Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 9.8
CVE-2022-32563
An issue was discovered in Couchbase Sync Gateway 3.x before 3.0.2. Admin credentials are not verified when using X.509 client-certificate authentica…
Sync Gateway
3.0.2+
HIGH 8.8
CVE-2022-26493
Xecurify's miniOrange Premium, Standard, and Enterprise Drupal SAML SP modules possess an authentication and authorization bypass vulnerability. An a…
Saml Sp 2.0 Single Sign On
after 8.x-2.24
HIGH 7.5
CVE-2022-27782
libcurl would reuse a previously created connection even when a TLS or SSHrelated option had been changed that should have prohibited reuse.libcurl k…
Curl
7.83.1 / 8.2.12+
MEDIUM 5.9
CVE-2022-26491
An issue was discovered in Pidgin before 2.14.9. A remote attacker who can spoof DNS responses can redirect a client connection to a malicious server…
Debian Linux
2.14.9+
HIGH 7.5
CVE-2020-26184
Dell BSAFE Micro Edition Suite, versions prior to 4.5.1, contain an Improper Certificate Validation vulnerability.
HTTP Server
4.5.1+
MEDIUM 5.5
CVE-2022-26766
A certificate parsing issue was addressed with improved checks. This issue is fixed in tvOS 15.5, iOS 15.5 and iPadOS 15.5, Security Update 2022-004 …
Ipados
8.6 / 10.15.7+
MEDIUM 5.3
CVE-2022-22306
An improper certificate validation vulnerability [CWE-295] in FortiOS 6.0.0 through 6.0.14, 6.2.0 through 6.2.10, 6.4.0 through 6.4.8, 7.0.0 may allo…
Fortios
6.4.9+
HIGH 7.5
CVE-2022-29222
Pion DTLS is a Go implementation of Datagram Transport Layer Security. Prior to version 2.1.5, a DTLS Client could provide a Certificate that it does…
Dtls
2.1.5+
HIGH 7.5
CVE-2022-22787
The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.10.0 fails to properly validate the hostname during a ser…
Meetings
5.10.0+
MEDIUM 5.3
CVE-2021-29726
IBM Sterling Secure Proxy 6.0.3 and IBM Secure External Authentication Server 6.0.3 does not properly ensure that a certificate is actually associate…
Secure External Authentication Server
Patch available
MEDIUM 5.9
CVE-2013-10001
A vulnerability was found in HTC One/Sense 4.x. It has been rated as problematic. Affected by this issue is the certification validation of the mail …
Mail
Mitigation only
MEDIUM 5.9
CVE-2021-27768
Using the ability to perform a Man-in-the-Middle (MITM) attack, which indicates a lack of hostname verification, sensitive account information was ab…
Verse
12.0.9+
HIGH 8.8
CVE-2022-26923 KEVEPSS 83%
Active Directory Domain Services Elevation of Privilege Vulnerability
Windows 10 1507
10.0.10240.19297 / 10.0.14393.5850+
HIGH 7.5
CVE-2022-24901
Improper validation of the Apple certificate URL in the Apple Game Center authentication adapter allows attackers to bypass authentication, making th…
Parse Server
4.10.10 / 5.2.1+
MEDIUM 5.3
CVE-2022-1343
The function `OCSP_basic_verify` verifies the signer certificate on an OCSP response. In the case where the (non-default) flag OCSP_NOCHECKS is used …
OpenSSL
3.0.3+
MEDIUM 6.5
CVE-2021-3898
Versions of Motorola Ready For and Motorola Device Help Android applications prior to 2021-04-08 do not properly verify the server certificate which …
Device Help
2021-04-08+
HIGH 7.5
CVE-2022-27536
Certificate.Verify in crypto/x509 in Go 1.18.x before 1.18.1 can be caused to panic on macOS when presented with certain malformed certificates. This…
Go
1.18.1+
HIGH 8.1
CVE-2022-22549
Dell PowerScale OneFS, 8.2.x-9.3.x, contains a Improper Certificate Validation. A unauthenticated remote attacker could potentially exploit this vuln…
Emc Powerscale Onefs
after 9.3.0
MEDIUM 6.7
CVE-2022-20071
In ccu, there is a possible escalation of privilege due to a missing certificate validation. This could lead to local escalation of privilege with Sy…
Android
Mitigation only
MEDIUM 5.9
CVE-2022-20081
In A-GPS, there is a possible man in the middle attack due to improper certificate validation. This could lead to remote information disclosure with …
Android
Mitigation only
HIGH 7.5
CVE-2022-28142
Jenkins Proxmox Plugin 0.6.0 and earlier disables SSL/TLS certificate validation globally for the Jenkins controller JVM when configured to ignore SS…
Proxmox
after 0.6.0
MEDIUM 6.8
CVE-2022-0123
An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. GitLab does not val…
GitLab
14.4.5 / 14.5.3+
CRITICAL 9.1
CVE-2021-45490
The client applications in 3CX on Windows, the 3CX app for iOS, and the 3CX application for Android through 2022-03-17 lack SSL certificate validatio…
3cx
after 2022-03-17
HIGH 8.1
CVE-2022-0759
A flaw was found in all versions of kubeclient up to (but not including) v4.9.3, the Ruby client for Kubernetes REST API, in the way it parsed kubeco…
Kubeclient
4.9.3+
HIGH 7.4
CVE-2021-3618
ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocols but using compatible certif…
Nginx
1.21.0 / 3.0.4+
MEDIUM 6.5
CVE-2022-25243
"Vault and Vault Enterprise 1.8.0 through 1.8.8, and 1.9.3 allowed the PKI secrets engine under certain configurations to issue wildcard certificates…
Vault
1.8.9 / 1.9.4+
HIGH 7.5
CVE-2021-3698
A flaw was found in Cockpit in versions prior to 260 in the way it handles the certificate verification performed by the System Security Services Dae…
Enterprise Linux
260+
MEDIUM 5.9
CVE-2021-42017
A vulnerability has been identified in RUGGEDCOM i800, RUGGEDCOM i801, RUGGEDCOM i802, RUGGEDCOM i803, RUGGEDCOM M2100, RUGGEDCOM M2100F, RUGGEDCOM M…
Ruggedcom Ros
5.6.0+
MEDIUM 5.5
CVE-2022-22946
In spring cloud gateway versions prior to 3.1.1+ , applications that are configured to enable HTTP2 and no key store or trusted certificates are set …
Spring Cloud Gateway
Patch available
HIGH 7.4
CVE-2021-44531EPSS 8%
Accepting arbitrary Subject Alternative Name (SAN) types, unless a PKI is specifically defined to use a particular SAN type, can result in bypassing …
Node.js
12.22.9 / 14.18.3+