumactl without providing a CA certificate, kumactl disables TLS verification and sends API t… No fix yet Fix from $4,0002026-08-12 CRITICAL 9.1 CVE-2026-71290 Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. HostnameVerificationPolicy#BUILTIN setting has no effe… Httpclient No fix yet Fix from $5,7502026-08-11 HIGH 8.3 CVE-2026-66154 An insufficient certificate validation in a privileged communication workflow, was identified in a GMS application 9.5.1 (Build 9510.1044) and earlie… No fix yet Fix from $4,9002026-08-11 MEDIUM 5.5 CVE-2026-48437 CAI Content Credentials is affected by an Improper Certificate Validation vulnerability that could result in a Security feature bypass. An attacker c… C2pa 0.12.1 / 0.27.6+ Fix from $4,0002026-08-11 HIGH 8.1 CVE-2026-18129 Cleartext transmission of sensitive information in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a remote unauthenticated attack… No fix yet Fix from $4,9002026-08-11 HIGH 7.4 CVE-2026-15554 the Undertow AJP listener honours forged ssl_cert and is_ssl AJP attributes without requiring any shared-secret authentication. This enables an unaut… No fix yet Fix from $4,9002026-08-11 MEDIUM 6.4 CVE-2026-66760 SAP Approuter does not correctly validate client certificates in certain callback flows. An attacker with low privileges, holding a certificate from … No fix yet Fix from $4,0002026-08-11 MEDIUM 6.5 CVE-2026-66404 DEEBOT PRO M1 and DEEBOT PRO K1VAC do not validate server certificates in MQTT communications. Operation logs and activity logs stored on the affecte… No fix yet Fix from $4,0002026-08-10 CRITICAL 9.1 CVE-2026-64993 Dell RVTools versions prior to 4.8.1, contains an improper certificate validation vulnerability in the collector. A remote unauthenticated attacker c… Rvtools 4.8.1+ Fix from $2,3002026-08-06 MEDIUM 6.1 CVE-2026-16792 An improper certificate validation vulnerability was reported in multiple Lenovo XClarity Orchestrator (LXCO) 2.2.0 microservices that could allow an… No fix yet Fix from $1,6002026-08-04 MEDIUM 6.9 CVE-2026-69248 cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 49.0.0, if an intermediate constrain… No fix yet Fix from $1,6002026-08-03 HIGH 7.4 CVE-2026-67598 Emlog Pro through 2.6.23 contains a disabled TLS certificate validation vulnerability in include/service/ai.php that allows network-adjacent attacker… No fix yet Fix from $1,9502026-08-03 MEDIUM 6.5 CVE-2025-9291 A certification validation weakness exists in communication between affected Omada devices and cloud controllers. Certificate identity verification d… Omada Fusion 2.5g Firmware No fix yet Fix from $1,6002026-08-03 HIGH 7.5 CVE-2026-18089 Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass by verifying responses against the response-embedded certificate in verify_… Net\ 0.86+ Fix from $1,9502026-08-03 HIGH 7.3 CVE-2026-0392 eParakstītājs 3.0 for Windows before version 1.10.0 retrieves and executes its automatic updates over a channel that is not authenticated or integrit… No fix yet Fix from $1,9502026-08-03 CRITICAL 9.3 CVE-2026-58062 In Bouncy Castle for Java before 1.85, Stapled OCSP response accepted without binding to the checked certificate. This issue also affects Bouncy Cast… No fix yet Fix from $2,3002026-08-03 CRITICAL 9.3 CVE-2026-8763 In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in rfc822Name and URI. This issue also affects Bouncy Castle for Java… Mitigation only Fix from $2,3002026-08-03 MEDIUM 5.9 CVE-2026-67294 FreeRDP before 3.29.0 improperly validates the Extended Key Usage (EKU) purpose of the peer certificate during client-side server TLS authentication.… No fix yet Fix from $1,6002026-08-01 CRITICAL 9.8 CVE-2026-66402 FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains multiple TLS certificate identity validation weaknesses in tls_verify_certificate(), tls… No fix yet Fix from $2,3002026-08-01 HIGH 8.2 CVE-2026-18141 A flaw was found in aap-gateway, a component of Ansible Automation Platform's Event-Driven Ansible (EDA). An unauthenticated remote attacker can bypa… No fix yet Fix from $1,9502026-07-31 HIGH 7.4 CVE-2026-8497 Improper certificate validation in the Devolutions Server connection handling in Devolutions Password Manager 2026.2.1.0 and earlier on Android, iOS,… No fix yet Fix from $1,9502026-07-29