Vulnerability index

Browse CVEs

1,354 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Certificate ValidationCWE-295 × clear
MEDIUM 5.9 CVE-2022-33683 Apache Pulsar Brokers and Proxies create an internal Pulsar Admin Client that does not verify peer TLS certificates, even when tlsAllowInsecureConnec… Pulsar 2.7.5 / 2.8.4+ Fix from $1,6002022-09-23 HIGH 8.1 CVE-2022-41244 Jenkins View26 Test-Reporting Plugin 1.0.7 and earlier does not perform hostname validation when connecting to the configured View26 server that coul… View26 Test Reporting after 1.0.7 Fix from $1,9502022-09-21 HIGH 8.1 CVE-2022-41243 Jenkins SmallTest Plugin 1.0.4 and earlier does not perform hostname validation when connecting to the configured View26 server that could be abused … Smalltest after 1.0.4 Fix from $1,9502022-09-21 HIGH 7.8 CVE-2022-29908 The folioupdate service in Fabasoft Cloud Enterprise Client 22.4.0043 allows Local Privilege Escalation. Fabasoft Cloud Enterprise Client No fix yet Fix from $1,9502022-09-19 CRITICAL 9.8 CVE-2022-34831 An issue was discovered in Keyfactor PrimeKey EJBCA before 7.9.0, related to possible inconsistencies in DNS identifiers submitted in an ACME order a… Ejbca 7.9.0+ Fix from $2,3002022-09-14 HIGH 8.1 CVE-2022-36173 FreshService macOS Agent < 4.4.0 and FreshServce Linux Agent < 3.4.0 are vulnerable to TLS Man-in-The-Middle via the FreshAgent client and scheduled … Freshservice Agent 2.12.0 / 3.4.0+ Fix from $1,9502022-09-12 MEDIUM 6.5 CVE-2022-1632 An Improper Certificate Validation attack was found in Openshift. A re-encrypt Route with destinationCACertificate explicitly set to the default serv… Ansible Automation Platform Mitigation only Fix from $1,6002022-09-01 HIGH 7.4 CVE-2022-2996 A flaw was found in the python-scciclient when making an HTTPS connection to a server where the server's certificate would not be verified. This issu… Python Scciclient Patch available Fix from $1,9502022-09-01 HIGH 8.1 CVE-2021-43766 Odyssey passes to server unencrypted bytes from man-in-the-middle When Odyssey is configured to use certificate Common Name for client authentication… Odyssey Mitigation only Fix from $1,9502022-08-25 MEDIUM 5.9 CVE-2021-43767 Odyssey passes to client unencrypted bytes from man-in-the-middle When Odyssey storage is configured to use the PostgreSQL server using 'trust' authe… PostgreSQL 9.6.24 / 10.19+ Fix from $1,6002022-08-25 MEDIUM 5.4 CVE-2020-35509 A flaw was found in keycloak affecting versions 11.0.3 and 12.0.0. An expired certificate would be accepted by the direct-grant authenticator because… Keycloak Mitigation only Fix from $1,6002022-08-23 CRITICAL 9.8 CVE-2022-37437 When using Ingest Actions to configure a destination that resides on Amazon Simple Storage Service (S3) in Splunk Web, TLS certificate validation is … Splunk Mitigation only Fix from $2,3002022-08-16 CRITICAL 9.1 CVE-2022-34865 In BIG-IP Versions 15.1.x before 15.1.6.1, 14.1.x before 14.1.5, and all versions of 13.1.x, Traffic Intelligence feeds, which use HTTPS, do not veri… Big Ip Access Policy Manager 14.1.5 / 15.1.6.1+ Fix from $2,3002022-08-04 CRITICAL 9.8 CVE-2022-31183 fs2 is a compositional, streaming I/O library for Scala. When establishing a server-mode `TLSSocket` using `fs2-io` on Node.js, the parameter `reques… Fs2 3.2.11+ Fix from $2,3002022-08-01 HIGH 8.1 CVE-2022-1805 When connecting to Amazon Workspaces, the SHA256 