Vulnerability index

Browse CVEs

1,344 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Certificate ValidationCWE-295 × clear
HIGH 7.5 CVE-2024-8287 Anbox Management Service, in versions 1.17.0 through 1.23.0, does not validate the TLS certificate provided to it by the Anbox Stream Agent. An attac… Anbox Cloud 1.23.1+ Fix from $1,9502024-09-18 MEDIUM 6.5 CVE-2024-8096 When curl is told to use the Certificate Status Request TLS extension, often referred to as OCSP stapling, to verify that the server certificate is v… Curl 8.10.0+ Fix from $1,6002024-09-11 HIGH 8.1 CVE-2024-31489 AAn improper certificate validation vulnerability [CWE-295] in FortiClientWindows 7.2.0 through 7.2.2, 7.0.0 through 7.0.11, FortiClientLinux 7.2.0,… Forticlient 7.0.12 / 7.2.3+ Fix from $1,9502024-09-10 MEDIUM 5.9 CVE-2022-45856 An improper certificate validation vulnerability [CWE-295] in FortiClientWindows 6.4 all versions, 7.0.0 through 7.0.7, FortiClientMac 6.4 all versio… Forticlient 7.0.7 / 7.0.8+ Fix from $1,6002024-09-10 HIGH 8.3 CVE-2024-40714 An improper certificate validation vulnerability in TLS certificate validation allows an attacker on the same network to intercept sensitive credenti… Veeam Backup \& Replication 12.2.0.334+ Fix from $1,9502024-09-07 HIGH 7.8 CVE-2024-38642 An improper certificate validation vulnerability has been reported to affect QuMagie. If exploited, the vulnerability could allow local network users… Qumagie Mitigation only Fix from $1,9502024-09-06 CRITICAL 9.8 CVE-2024-45159 An issue was discovered in Mbed TLS 3.x before 3.6.1. With TLS 1.3, when a server enables optional authentication of the client, if the client-provid… Mbed Tls 3.6.1+ Fix from $2,3002024-09-05 MEDIUM 5.9 CVE-2024-8285 A flaw was found in Kroxylicious. When establishing the connection with the upstream Kafka server using a TLS secured connection, Kroxylicious fails … Kroxylicious Mitigation only Fix from $1,6002024-08-30 MEDIUM 6.8 CVE-2024-39771 QBiC CLOUD CC-2L v1.1.30 and earlier and Safie One v1.8.2 and earlier do not properly validate certificates, which may allow a network-adjacent unaut… Qbic Cloud Cc 2\/2l Firmware after 1.8.2 Fix from $1,6002024-08-28 HIGH 7.5 CVE-2024-41996 Validating the order of the public keys in the Diffie-Hellman Key Agreement Protocol, when an approved safe prime is used, allows remote attackers (f… Mitigation only Fix from $1,9502024-08-26 HIGH 7.5 CVE-2024-45234 An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) a… Fort Validator 1.6.3+ Fix from $1,9502024-08-24 HIGH 8.2 CVE-2024-37311 Collabora Online is a collaborative online office suite based on LibreOffice. In affected versions of Collabora Online, https connections from coolws… Mitigation only Fix from $1,9502024-08-23 HIGH 8.1 CVE-2024-8007 A flaw was found in the openstack-tripleo-common component of the Red Hat OpenStack Platform (RHOSP) director. This vulnerability allows an attacker … Openstack Platform Mitigation only Fix from $1,9502024-08-21 MEDIUM 5.9 CVE-2024-32928 The libcurl CURLOPT_SSL_VERIFYPEER option was disabled on a subset of requests made by Nest production devices which enabled a potential man-in-the-m… Nest Mini Firmware Mitigation only Fix from $1,6002024-08-19 HIGH 7.5 CVE-2023-50314 IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.8 could allow an attacker with access to the network to conduct spoofing attacks. A… Websphere