Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 5.6
CVE-2026-18257
Improper validity period check for root issuer certificate in CycloneCrypto cryptographic wrapper of S2OPC allows a certificate issued by this root i…
No fix yet
CRITICAL 10.0
CVE-2026-58162
The Apache Traffic Server certifier plugin generates certificates based on attacker-controlled client SNI.
This issue affects Apache Traffic Server:…
Traffic Server
9.2.15 / 10.1.4+
MEDIUM 5.9
CVE-2026-16107
IBM TS4500 CLI tool Versions: 0.1.31 through 1.12.0.0 does not validate or improperly validates TLS certificate validation, which could allow an att…
No fix yet
HIGH 8.1
CVE-2026-54342
In epa4all, prior to version 2026-05-20, an attacker on the network path between epa4all and any backend (ePA Aktensystem, Konnektor, IDP, TSS) can p…
No fix yet
CRITICAL 9.1
CVE-2026-48021
In epa4all, prior to version 2026-05-20, an attacker who can intercept the TLS connection between epa4all and the ePA backend can complete the VAU ha…
No fix yet
HIGH 7.5
CVE-2026-52688
RRSIGs with too few labels can lead to bypass of DNSSEC wildcard validation
No fix yet
CRITICAL 9.1
CVE-2026-56820
Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and prior to 4…
Netty
4.1.136 / 4.2.16+
HIGH 8.0
CVE-2026-60648
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are a…
Webcenter Content
No fix yet
HIGH 7.3
CVE-2026-56624
Improper certificate validation in Apache MINA SSHD (server-side). Apache MINA SSHD is a Java library for client-side and server-side SSH.
Server…
Mina Sshd
2.19.0+
CRITICAL 9.1
CVE-2026-46428
lettre is a a mailer library for Rust. Starting in version 0.10.1 and prior to version 0.11.22, an inverted-boolean bug in lettre's `boring-tls` inte…
No fix yet
HIGH 8.2
CVE-2026-13410
Dancer::Plugin::Auth::Google versions before 0.08 for Perl have TLS verification disabled.
The default user agent is initialised with SSL_verify_mod…
No fix yet
MEDIUM 5.3
CVE-2026-38974
Dulwich through 1.1.0 was found to be missing SSH host key verification in contrib/paramiko_vendor.py.
Mitigation only
CRITICAL 9.5
CVE-2026-13385
An Improper Validation of Integrity Check Value and Improper Certificate Validation in certain ASUS router models allows a remote man-in-the-middle(M…
Mitigation only
MEDIUM 6.5
CVE-2026-50302
Improper certificate validation in Windows Cryptographic Services allows an unauthorized attacker to bypass a security feature over a network.
Windows 10 21h2
10.0.19044.7548 / 10.0.19045.7548+
HIGH 7.8
CVE-2026-55001
Improper certificate validation in Windows Active Directory allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.9339 / 10.0.17763.9020+
HIGH 8.8
CVE-2026-47632
Improper certificate validation in Azure Connected Machine Agent allows an unauthorized attacker to elevate privileges over an adjacent network.
Azure Connected Machine Agent
Mitigation only
CRITICAL 9.8
CVE-2026-59836
A improper certificate validation vulnerability in Fortinet FortiClientEMS 7.4.3 through 7.4.5, FortiClientEMS 7.4.0 through 7.4.1, FortiClientEMS 7.…
Forticlientems
7.4.6+
HIGH 7.5
CVE-2026-15683
Lorex 2K Indoor Wi-Fi Security Camera Device Management Server Improper Certificate Validation Vulnerability. This vulnerability allows network-adjac…
Mitigation only
CRITICAL 9.5
CVE-2026-22093
The EVbee Service Android app uses TLS encrypted communication (HTTPS), but does not validate the certificate provided by the server. This allows an …
Mitigation only
HIGH 7.4
CVE-2026-54919
cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. In affected Mbed TLS backend versions from 0.31.0 through 0.46.1 an…
Cpp Httplib
0.47.0+
MEDIUM 5.9
CVE-2026-0277
An improper certificate validation vulnerability in the Prisma® Access Agent for iOS enables an attacker to perform a man-in-the-middle (MitM) attack…
Prisma Access Agent
26.2.1+
HIGH 8.1
CVE-2026-59818
etcd is a distributed key-value store for the data of a distributed system. Prior to 3.5.32 and 3.6.13, when etcd is configured with --listen-client-…
Etcd
3.5.32 / 3.6.13+
HIGH 7.4
CVE-2026-55436
Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.30.0 and prior to versions 2.32.7, 2.33.…
Coder
2.32.7 / 2.33.8+
HIGH 7.4
CVE-2026-6900
Improper certificate validation vulnerability in B&R Industrial Automation GmbH APROL.
This issue affects APROL: before R 4.4-01P5.
Mitigation only
HIGH 7.5
CVE-2026-12064
When a user invokes curl using a schemeless URL combined with
`--proto-default` sftp (or scp), a disconnect occurs between the tool layer
and libcurl…
Curl
8.21.0+
HIGH 8.1
CVE-2026-8286
A vulnerability exists where a new transfer that uses STARTTLS to upgrade the
connection might reuse an existing live connection even though the TLS
…
Curl
8.21.0+
CRITICAL 9.1
CVE-2026-11564
libcurl keeps previously used connections in a connection pool for subsequent
transfers to reuse if one of them matches the setup.
An easy handle th…
Curl
8.21.0+
MEDIUM 6.4
CVE-2026-12374
Improper certificate validation and a time-of-check time-of-use (TOCTOU) race condition in the PrivilegedHelperTool XPC service in Cato Client before…
Mitigation only
HIGH 7.5
CVE-2026-7532
iPAddress name constraints bypass when WOLFSSL_IP_ALT_NAME is not defined. IP address name constraints are not enforced in that configuration, allowi…
Wolfssl
5.9.2+
MEDIUM 5.3
CVE-2026-10098
OCSP CertID serial-number length-confusion in wolfSSL_OCSP_resp_find_status allows a same-issuer SingleResponse whose serial is a prefix of the targe…
Wolfssl
5.9.2+