Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.9
CVE-2022-33683
Apache Pulsar Brokers and Proxies create an internal Pulsar Admin Client that does not verify peer TLS certificates, even when tlsAllowInsecureConnec…
Pulsar
2.7.5 / 2.8.4+
HIGH 8.1
CVE-2022-41244
Jenkins View26 Test-Reporting Plugin 1.0.7 and earlier does not perform hostname validation when connecting to the configured View26 server that coul…
View26 Test Reporting
after 1.0.7
HIGH 8.1
CVE-2022-41243
Jenkins SmallTest Plugin 1.0.4 and earlier does not perform hostname validation when connecting to the configured View26 server that could be abused …
Smalltest
after 1.0.4
HIGH 7.8
CVE-2022-29908
The folioupdate service in Fabasoft Cloud Enterprise Client 22.4.0043 allows Local Privilege Escalation.
Fabasoft Cloud Enterprise Client
No fix yet
CRITICAL 9.8
CVE-2022-34831
An issue was discovered in Keyfactor PrimeKey EJBCA before 7.9.0, related to possible inconsistencies in DNS identifiers submitted in an ACME order a…
Ejbca
7.9.0+
HIGH 8.1
CVE-2022-36173
FreshService macOS Agent < 4.4.0 and FreshServce Linux Agent < 3.4.0 are vulnerable to TLS Man-in-The-Middle via the FreshAgent client and scheduled …
Freshservice Agent
2.12.0 / 3.4.0+
MEDIUM 6.5
CVE-2022-1632
An Improper Certificate Validation attack was found in Openshift. A re-encrypt Route with destinationCACertificate explicitly set to the default serv…
Ansible Automation Platform
Mitigation only
HIGH 7.4
CVE-2022-2996
A flaw was found in the python-scciclient when making an HTTPS connection to a server where the server's certificate would not be verified. This issu…
Python Scciclient
Patch available
HIGH 8.1
CVE-2021-43766
Odyssey passes to server unencrypted bytes from man-in-the-middle When Odyssey is configured to use certificate Common Name for client authentication…
Odyssey
Mitigation only
MEDIUM 5.9
CVE-2021-43767
Odyssey passes to client unencrypted bytes from man-in-the-middle When Odyssey storage is configured to use the PostgreSQL server using 'trust' authe…
PostgreSQL
9.6.24 / 10.19+
MEDIUM 5.4
CVE-2020-35509
A flaw was found in keycloak affecting versions 11.0.3 and 12.0.0. An expired certificate would be accepted by the direct-grant authenticator because…
Keycloak
Mitigation only
CRITICAL 9.8
CVE-2022-37437
When using Ingest Actions to configure a destination that resides on Amazon Simple Storage Service (S3) in Splunk Web, TLS certificate validation is …
Splunk
Mitigation only
CRITICAL 9.1
CVE-2022-34865
In BIG-IP Versions 15.1.x before 15.1.6.1, 14.1.x before 14.1.5, and all versions of 13.1.x, Traffic Intelligence feeds, which use HTTPS, do not veri…
Big Ip Access Policy Manager
14.1.5 / 15.1.6.1+
CRITICAL 9.8
CVE-2022-31183
fs2 is a compositional, streaming I/O library for Scala. When establishing a server-mode `TLSSocket` using `fs2-io` on Node.js, the parameter `reques…
Fs2
3.2.11+
HIGH 8.1
CVE-2022-1805
When connecting to Amazon Workspaces, the SHA256 presented by AWS connection provisioner is not fully verified by Zero Clients. The issue could be ex…
Tera2 Pcoip Zero Client Firmware
22.01.5+
HIGH 8.1
CVE-2022-36881
Jenkins Git client Plugin 3.11.0 and earlier does not perform SSH host key verification when connecting to Git repositories via SSH, enabling man-in-…
Git Client
after 3.11.0
HIGH 7.5
CVE-2022-26305
An Improper Certificate Validation vulnerability in LibreOffice existed where determining if a macro was signed by a trusted author was done by only …
Libreoffice
7.2.7 / 7.3.2+
HIGH 7.4
CVE-2022-20860
A vulnerability in the SSL/TLS implementation of Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to alter communications with a…
Nexus Dashboard
2.2+
HIGH 7.5
CVE-2021-29755
IBM QRadar SIEM 7.3, 7.4, and 7.5 does not preform proper certificate validation for some inter-host communications. IBM X-Force ID: 202015.
Qradar Security Information And Event Manager
7.3.3 / 7.4.3+
MEDIUM 5.4
CVE-2021-22131
A improper validation of certificate with host mismatch in Fortinet FortiTokenAndroid version 5.0.3 and below, Fortinet FortiTokeniOS version 5.2.0 a…
Fortitoken Mobile
Patch available
HIGH 7.5
CVE-2020-16093
In LemonLDAP::NG (aka lemonldap-ng) through 2.0.8, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backend…
Debian Linux
after 2.0.8
MEDIUM 6.5
CVE-2022-32210
`Undici.ProxyAgent` never verifies the remote server's certificate, and always exposes all request & response data to the proxy. This unexpectedly me…
Undici
5.5.1+
CRITICAL 9.6
CVE-2022-31105
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo CD starting with version 0.4.0 and prior to 2.2.11, 2.3.6, and 2.4.5 i…
Argo Cd
2.2.11 / 2.3.6+
MEDIUM 5.9
CVE-2022-20813
Multiple vulnerabilities in the API and in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication S…
Expressway
Mitigation only
CRITICAL 9.1
CVE-2014-8164
A insecure configuration for certificate verification (http.verify_mode = OpenSSL::SSL::VERIFY_NONE) may lead to verification bypass in Red Hat Cloud…
Cloudforms Management Engine
Mitigation only
HIGH 7.5
CVE-2022-31083
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 4.10.11 and 5.2.2, the cert…
Parse Server
4.10.11 / 5.2.2+
HIGH 8.1
CVE-2022-32156
In Splunk Enterprise and Universal Forwarder versions before 9.0, the Splunk command-line interface (CLI) did not validate TLS certificates while con…
Splunk
9.0+
CRITICAL 9.1
CVE-2022-32151
The httplib and urllib Python libraries that Splunk shipped with Splunk Enterprise did not validate certificates using the certificate authority (CA)…
Splunk
8.2.2203 / 9.0+
HIGH 7.2
CVE-2022-32152
Splunk Enterprise peers in Splunk Enterprise versions before 9.0 and Splunk Cloud Platform versions before 8.2.2203 did not validate the TLS certific…
Splunk
8.2.2203 / 9.0+
HIGH 8.1
CVE-2022-32153
Splunk Enterprise peers in Splunk Enterprise versions before 9.0 and Splunk Cloud Platform versions before 8.2.2203 did not validate the TLS certific…
Splunk
8.2.2203 / 9.0+