Vulnerability index

Browse CVEs

1,354 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Certificate ValidationCWE-295 × clear
MEDIUM 6.3 CVE-2024-2379 libcurl skips the certificate verification for a QUIC connection under certain conditions, when built to use wolfSSL. If told to use an unknown/bad c… Curl 12.7.6 / 13.6.8+ Fix from $1,6002024-03-27 CRITICAL 9.8 CVE-2024-1351 Under certain configurations of --tlsCAFile and tls.CAFile, MongoDB Server may skip peer certificate validation which may result in untrusted connect… MongoDB 4.4.29 / 5.0.25+ Fix from $2,3002024-03-07 MEDIUM 5.3 CVE-2024-28161 In Jenkins Delphix Plugin 3.0.1, a global option for administrators to enable or disable SSL/TLS certificate validation for Data Control Tower (DCT) … Delphix Mitigation only Fix from $1,6002024-03-06 CRITICAL 9.8 CVE-2024-2048 Vault and Vault Enterprise (“Vault”) TLS certificate auth method did not correctly validate client certificates when configured with a non-CA certifi… Vault 1.14.10 / 1.15.5+ Fix from $2,3002024-03-04 MEDIUM 5.9 CVE-2023-47742 IBM QRadar Suite Products 1.10.12.0 through 1.10.18.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 could disclose sensitive information … Cloud Pak For Security after 1.10.18.0 Fix from $1,6002024-03-03 CRITICAL 9.1 CVE-2024-25141 When ssl was enabled for Mongo Hook, default settings included "allow_insecure" which caused that certificates were not validated. This was unexpecte… Apache Airflow Providers Mongo 4.0.0+ Fix from $2,3002024-02-20 HIGH 7.3 CVE-2023-49250 Because the HttpUtils class did not verify certificates, an attacker that could perform a Man-in-the-Middle (MITM) attack on outgoing https connectio… Dolphinscheduler 3.2.1+ Fix from $1,9502024-02-20 HIGH 7.5 CVE-2023-40104 In ca-certificates, there is a possible way to read encrypted TLS data due to untrusted cryptographic certificates. This could lead to remote informa… Android Patch available Fix from $1,9502024-02-15 HIGH 7.4 CVE-2024-25642 Due to improper validation of certificate in SAP Cloud Connector - version 2.0, attacker can impersonate the genuine servers to interact with SCC bre… Cloud Connector Mitigation only Fix from $1,9502024-02-13 HIGH 7.2 CVE-2023-43017 IBM Security Verify Access 10.0.0.0 through 10.0.6.1 could allow a privileged user to install a configuration file that could allow remote access. I… Security Verify Access after 10.0.6.1 Fix from $1,9502024-02-07 HIGH 7.5 CVE-2023-47700 IBM SAN Volume Controller, IBM Storwize, IBM FlashSystem and IBM Storage Virtualize 8.6 products could allow a remote attacker to spoof a trusted sys… Storage Virtualize Mitigation only Fix from $1,9502024-02-07 CRITICAL 9.8 CVE-2023-32330 IBM Security Verify Access 10.0.0.0 through 10.0.6.1 uses insecure calls that could allow an attacker on the network to take control of the server. … Security Verify Access after 10.0.6.1 Fix from $2,3002024-02-07 CRITICAL 9.8 CVE-2024-25140 A default installation of RustDesk 1.2.3 on Windows places a WDKTestCert certificate under Trusted Root Certification Authorities with Enhanced Key U… Rustdesk No fix yet Fix from $2,3002024-02-06 HIGH 8.0 CVE-2024-1052 Boundary and Boundary Enterprise (“Boundary”) is vulnerable to session hijacking through TLS certificate tampering. An attacker with privileges to en… Boundary 0.15.0+ Fix from $1,9502024-02-05 MEDIUM 5.3 CVE-2024-0853 curl inadvertently kept