presented by AWS connection provisioner is not fully verified by Zero Clients. The issue could be ex… Tera2 Pcoip Zero Client Firmware 22.01.5+ Fix from $1,9502022-07-28 HIGH 8.1 CVE-2022-36881 Jenkins Git client Plugin 3.11.0 and earlier does not perform SSH host key verification when connecting to Git repositories via SSH, enabling man-in-… Git Client after 3.11.0 Fix from $1,9502022-07-27 HIGH 7.5 CVE-2022-26305 An Improper Certificate Validation vulnerability in LibreOffice existed where determining if a macro was signed by a trusted author was done by only … Libreoffice 7.2.7 / 7.3.2+ Fix from $1,9502022-07-25 HIGH 7.4 CVE-2022-20860 A vulnerability in the SSL/TLS implementation of Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to alter communications with a… Nexus Dashboard 2.2+ Fix from $1,9502022-07-21 HIGH 7.5 CVE-2021-29755 IBM QRadar SIEM 7.3, 7.4, and 7.5 does not preform proper certificate validation for some inter-host communications. IBM X-Force ID: 202015. Qradar Security Information And Event Manager 7.3.3 / 7.4.3+ Fix from $1,9502022-07-20 MEDIUM 5.4 CVE-2021-22131 A improper validation of certificate with host mismatch in Fortinet FortiTokenAndroid version 5.0.3 and below, Fortinet FortiTokeniOS version 5.2.0 a… Fortitoken Mobile Patch available Fix from $1,6002022-07-18 HIGH 7.5 CVE-2020-16093 In LemonLDAP::NG (aka lemonldap-ng) through 2.0.8, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backend… Debian Linux after 2.0.8 Fix from $1,9502022-07-18 MEDIUM 6.5 CVE-2022-32210 `Undici.ProxyAgent` never verifies the remote server's certificate, and always exposes all request & response data to the proxy. This unexpectedly me… Undici 5.5.1+ Fix from $1,6002022-07-14 CRITICAL 9.6 CVE-2022-31105 Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo CD starting with version 0.4.0 and prior to 2.2.11, 2.3.6, and 2.4.5 i… Argo Cd 2.2.11 / 2.3.6+ Fix from $2,3002022-07-12 MEDIUM 5.9 CVE-2022-20813 Multiple vulnerabilities in the API and in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication S… Expressway Mitigation only Fix from $1,6002022-07-06 CRITICAL 9.1 CVE-2014-8164 A insecure configuration for certificate verification (http.verify_mode = OpenSSL::SSL::VERIFY_NONE) may lead to verification bypass in Red Hat Cloud… Cloudforms Management Engine Mitigation only Fix from $2,3002022-07-06 HIGH 7.5 CVE-2022-31083 Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 4.10.11 and 5.2.2, the cert… Parse Server 4.10.11 / 5.2.2+ Fix from $1,9502022-06-17 HIGH 8.1 CVE-2022-32156 In Splunk Enterprise and Universal Forwarder versions before 9.0, the Splunk command-line interface (CLI) did not validate TLS certificates while con… Splunk 9.0+ Fix from $1,9502022-06-15 CRITICAL 9.1 CVE-2022-32151 The httplib and urllib Python libraries that Splunk shipped with Splunk Enterprise did not validate certificates using the certificate authority (CA)… Splunk 8.2.2203 / 9.0+ Fix from $2,3002022-06-15 HIGH 7.2 CVE-2022-32152 Splunk Enterprise peers in Splunk Enterprise versions before 9.0 and Splunk Cloud Platform versions before 8.2.2203 did not validate the TLS certific… Splunk 8.2.2203 / 9.0+ Fix from $1,9502022-06-15 HIGH 8.1 CVE-2022-32153 Splunk Enterprise peers in Splunk Enterprise versions before 9.0 and Splunk Cloud Platform versions before 8.2.2203 did not validate the TLS certific… Splunk 8.2.2203 / 9.0+ Fix from $1,9502022-06-15