Application Server after 24.0.0.8 Fix from $1,9502024-08-14 MEDIUM 5.9 CVE-2023-50315 IBM WebSphere Application Server 8.5 and 9.0 could allow an attacker with access to the network to conduct spoofing attacks. An attacker could explo… Websphere Application Server Mitigation only Fix from $1,6002024-08-14 HIGH 8.1 CVE-2024-7570 Improper certificate validation in Ivanti ITSM on-prem and Neurons for ITSM Versions 2023.4 and earlier allows a remote attacker in a MITM position t… Neurons For Itsm Patch available Fix from $1,9502024-08-13 CRITICAL 9.8 CVE-2024-42395 There is a vulnerability in the AP Certificate Management Service which could allow a threat actor to execute an unauthenticated RCE attack. Successf… Arubaos 8.10.0.13 / 8.12.0.2+ Fix from $2,3002024-08-06 HIGH 7.4 CVE-2024-7383 A flaw was found in libnbd. The client did not always correctly verify the NBD server's certificate when using TLS to connect to an NBD server. This … Mitigation only Fix from $1,9502024-08-05 HIGH 7.8 CVE-2024-6472 Certificate Validation user interface in LibreOffice allows potential vulnerability. Signed macros are scripts that have been digitally signed by… Libreoffice 24.2.5.1+ Fix from $1,9502024-08-05 HIGH 7.3 CVE-2024-32865 Under certain circumstances the exacqVision Server will not properly validate TLS certificates provided by connected devices. Exacqvision Server 24.06+ Fix from $1,9502024-08-01 HIGH 7.5 CVE-2024-41264 An issue discovered in casdoor v1.636.0 allows attackers to obtain sensitive information via the ssh.InsecureIgnoreHostKey() method. Casdoor Mitigation only Fix from $1,9502024-08-01 MEDIUM 5.9 CVE-2024-41256 Default configurations in the ShareProofVerifier function of filestash v0.4 causes the application to skip the TLS certificate verification process w… Filestash after 0.4 Fix from $1,6002024-07-31 MEDIUM 5.3 CVE-2024-41258 An issue was discovered in filestash v0.4. The usage of the ssh.InsecureIgnoreHostKey() disables host key verification, possibly allowing attackers t… Filestash after 0.4 Fix from $1,6002024-07-31 HIGH 8.8 CVE-2024-40464 An issue in beego v.2.2.0 and before allows a remote attacker to escalate privileges via the sendMail function located in beego/core/logs/smtp.go file Beego 2.2.1+ Fix from $1,9502024-07-31 HIGH 8.1 CVE-2024-28872 The TLS certificate validation code is flawed. An attacker can obtain a TLS certificate from the Stork server and use it to connect to the Stork agen… Stork 1.15.1+ Fix from $1,9502024-07-11 MEDIUM 5.9 CVE-2024-37865 An issue in S3Browser v.11.4.5 and v.10.9.9 and fixed in v.11.5.7 allows a remote attacker to obtain sensitive information via the S3 compatible stor… S3 Browser 11.7.5+ Fix from $1,6002024-07-09 HIGH 7.5 CVE-2024-39698 electron-updater allows for automatic updates for Electron apps. The file `packages/electron-updater/src/windowsExecutableCodeSignatureVerifier.ts` i… Electron Builder 6.3.0+ Fix from $1,9502024-07-09 HIGH 7.4 CVE-2023-50178 An improper certificate validation vulnerability [CWE-295] in FortiADC 7.4.0, 7.2.0 through 7.2.3, 7.1 all versions, 7.0 all versions, 6.2 all versio… Fortiadc after 7.2.3 Fix from $1,9502024-07-09 MEDIUM 5.9 CVE-2023-50179 An improper certificate validation vulnerability [CWE-295] in FortiADC 7.4.0, 7.2 all versions, 7.1 all versions, 7.0 all versions may allow a remote… Fortiadc 7.4.1+ Fix from $1,6002024-07-09