Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.9
CVE-2023-50454
An issue was discovered in Zammad before 6.2.0. In several subsystems, SSL/TLS was used to establish connections to external services without proper …
Zammad
Mitigation only
HIGH 7.5
CVE-2023-49247
Permission verification vulnerability in distributed scenarios. Successful exploitation of this vulnerability may affect service confidentiality.
Emui
No fix yet
HIGH 7.5
CVE-2023-5909
KEPServerEX does not properly validate certificates from clients which may allow unauthenticated users to connect.
Industrial Gateway Server
after 7.614
CRITICAL 9.1
CVE-2023-49312
Precision Bridge PrecisionBridge.exe (aka the thick client) before 7.3.21 allows an integrity violation in which the same license key is used on mult…
Precision Bridge
7.3.21+
MEDIUM 5.9
CVE-2023-43082
Dell Unity prior to 5.3 contains a 'man in the middle' vulnerability in the vmadapter component. If a customer has a certificate signed by a third-pa…
Unity Operating Environment
5.3.0.0.5.120+
HIGH 7.4
CVE-2023-48052
Missing SSL certificate validation in HTTPie v3.2.2 allows attackers to eavesdrop on communications between the host and server via a man-in-the-midd…
Httpie
Mitigation only
HIGH 7.4
CVE-2023-48054
Missing SSL certificate validation in localstack v2.3.2 allows attackers to eavesdrop on communications between the host and server via a man-in-the-…
Localstack
Mitigation only
HIGH 7.5
CVE-2023-42532
Improper Certificate Validation in FotaAgent prior to SMR Nov-2023 Release1 allows remote attacker to intercept the network traffic including Firmwar…
Android
Mitigation only
HIGH 7.5
CVE-2023-46724
Squid is a caching proxy for the Web. Due to an Improper Validation of Specified Index bug, Squid versions 3.3.0.1 through 5.9 and 6.0 prior to 6.4 c…
Squid
6.4+
CRITICAL 9.8
CVE-2023-42425
An issue in Turing Video Turing Edge+ EVC5FD v.1.38.6 allows remote attacker to execute arbitrary code and obtain sensitive information via the cloud…
Edge\+ Evc5fd Firmware
Mitigation only
HIGH 7.8
CVE-2023-21358
In UWB Google, there is a possible way for a malicious app to masquerade as system app com.android.uwb.resources due to improperly used crypto. This …
Android
Mitigation only
HIGH 7.5
CVE-2023-31421
It was discovered that when acting as TLS clients, Beats, Elastic Agent, APM Server, and Fleet Server did not verify whether the server certificate i…
Elastic Beats
after 8.9.2
MEDIUM 5.9
CVE-2023-31580
light-oauth2 before version 2.1.27 obtains the public key without any verification. This could allow attackers to authenticate to the application wit…
Light Oauth2
2.1.27+
MEDIUM 5.9
CVE-2022-3761
OpenVPN Connect versions before 3.4.0.4506 (macOS) and OpenVPN Connect before 3.4.0.3100 (Windows) allows man-in-the-middle attackers to intercept co…
Connect
3.4.0.3121 / 3.4.0.4506+
MEDIUM 5.3
CVE-2022-43892
IBM Security Verify Privilege On-Premises 11.5 does not validate, or incorrectly validates, a certificate which could disclose sensitive information …
Security Verify Privilege On Premises
11.5+
CRITICAL 9.1
CVE-2023-5422
The functions to fetch e-mail via POP3 or IMAP as well as sending e-mail via SMTP use OpenSSL for static SSL or TLS based communication. As the
SSL_…
Otrs
7.0.47 / 8.0.37+
HIGH 7.5
CVE-2023-4499
A potential security vulnerability has been identified in the HP ThinUpdate utility (also known as HP Recovery Image and Software Download Tool) whic…
Thinupdate
2.7.15+
CRITICAL 9.8
CVE-2023-5554
Lack of TLS certificate verification in log transmission of a financial module within LINE client for iOS prior to 13.16.0.
Line
13.16.0+
CRITICAL 9.1
CVE-2023-45613
In JetBrains Ktor before 2.3.5 server certificates were not verified
Ktor
2.3.5+
HIGH 7.1
CVE-2023-2422
A flaw was found in Keycloak. A Keycloak server configured to support mTLS authentication for OAuth/OpenID clients does not properly verify the clien…
Keycloak
Mitigation only
HIGH 7.4
CVE-2023-4586
A vulnerability was found in the Hot Rod client. This security issue occurs as the Hot Rod client does not enable hostname validation when using TLS,…
Data Grid
Mitigation only
MEDIUM 5.5
CVE-2023-41991 KEV
A certificate validation issue was addressed. This issue is fixed in macOS Ventura 13.6, iOS 16.7 and iPadOS 16.7. A malicious app may be able to byp…
Ipados
13.6 / 16.7+
HIGH 8.1
CVE-2023-38355
MiniTool Movie Maker 7.0 contains an insecure installation process that allows attackers to achieve remote code execution through a man in the middle…
Movie Maker
Mitigation only
HIGH 8.1
CVE-2023-38356
MiniTool Power Data Recovery 11.6 contains an insecure installation process that allows attackers to achieve remote code execution through a man in t…
Power Data Recovery
Mitigation only
HIGH 8.1
CVE-2023-38352
MiniTool Partition Wizard 12.8 contains an insecure update mechanism that allows attackers to achieve remote code execution through a man in the midd…
Partition Wizard
Mitigation only
MEDIUM 5.9
CVE-2023-38353
MiniTool Power Data Recovery version 11.6 and before contains an insecure in-app payment system that allows attackers to steal highly sensitive infor…
Power Data Recovery
after 11.6
HIGH 8.1
CVE-2023-38354
MiniTool Shadow Maker version 4.1 contains an insecure installation process that allows attackers to achieve remote code execution through a man in t…
Shadowmaker
Mitigation only
HIGH 8.1
CVE-2023-38351
MiniTool Partition Wizard 12.8 contains an insecure installation mechanism that allows attackers to achieve remote code execution through a man in th…
Partition Wizard
Mitigation only
HIGH 7.5
CVE-2023-4801
An improper certification validation vulnerability in the Insider Threat Management (ITM) Agent for MacOS could be used by an anonymous actor on an a…
Insider Threat Management
7.14.3.69+
HIGH 7.5
CVE-2023-30729
Improper Certificate Validation in Samsung Email prior to version 6.1.82.0 allows remote attacker to intercept the network traffic including sensitiv…
Email
6.1.82.0+