Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.0
CVE-2025-0309
An insufficient validation on the server connection endpoint in Netskope Client allows local users to elevate privileges on the system. The insuffici…
Mitigation only
MEDIUM 5.3
CVE-2025-2183
An insufficient certificate validation issue in the Palo Alto Networks GlobalProtect™ app enables attackers to connect the GlobalProtect app to arbit…
Mitigation only
HIGH 7.4
CVE-2025-54809
F5 Access for Android before version 3.1.2 which uses HTTPS does not verify the remote endpoint identity.
Note: Software versions which have rea…
F5 Access
3.1.2+
HIGH 7.3
CVE-2025-8393
A TLS vulnerability exists in the phone application used to manage a
connected device. The phone application accepts self-signed certificates
when …
Mitigation only
MEDIUM 5.4
CVE-2025-20215
A vulnerability in the meeting-join functionality of Cisco Webex Meetings could have allowed an unauthenticated, network-proximate attacker to comple…
Mitigation only
MEDIUM 5.7
CVE-2025-48393
The server identity check mechanism for firmware upgrade performed via command shell is insecurely implemented potentially allowing an attacker to pe…
Mitigation only
MEDIUM 5.3
CVE-2025-2028
Lack of TLS validation when downloading a CSV file including mapping from IPs to countries used ONLY for displaying country flags in logs
Log Server
Mitigation only
HIGH 7.5
CVE-2025-54607
Authentication management vulnerability in the ArkWeb module.
Impact: Successful exploitation of this vulnerability may affect service confidentialit…
Harmonyos
No fix yet
HIGH 8.0
CVE-2025-8476
Alpine iLX-507 TIDAL Improper Certificate Validation Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on…
Ilx 507 Firmware
Mitigation only
MEDIUM 6.8
CVE-2025-6037
Vault and Vault Enterprise (“Vault”) TLS certificate auth method did not correctly validate client certificates when configured with a non-CA certifi…
Vault
1.16.23 / 1.18.12+
MEDIUM 6.5
CVE-2025-36005
IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4.1, 3.5.0, 3.5.1, 3.6.0, and MQ Operator…
Mq Operator
after 3.6.0
CRITICAL 9.2
CVE-2025-7395
A certificate verification error in wolfSSL when building with the WOLFSSL_SYS_CA_CERTS and WOLFSSL_APPLE_NATIVE_CERT_VALIDATION options results in t…
Mitigation only
MEDIUM 6.8
CVE-2025-30024
The communication protocol used between client
and server had a flaw that could be leveraged to execute a man in the middle attack.
Device Manager
5.32.137+
CRITICAL 9.1
CVE-2025-46788
Improper certificate validation in Zoom Workplace for Linux before version 6.4.13 may allow an unauthorized user to conduct an information disclosure…
Workplace Desktop
6.4.13+
MEDIUM 5.3
CVE-2025-32989
A heap-buffer-overread vulnerability was found in GnuTLS in how it handles the Certificate Transparency (CT) Signed Certificate Timestamp (SCT) exten…
Openshift Container Platform
Mitigation only
MEDIUM 6.5
CVE-2025-35983
Improper Certificate Validation (CWE-295) in the Controller 7000 OneLink implementation could allow an unprivileged attacker to perform a limited den…
Mitigation only
MEDIUM 6.5
CVE-2025-48802
Improper certificate validation in Windows SMB allows an authorized attacker to perform spoofing over a network.
Windows 11 22h2
10.0.20348.3932 / 10.0.22621.5624+
HIGH 8.1
CVE-2024-31854
A vulnerability has been identified in SICAM TOOLBOX II (All versions < V07.11). During establishment of a https connection to the TLS server of a ma…
Sicam Toolbox Ii
07.11+
HIGH 8.1
CVE-2024-31853
A vulnerability has been identified in SICAM TOOLBOX II (All versions < V07.11). During establishment of a https connection to the TLS server of a ma…
Sicam Toolbox Ii
07.11+
MEDIUM 6.1
CVE-2025-7095
A vulnerability classified as critical has been found in Comodo Internet Security Premium 12.3.4.8162. This affects an unknown part of the component …
Internet Security
No fix yet
HIGH 8.3
CVE-2025-34066
An improper certificate validation vulnerability exists in AVTECH IP cameras, DVRs, and NVRs due to the use of wget with --no-check-certificate in sc…
No fix yet
CRITICAL 9.8
CVE-2025-29331
An issue in MHSanaei 3x-ui before v.2.5.3 and before allows a remote attacker to execute arbitrary code via the management script x-ui passes the no …
3x Ui
2.5.3+
HIGH 8.3
CVE-2025-6032
A flaw was found in Podman. The podman machine init command fails to verify the TLS certificate when downloading the VM images from an OCI registry. …
Patch available
CRITICAL 9.8
CVE-2025-6433
If a user visited a webpage with an invalid TLS certificate, and granted an exception, the webpage was able to provide a WebAuthn challenge that the …
Firefox
140.0+
MEDIUM 6.5
CVE-2025-39205
A vulnerability exists in the IEC 61850 in MicroSCADA X SYS600 product. The certificate validation of the TLS protocol allows remote Man-in-the-Middl…
Microscada X Sys600
10.7+
CRITICAL 9.8
CVE-2025-32878
An issue was discovered on COROS PACE 3 devices through 3.0808.0. It implements a function to connect the watch to a WLAN. This function is mainly fo…
Coros Pace 3 Firmware
after 3.0808.0
CRITICAL 9.8
CVE-2025-36041
IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4.1, 3.5.0, 3.5.1 through 3.5.3, and MQ O…
Mq Operator
after 3.5.3
MEDIUM 6.5
CVE-2025-24471
An Improper Certificate Validation vulnerability [CWE-295] in FortiOS version 7.6.1 and below, version 7.4.7 and below may allow an EAP verified remo…
Fortisase
7.4.8 / 7.6.2+
HIGH 8.8
CVE-2025-33031
An improper certificate validation vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then…
File Station
5.5.6.4847+
HIGH 8.8
CVE-2025-30279
An improper certificate validation vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can the…
File Station
5.5.6.4847+