Vulnerability index

Browse CVEs

1,354 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Certificate ValidationCWE-295 × clear
MEDIUM 5.9 CVE-2023-31485 GitLab::API::v4 through 0.26 does not verify TLS certificates when connecting to a GitLab server, enabling machine-in-the-middle attacks. \ after 0.26 Fix from $1,6002023-04-29 HIGH 8.1 CVE-2023-31486 HTTP::Tiny before 0.083, a Perl core module since 5.13.9 and available standalone on CPAN, has an insecure default TLS configuration where users must… Perl 0.083 / 5.38.0+ Fix from $1,9502023-04-29 CRITICAL 9.8 CVE-2022-47758 Nanoleaf firmware v7.1.1 and below is missing TLS verification, allowing attackers to execute arbitrary code via a DNS hijacking attack. Nanoleaf Firmware Mitigation only Fix from $2,3002023-04-27 CRITICAL 9.8 CVE-2021-46880 x509/x509_verify.c in LibreSSL before 3.4.2, and OpenBSD before 7.0 errata 006, allows authentication bypass because an error for an unverified certi… Libressl 3.4.2 / 7.0+ Fix from $2,3002023-04-15 CRITICAL 9.8 CVE-2023-26463 strongSwan 5.9.8 and 5.9.9 potentially allows remote code execution because it uses a variable named "public" for two different purposes within the s… Strongswan Mitigation only Fix from $2,3002023-04-15 MEDIUM 6.5 CVE-2023-30516 Jenkins Image Tag Parameter Plugin 2.0 improperly introduces an option to opt out of SSL/TLS certificate validation when connecting to Docker registr… Image Tag Parameter 2.0+ Fix from $1,6002023-04-12 MEDIUM 5.3 CVE-2023-30517 Jenkins NeuVector Vulnerability Scanner Plugin 1.22 and earlier unconditionally disables SSL/TLS certificate and hostname validation when connecting … Neuvector Vulnerability Scanner after 1.22 Fix from $1,6002023-04-12 MEDIUM 5.3 CVE-2022-48437 An issue was discovered in x509/x509_verify.c in LibreSSL before 3.6.1, and in OpenBSD before 7.2 errata 001. x509_verify_ctx_add_chain does not stor… Libressl 3.6.1 / 7.2+ Fix from $1,6002023-04-12 HIGH 8.1 CVE-2023-22642 An improper certificate validation vulnerability [CWE-295] in FortiAnalyzer and FortiManager 7.2.0 through 7.2.1, 7.0.0 through 7.0.5, 6.4.8 through … Fortianalyzer 6.4.11 / 7.0.6+ Fix from $1,9502023-04-11 MEDIUM 6.3 CVE-2023-23588 A vulnerability has been identified in SIMATIC IPC1047 (All versions), SIMATIC IPC1047E (All versions with maxView Storage Manager < 4.09.00.25611 on… Simatic Ipc647d Firmware 4.09.00.25611+ Fix from $1,6002023-04-11 MEDIUM 6.5 CVE-2023-28093 A user with a compromised configuration can start an unsigned binary as a service. Synchronization Engine 3.1.30+ Fix from $1,6002023-04-10 MEDIUM 5.9 CVE-2023-25392 Allegro Tech BigFlow <1.6 is vulnerable to Missing SSL Certificate Validation. Bigflow 1.6+ Fix from $1,6002023-04-10 MEDIUM 6.5 CVE-2023-29000 The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server. Starting with version 3.0.0 and prior to version 3.7.0, by trustin… Desktop 3.7.0+ Fix from $1,6002023-04-04 HIGH 8.8 CVE-2022-27644 This vulnerability allows network-adjacent attackers to compromise the integrity of downloaded information on affected installations of NETGEAR R6700… R6400 Firmware 1.0.4.84 / 1.0.4.126+ Fix from $1,9502023-03-29 MEDIUM 5.3 CVE-2023-0465 Applications that use a non-default option when verifying certificates may be vulnerable to an attack from a malicious CA to circumvent certain check… OpenSSL 1.0.2zh / 1.1.1u+ Fix from $1,6002023-03-28 