Vulnerability index

Browse CVEs

1,344 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Certificate ValidationCWE-295 × clear
MEDIUM 5.6 CVE-2026-18257 Improper validity period check for root issuer certificate in CycloneCrypto cryptographic wrapper of S2OPC allows a certificate issued by this root i… No fix yet Fix from $1,6002026-07-29 CRITICAL 10.0 CVE-2026-58162 The Apache Traffic Server certifier plugin generates certificates based on attacker-controlled client SNI. This issue affects Apache Traffic Server:… Traffic Server 9.2.15 / 10.1.4+ Fix from $2,3002026-07-29 MEDIUM 5.9 CVE-2026-16107 IBM TS4500 CLI tool Versions:  0.1.31 through 1.12.0.0 does not validate or improperly validates TLS certificate validation, which could allow an att… No fix yet Fix from $1,6002026-07-28 HIGH 8.1 CVE-2026-54342 In epa4all, prior to version 2026-05-20, an attacker on the network path between epa4all and any backend (ePA Aktensystem, Konnektor, IDP, TSS) can p… No fix yet Fix from $1,9502026-07-24 CRITICAL 9.1 CVE-2026-48021 In epa4all, prior to version 2026-05-20, an attacker who can intercept the TLS connection between epa4all and the ePA backend can complete the VAU ha… No fix yet Fix from $2,3002026-07-24 HIGH 7.5 CVE-2026-52688 RRSIGs with too few labels can lead to bypass of DNSSEC wildcard validation No fix yet Fix from $1,9502026-07-23 CRITICAL 9.1 CVE-2026-56820 Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and prior to 4… Netty 4.1.136 / 4.2.16+ Fix from $2,3002026-07-21 HIGH 8.0 CVE-2026-60648 Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are a… Webcenter Content No fix yet Fix from $1,9502026-07-21 HIGH 7.3 CVE-2026-56624 Improper certificate validation in Apache MINA SSHD (server-side). Apache MINA SSHD is a Java library for client-side and server-side SSH. Server… Mina Sshd 2.19.0+ Fix from $1,9502026-07-20 CRITICAL 9.1 CVE-2026-46428 lettre is a a mailer library for Rust. Starting in version 0.10.1 and prior to version 0.11.22, an inverted-boolean bug in lettre's `boring-tls` inte… No fix yet Fix from $2,3002026-07-20 HIGH 8.2 CVE-2026-13410 Dancer::Plugin::Auth::Google versions before 0.08 for Perl have TLS verification disabled. The default user agent is initialised with SSL_verify_mod… No fix yet Fix from $1,9502026-07-17 MEDIUM 5.3 CVE-2026-38974 Dulwich through 1.1.0 was found to be missing SSH host key verification in contrib/paramiko_vendor.py. Mitigation only Fix from $1,6002026-07-15 CRITICAL 9.5 CVE-2026-13385 An Improper Validation of Integrity Check Value and Improper Certificate Validation in certain ASUS router models allows a remote man-in-the-middle(M… Mitigation only Fix from $2,3002026-07-15 MEDIUM 6.5 CVE-2026-50302 Improper certificate validation in Windows Cryptographic Services allows an unauthorized attacker to bypass a security feature over a network. Windows 10 21h2 10.0.19044.7548 / 10.0.19045.7548+ Fix from $1,6002026-07-14 HIGH 7.8 CVE-2026-55001 Improper certificate validation in Windows Active Directory allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,9502026-07-14 HIGH 8.8 CVE-2026-47632 Improper certificate validation in Azure Connected Machine Agent allows an unauthorized attacker to elevate privileges over an adjacent network. Azure Connected Machine Agent Mitigation only Fix from $1,9502026-07-14 CRITICAL 9.8 CVE-2026-59836 A improper certificate validation vulnerability in Fortinet FortiClientEMS 7.4.3 through 7.4.5, FortiClientEMS 7.4.0 through 7.4.1, FortiClientEMS 7.… Forticlientems 7.4.6+ Fix from $2,3002026-07-14 HIGH 7.5 CVE-2026-15683 Lorex 2K Indoor Wi-Fi Security Camera Device Management Server Improper Certificate Validation Vulnerability. This vulnerability allows network-adjac… Mitigation only Fix from $1,9502026-07-13 CRITICAL 9.5 CVE-2026-22093 The EVbee Service Android app uses TLS encrypted communication (HTTPS), but does not validate the certificate provided by the server. This allows an … Mitigation only Fix from $2,3002026-07-13 HIGH 7.4 CVE-2026-54919 cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. In affected Mbed TLS backend versions from 0.31.0 through 0.46.1 an… Cpp Httplib 0.47.0+ Fix from $1,9502026-07-10 MEDIUM 5.9 CVE-2026-0277 An improper certificate validation vulnerability in the Prisma® Access Agent for iOS enables an attacker to perform a man-in-the-middle (MitM) attack… Prisma Access Agent 26.2.1+ Fix from $1,6002026-07-09 HIGH 8.1 CVE-2026-59818 etcd is a distributed key-value store for the data of a distributed system. Prior to 3.5.32 and 3.6.13, when etcd is configured with --listen-client-… Etcd 3.5.32 / 3.6.13+ Fix from $1,9502026-07-08 HIGH 7.4 CVE-2026-55436 Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.30.0 and prior to versions 2.32.7, 2.33.… Coder 2.32.7 / 2.33.8+ Fix from $1,9502026-07-08 HIGH 7.4 CVE-2026-6900 Improper certificate validation vulnerability in B&R Industrial Automation GmbH APROL. This issue affects APROL: before R 4.4-01P5. Mitigation only Fix from $1,9502026-07-06 HIGH 7.5 CVE-2026-12064 When a user invokes curl using a schemeless URL combined with `--proto-default` sftp (or scp), a disconnect occurs between the tool layer and libcurl… Curl 8.21.0+ Fix from $1,9502026-07-03 HIGH 8.1 CVE-2026-8286 A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS … Curl 8.21.0+ Fix from $1,9502026-07-03 CRITICAL 9.1 CVE-2026-11564 libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. An easy handle th… Curl 8.21.0+ Fix from $2,3002026-07-03 MEDIUM 6.4 CVE-2026-12374 Improper certificate validation and a time-of-check time-of-use (TOCTOU) race condition in the PrivilegedHelperTool XPC service in Cato Client before… Mitigation only Fix from $1,6002026-07-01 HIGH 7.5 CVE-2026-7532 iPAddress name constraints bypass when WOLFSSL_IP_ALT_NAME is not defined. IP address name constraints are not enforced in that configuration, allowi… Wolfssl 5.9.2+ Fix from $1,9502026-06-25 MEDIUM 5.3 CVE-2026-10098 OCSP CertID serial-number length-confusion in wolfSSL_OCSP_resp_find_status allows a same-issuer SingleResponse whose serial is a prefix of the targe… Wolfssl 5.9.2+ Fix from $1,6002026-06-25