Vulnerability index

Browse CVEs

1,354 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Certificate ValidationCWE-295 × clear
MEDIUM 5.9 CVE-2023-41180 Incorrect certificate validation in InvokeHTTP on Apache NiFi MiNiFi C++ versions 0.13 to 0.14 allows an intermediary to present a forged certificate… Nifi Minifi C\+\+ after 0.14.0 Fix from $1,6002023-09-03 MEDIUM 5.9 CVE-2023-39441 Apache Airflow SMTP Provider before 1.3.0, Apache Airflow IMAP Provider before 3.3.0, and Apache Airflow before 2.7.0 are affected by the Validation … Airflow 1.3.0 / 2.7.0+ Fix from $1,6002023-08-23 HIGH 7.5 CVE-2023-1409 If the MongoDB Server running on Windows or macOS is configured to use TLS with a specific set of configuration options that are already known to wor… MongoDB 4.4.23 / 6.0.7+ Fix from $1,9502023-08-23 HIGH 7.5 CVE-2023-21265 In multiple locations, there are root CA certificates which need to be disabled. This could lead to remote information disclosure with no additional … Android Patch available Fix from $1,9502023-08-14 CRITICAL 9.8 CVE-2023-40256 A vulnerability was discovered in Veritas NetBackup Snapshot Manager before 10.2.0.1 that allowed untrusted clients to interact with the RabbitMQ ser… Netbackup Snapshot Manager after 8.3.0.2 Fix from $2,3002023-08-11 MEDIUM 5.3 CVE-2023-38686 Sydent is an identity server for the Matrix communications protocol. Prior to version 2.5.6, if configured to send emails using TLS, Sydent does not … Sydent 2.5.6+ Fix from $1,6002023-08-04 HIGH 8.1 CVE-2023-34143 Improper Validation of Certificate with Host Mismatch vulnerability in Hitachi Device Manager on Windows, Linux (Device Manager Server, Device Manage… Device Manager 8.8.5-02+ Fix from $1,9502023-07-18 HIGH 8.8 CVE-2023-3724 If a TLS 1.3 client gets neither a PSK (pre shared key) extension nor a KSE (key share extension) when connecting to a malicious server, a default pr… Wolfssl 5.6.2+ Fix from $1,9502023-07-17 HIGH 8.1 CVE-2023-3615 Mattermost iOS app fails to properly validate the server certificate while initializing the TLS connection allowing a network attacker to intercept t… Mattermost 2.5.1+ Fix from $1,9502023-07-17 HIGH 7.5 CVE-2023-38325 The cryptography package before 41.0.2 for Python mishandles SSH certificates that have critical options. Cryptography 41.0.2+ Fix from $1,9502023-07-14 HIGH 8.1 CVE-2023-31190 DroneScout ds230 Remote ID receiver from BlueMark Innovations is affected by an Improper Authentication vulnerability during the firmware update proc… Dronescout Ds230 Firmware after 20230329-1042 Fix from $1,9502023-07-11 HIGH 8.1 CVE-2023-23546 A misconfiguration vulnerability exists in the urvpn_client functionality of Milesight UR32L v32.3.0.5. A specially-crafted man-in-the-middle attack … Ur32l Firmware No fix yet Fix from $1,9502023-07-06 MEDIUM 5.3 CVE-2023-33201 Bouncy Castle For Java before 1.74 is affected by an LDAP injection vulnerability. The vulnerability only affects applications that use an LDAP CertS… Bc Java 1.74+ Fix from $1,6002023-07-05 HIGH 7.5 CVE-2023-30222 An information disclosure vulnerability in 4D SAS 4D Server Application v17, v18, v19 R7 and earlier allows attackers to retrieve password hashes for… Server No fix yet Fix from $1,9502023-06-16 HIGH 8.1 CVE-2023-35142 Jenkins Checkmarx Plugin 2022.4.3 and earlier disables SSL/TLS validation for connections to the Checkmarx server by default. Checkmarx after 2023.4.3 Fix from $1,9502023-06-14 MEDIUM 5.3 CVE-2023-34410 An issue was discovered in Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.2. Certificate validation for TLS does not always … Debian Linux 5.15.15 / 6.2.9+ Fix from $1,6002023-06-05 MEDIUM 6.5 CVE-2023-0430 Certificate OCSP revocation status was not checked when verifying S/Mime signatures. Mail signed with a revoked certificate would be displayed as hav… Thunderbird 102.7.1+ Fix from $1,6002023-06-02 MEDIUM 6.5 CVE-2023-0547 OCSP revocation status of recipient certificates was not checked when sending S/Mime encrypted email, and revoked certificates would be accepted. Thu… Thunderbird 102.10+ Fix from $1,6002023-06-02 MEDIUM 5.9 CVE-2023-28321 An improper certificate validation vulnerability exists in curl <v8.1.0 in the way it supports matching of wildcard patterns when listed as "Subject … Curl 8.1.0+ Fix from $1,6002023-05-26 MEDIUM 6.5 CVE-2023-1664 A flaw was found in Keycloak. This flaw depends on a non-default configuration "Revalidate Client Certificate" to be enabled and the reverse proxy is… Build Of Quarkus Mitigation only Fix from $1,6002023-05-26 HIGH 8.1 CVE-2023-20881 Cloud foundry instances having CAPI version between 1.140 and 1.152.0 along with loggregator-agent v7+ may override other users syslog drain credenti… Capi Release after 29.0.0 Fix from $1,9502023-05-19 HIGH 7.5 CVE-2022-45457 Sensitive information disclosure and manipulation due to improper certification validation. The following products are affected: Acronis Agent (Windo… Agent 15+ Fix from $1,9502023-05-18 HIGH 7.5 CVE-2022-45458 Sensitive information disclosure and manipulation due to improper certification validation. The following products are affected: Acronis Agent (Windo… Agent 15+ Fix from $1,9502023-05-18 CRITICAL 9.8 CVE-2023-27823EPSS 53% An authentication bypass in Optoma 1080PSTX C02 allows an attacker to access the administration console without valid credentials. 1080pstx Mitigation only Fix from $2,3002023-05-12 MEDIUM 6.5 CVE-2023-23901 Improper following of a certificate's chain of trust exists in SkyBridge MB-A200 firmware Ver. 01.00.05 and earlier, and SkyBridge BASIC MB-A130 firm… Skybridge Basic Mb A130 Firmware after 1.4.1 Fix from $1,6002023-05-10 MEDIUM 5.3 CVE-2022-39161 IBM WebSphere Application Server 7.0, 8.0, 8.5, 9.0, and IBM WebSphere Application Server Liberty, when configured to communicate with the Web Server… Websphere Application Server Mitigation only Fix from $1,6002023-05-03 MEDIUM 5.9 CVE-2023-24461 An improper certificate validation vulnerability exists in the BIG-IP Edge Client for Windows and macOS and may allow an attacker to impersonate a BI… Big Ip Access Policy Manager 7.2.4.1+ Fix from $1,6002023-05-03 CRITICAL 9.8 CVE-2022-35898 OpenText BizManager before 16.6.0.1 does not perform proper validation during the change-password operation. This allows any authenticated user to ch… Bizmanager 16.6.0.1+ Fix from $2,3002023-05-01 MEDIUM 6.2 CVE-2022-48186 A certificate validation vulnerability exists in the Baiying Android application which could lead to information disclosure. Baiying 1.1.4+ Fix from $1,6002023-05-01 HIGH 8.1 CVE-2023-31484 CPAN.pm before 2.35 does not verify TLS certificates when downloading distributions over HTTPS. Perl 2.35 / 5.38.0+ Fix from $1,9502023-04-29