the SSL session ID for connections in its cache even when the verify status (*OCSP stapling*) test failed. A subsequent trans… Curl No fix yet Fix from $1,6002024-02-03 CRITICAL 9.8 CVE-2020-29504 Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.5.2, contain a Missing Required Crypt… Bsafe Crypto C Micro Edition 4.1.5 / 4.5.2+ Fix from $2,3002024-02-02 HIGH 7.5 CVE-2023-28807 In Zscaler Internet Access (ZIA) a mismatch between Connect Host and Client Hello's Server Name Indication (SNI) enables attackers to evade network s… Secure Internet And Saas Access 6.2r.290+ Fix from $1,9502024-01-31 MEDIUM 6.5 CVE-2023-50356 SSL connections to some LDAP servers are vulnerable to a man-in-the-middle attack due to improper certificate validation in AREAL Topkapi Vision (Ser… Vision Server 6.2.4719+ Fix from $1,6002024-01-31 CRITICAL 9.8 CVE-2023-51837 Ylianst MeshCentral 1.1.16 is vulnerable to Missing SSL Certificate Validation. Meshcentral No fix yet Fix from $2,3002024-01-30 MEDIUM 5.9 CVE-2023-33757 A lack of SSL certificate validation in Splicecom iPCS (iOS App) v1.3.4, iPCS2 (iOS App) v2.8 and before, and iPCS (Android App) v1.8.5 and before al… Ipcs after 2.8 Fix from $1,6002024-01-25 MEDIUM 5.3 CVE-2023-33760 SpliceCom Maximiser Soft PBX v1.5 and before was discovered to utilize a default SSL certificate. This issue can allow attackers to eavesdrop on comm… Maximiser Soft Pbx after 1.5 Fix from $1,6002024-01-25 HIGH 7.8 CVE-2023-6043 A privilege escalation vulnerability was reported in Lenovo Vantage that could allow a local attacker to bypass integrity checks and execute arbitrar… Vantage 4.0.49.0+ Fix from $1,9502024-01-19 MEDIUM 6.5 CVE-2023-33295 Cohesity DataProtect prior to 6.8.1_u5 or 7.1 was discovered to have a incorrect access control vulnerability due to a lack of TLS Certificate Valida… Cohesity Dataplatform after 7.0.1 Fix from $1,6002024-01-19 HIGH 7.5 CVE-2023-51662 The Snowflake .NET driver provides an interface to the Microsoft .NET open source software framework for developing applications. Snowflake recently … Snowflake Connector 2.1.5+ Fix from $1,9502023-12-22 HIGH 8.6 CVE-2023-5594 Improper validation of the server’s certificate chain in secure traffic scanning feature considered intermediate certificate signed using the MD5 or … Endpoint Antivirus Mitigation only Fix from $1,9502023-12-21 HIGH 7.5 CVE-2023-1514 A vulnerability exists in the component RTU500 Scripting interface. When a client connects to a server using TLS, the server presents a certificate. … Rtu500 Scripting Interface Mitigation only Fix from $1,9502023-12-19 HIGH 8.1 CVE-2023-6680 An improper certificate validation issue in Smartcard authentication in GitLab EE affecting all versions from 11.6 prior to 16.4.4, 16.5 prior to 16.… GitLab 16.4.4 / 16.5.4+ Fix from $1,9502023-12-15 HIGH 7.5 CVE-2009-4123 The jruby-openssl gem before 0.6 for JRuby mishandles SSL certificate validation. Jruby Openssl 0.6+ Fix from $1,9502023-12-12 HIGH 7.8 CVE-2020-12614 An issue was discovered in BeyondTrust Privilege Management for Windows through 5.6. If the publisher criteria is selected, it defines the name of a … Privilege Management For Windows after 5.6 Fix from $1,9502023-12-12 CRITICAL 9.8 CVE-2023-48427 A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). Affected products do not properly validate the certificate of th… Sinec Ins 1.0+ Fix from $2,3002023-12-12