MEDIUM 5.3 CVE-2023-0466 The function X509_VERIFY_PARAM_add0_policy() is documented to implicitly enable the certificate policy check when doing certificate verification. How… OpenSSL 1.0.2zh / 1.1.1u+ Fix from $1,6002023-03-28 CRITICAL 9.8 CVE-2022-45597 ComponentSpace.Saml2 4.4.0 Missing SSL Certificate Validation. NOTE: the vendor does not consider this a vulnerability because the report is only abo… Saml Mitigation only Fix from $2,3002023-03-24 HIGH 7.8 CVE-2023-20963 KEV In WorkSource, there is a possible parcel mismatch. This could lead to local escalation of privilege with no additional execution privileges needed. … Android Patch available Fix from $1,9502023-03-24 HIGH 7.5 CVE-2023-0464 A security vulnerability has been identified in all supported versions of OpenSSL related to the verification of X.509 certificate chains that inclu… OpenSSL 1.0.2zh / 1.1.1u+ Fix from $1,9502023-03-22 HIGH 7.4 CVE-2021-21548 Dell EMC Unisphere for PowerMax versions before 9.1.0.27, Dell EMC Unisphere for PowerMax Virtual Appliance versions before 9.1.0.27, and PowerMax OS… Emc Unisphere For Powermax 9.1.0.27+ Fix from $1,9502023-03-17 HIGH 8.1 CVE-2022-4895 Improper Certificate Validation vulnerability in Hitachi Infrastructure Analytics Advisor on Linux (Analytics probe component), Hitachi Ops Center An… Infrastructure Analytics Advisor 10.9.1-00+ Fix from $1,9502023-02-28 MEDIUM 5.5 CVE-2023-1055 A flaw was found in RHDS 11 and RHDS 12. While browsing entries LDAP tries to decode the userPassword attribute instead of the userCertificate attrib… Directory Server Mitigation only Fix from $1,6002023-02-27 HIGH 7.4 CVE-2022-39948 An improper certificate validation vulnerability [CWE-295] in FortiOS 7.2.0 through 7.2.3, 7.0.0 through 7.0.7, 6.4 all versions, 6.2 all versions, 6… Fortiproxy 7.0.7 / 7.0.8+ Fix from $1,9502023-02-16 MEDIUM 6.8 CVE-2022-48306 Improper Validation of Certificate with Host Mismatch vulnerability in Gotham Chat IRC helper of Palantir Gotham allows A malicious attacker in a pri… Gotham Chat Irc 30221005.210011.9242+ Fix from $1,6002023-02-16 HIGH 7.4 CVE-2022-27890 It was discovered that the sls-logging was not verifying hostnames in TLS certificates due to a misuse of the javax.net.ssl.SSLSocketFactory API. A m… Atlasdb 0.730.0+ Fix from $1,9502023-02-16 MEDIUM 5.3 CVE-2023-22943 In Splunk Add-on Builder (AoB) versions below 4.1.2 and the Splunk CloudConnect SDK versions below 3.1.3, requests to third-party APIs through the RE… Add On Builder 3.1.3 / 4.1.2+ Fix from $1,6002023-02-14 MEDIUM 5.9 CVE-2023-22367 Ichiran App for iOS versions prior to 3.1.0 and Ichiran App for Android versions prior to 3.1.0 improperly verify server certificates, which may allo… Ichiran 3.1.0+ Fix from $1,6002023-02-13 MEDIUM 6.0 CVE-2022-34404 Dell System Update, version 2.0.0 and earlier, contains an Improper Certificate Validation in data parser module. A local attacker with high privileg… System Update 2.0.1.0+ Fix from $1,6002023-02-11 MEDIUM 5.9 CVE-2022-46496 BTicino Door Entry HOMETOUCH for iOS 1.4.2 was discovered to be missing an SSL certificate. Door Entry For Hometouch 1.5.1+ Fix from $1,6002023-02-06 CRITICAL 9.1 CVE-2022-31733 Starting with diego-release 2.55.0 and up to 2.69.0, and starting with CF Deployment 17.1 and up to 23.2.0, apps are accessible via another port on d… Cf Deployment after 23.2.0 Fix from $2,3002023-02-03