Vulnerability index

Browse CVEs

1,354 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Certificate ValidationCWE-295 × clear
MEDIUM 5.3 CVE-2022-3913 Rapid7 Nexpose and InsightVM versions 6.6.82 through 6.6.177 fail to validate the certificate of the update server when downloading updates. This fai… Nexpose 6.6.178+ Fix from $1,6002023-02-01 HIGH 7.5 CVE-2023-23131 Selfwealth iOS mobile App 3.3.1 is vulnerable to Insecure App Transport Security (ATS) Settings. Selfwealth Mitigation only Fix from $1,9502023-02-01 CRITICAL 9.8 CVE-2022-45100 Dell PowerScale OneFS, versions 8.2.x-9.3.x, contains an Improper Certificate Validation vulnerability. An remote unauthenticated attacker could pote… Emc Powerscale Onefs 9.1.0.25 / 9.2.1.18+ Fix from $2,3002023-02-01 HIGH 8.3 CVE-2022-32748 A CWE-295: Improper Certificate Validation vulnerability exists that could cause the CAE software to give wrong data to end users when using CAE to c… Ecostruxure Cybersecurity Admin Expert 2.4+ Fix from $1,9502023-01-30 HIGH 8.1 CVE-2020-36659 In Apache::Session::Browseable before 1.3.6, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backends, bec… Apache\ 1.3.6+ Fix from $1,9502023-01-27 HIGH 8.1 CVE-2020-36658 In Apache::Session::LDAP before 0.5, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backends, because the… Apache\ 0.5+ Fix from $1,9502023-01-27 HIGH 7.4 CVE-2023-0509 Improper Certificate Validation in GitHub repository pyload/pyload prior to 0.5.0b3.dev44. Pyload Ng 0.5.0b3.dev44 / 2023-01-25+ Fix from $1,9502023-01-26 HIGH 7.0 CVE-2023-23690 Cloud Mobility for Dell EMC Storage, versions 1.3.0.X and below contains an Improper Check for Certificate Revocation vulnerability. A threat actor d… Cloud Mobility For Dell Emc Storage 1.3.4.0+ Fix from $1,9502023-01-19 HIGH 8.8 CVE-2022-42979EPSS 24% Information disclosure due to an insecure hostname validation in the RYDE application 5.8.43 for Android and iOS allows attackers to take over an acc… Ryde Mitigation only Fix from $1,9502023-01-06 HIGH 7.5 CVE-2022-45197 Slixmpp before 1.8.3 lacks SSL Certificate hostname validation in XMLStream, allowing an attacker to pose as any server in the eyes of Slixmpp. Slixmpp 1.8.3+ Fix from $1,9502022-12-25 MEDIUM 6.5 CVE-2022-45419 If the user added a security exception for an invalid TLS certificate, opened an ongoing TLS connection with a server that used that certificate, and… Firefox 107.0+ Fix from $1,6002022-12-22 HIGH 8.1 CVE-2022-34469 When a TLS Certificate error occurs on a domain protected by the HSTS header, the browser should not allow the user to bypass the certificate error. … Firefox 102.0+ Fix from $1,9502022-12-22 MEDIUM 6.5 CVE-2022-22747 After accepting an untrusted certificate, handling an empty pkcs7 sequence as part of the certificate data could have lead to a crash. This crash is … Firefox 91.5 / 96.0+ Fix from $1,6002022-12-22 MEDIUM 5.4 CVE-2022-1197 When importing a revoked key that specified key compromise as the revocation reason, Thunderbird did not update the existing copy of the key that was… Thunderbird 91.8+ Fix from $1,6002022-12-22 MEDIUM 6.5 CVE-2022-1834 When displaying the sender of an email, and the sender name contained the Braille Pattern Blank space character multiple times, Thunderbird would hav… Thunderbird 91.10+ Fix from $1,6002022-12-22 MEDIUM 5.9 CVE-2022-32531 The Apache Bookkeeper Java Client (before 4.14.6 and also 4.15.0) does not close the connection to the bookkeeper server when TLS hostname verificati… Bookkeeper 4.14.6+ Fix from $1,6002022-12-15 MEDIUM 6.5 CVE-2022-46153 Traefik is an open source HTTP reverse proxy and load balancer. In affected versions there is a potential vulnerability in Traefik managing TLS conne… Traefik 2.9.6+ Fix from $1,6002022-12-08 CRITICAL 9.1 CVE-2022-43705 In Botan before 2.19.3, it is possible to forge OCSP responses due to a certificate verification error. This issue was introduced in Botan 1.11.34 (N… Botan 2.19.3+ Fix from $2,3002022-11-27 HIGH 7.5 CVE-2022-45391 Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.143 and earlier globally and unconditionally disables SSL/TLS certificate and hostname v… Ns Nd Integration Performance Publisher 4.8.0.146+ Fix from $1,9502022-11-15 HIGH 7.5 CVE-2022-38666 Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.146 and earlier unconditionally disables SSL/TLS certificate and hostname validation for… Ns Nd Integration Performance Publisher after 4.8.0.146 Fix from $1,9502022-11-15 HIGH 7.5 CVE-2022-20960 A vulnerability in Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated remote attacker to cause a denial o… Email Security Appliance 14.2.1-015 / 14.3.0-020+ Fix from $1,9502022-11-04 HIGH 8.1 CVE-2022-33684 The Apache Pulsar C++ Client does not verify peer TLS certificates when making HTTPS calls for the OAuth2.0 Client Credential Flow, even when tlsAllo… Pulsar 2.7.5 / 2.8.4+ Fix from $1,9502022-11-04 CRITICAL 9.8 CVE-2022-42813 A certificate validation issue existed in the handling of WKWebView. This issue was addressed with improved validation. This issue is fixed in tvOS 1… Ipados 9.1 / 13.0+ Fix from $2,3002022-11-01 MEDIUM 5.3 CVE-2022-41316 HashiCorp Vault and Vault Enterprise’s TLS certificate auth method did not initially load the optionally configured CRL issued by the role's CA into … Vault 1.9.10 / 1.10.7+ Fix from $1,6002022-10-12 HIGH 7.4 CVE-2022-40147 A vulnerability has been identified in Industrial Edge Management (All versions < V1.5.1). The affected software does not properly validate the serve… Industrial Edge Management 1.5.1+ Fix from $1,9502022-10-11 HIGH 7.8 CVE-2022-41747 An improper certification validation vulnerability in Trend Micro Apex One agents could allow a local attacker to load a DLL file with system service… Apex One Patch available Fix from $1,9502022-10-10 MEDIUM 5.9 CVE-2022-39264 nheko is a desktop client for the Matrix communication application. All versions below 0.10.2 are vulnerable homeservers inserting malicious secrets,… Fedora 0.10.2+ Fix from $1,6002022-09-28 MEDIUM 5.9 CVE-2021-45035 Velneo vClient on its 28.1.3 version, does not correctly check the certificate of authenticity by default. This could allow an attacker that has acce… Vclient Mitigation only Fix from $1,6002022-09-23 MEDIUM 5.9 CVE-2022-33681 Delayed TLS hostname verification in the Pulsar Java Client and the Pulsar Proxy make each client vulnerable to a man in the middle attack. Connectio… Pulsar 2.7.5 / 2.8.4+ Fix from $1,6002022-09-23 MEDIUM 5.9 CVE-2022-33682 TLS hostname verification cannot be enabled in the Pulsar Broker's Java Client, the Pulsar Broker's Java Admin Client, the Pulsar WebSocket Proxy's J… Pulsar 2.7.5 / 2.8.4+ Fix from $1,6002022-09-23