Vulnerability index

Browse CVEs

1,354 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Certificate ValidationCWE-295 × clear
CRITICAL 9.8 CVE-2022-32563 An issue was discovered in Couchbase Sync Gateway 3.x before 3.0.2. Admin credentials are not verified when using X.509 client-certificate authentica… Sync Gateway 3.0.2+ Fix from $2,3002022-06-10 HIGH 8.8 CVE-2022-26493 Xecurify's miniOrange Premium, Standard, and Enterprise Drupal SAML SP modules possess an authentication and authorization bypass vulnerability. An a… Saml Sp 2.0 Single Sign On after 8.x-2.24 Fix from $1,9502022-06-03 HIGH 7.5 CVE-2022-27782 libcurl would reuse a previously created connection even when a TLS or SSHrelated option had been changed that should have prohibited reuse.libcurl k… Curl 7.83.1 / 8.2.12+ Fix from $1,9502022-06-02 MEDIUM 5.9 CVE-2022-26491 An issue was discovered in Pidgin before 2.14.9. A remote attacker who can spoof DNS responses can redirect a client connection to a malicious server… Debian Linux 2.14.9+ Fix from $1,6002022-06-02 HIGH 7.5 CVE-2020-26184 Dell BSAFE Micro Edition Suite, versions prior to 4.5.1, contain an Improper Certificate Validation vulnerability. HTTP Server 4.5.1+ Fix from $1,9502022-06-01 MEDIUM 5.5 CVE-2022-26766 A certificate parsing issue was addressed with improved checks. This issue is fixed in tvOS 15.5, iOS 15.5 and iPadOS 15.5, Security Update 2022-004 … Ipados 8.6 / 10.15.7+ Fix from $1,6002022-05-26 MEDIUM 5.3 CVE-2022-22306 An improper certificate validation vulnerability [CWE-295] in FortiOS 6.0.0 through 6.0.14, 6.2.0 through 6.2.10, 6.4.0 through 6.4.8, 7.0.0 may allo… Fortios 6.4.9+ Fix from $1,6002022-05-24 HIGH 7.5 CVE-2022-29222 Pion DTLS is a Go implementation of Datagram Transport Layer Security. Prior to version 2.1.5, a DTLS Client could provide a Certificate that it does… Dtls 2.1.5+ Fix from $1,9502022-05-21 HIGH 7.5 CVE-2022-22787 The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.10.0 fails to properly validate the hostname during a ser… Meetings 5.10.0+ Fix from $1,9502022-05-18 MEDIUM 5.3 CVE-2021-29726 IBM Sterling Secure Proxy 6.0.3 and IBM Secure External Authentication Server 6.0.3 does not properly ensure that a certificate is actually associate… Secure External Authentication Server Patch available Fix from $1,6002022-05-17 MEDIUM 5.9 CVE-2013-10001 A vulnerability was found in HTC One/Sense 4.x. It has been rated as problematic. Affected by this issue is the certification validation of the mail … Mail Mitigation only Fix from $1,6002022-05-17 MEDIUM 5.9 CVE-2021-27768 Using the ability to perform a Man-in-the-Middle (MITM) attack, which indicates a lack of hostname verification, sensitive account information was ab… Verse 12.0.9+ Fix from $1,6002022-05-12 HIGH 8.8 CVE-2022-26923 KEVEPSS 83% Active Directory Domain Services Elevation of Privilege Vulnerability Windows 10 1507 10.0.10240.19297 / 10.0.14393.5850+ Fix from $1,9502022-05-10 HIGH 7.5 CVE-2022-24901 Improper validation of the Apple certificate URL in the Apple Game Center authentication adapter allows attackers to bypass authentication, making th… Parse Server 4.10.10 / 5.2.1+ Fix from $1,9502022-05-04 MEDIUM 5.3 CVE-2022-1343 The function `OCSP_basic_verify` verifies the signer certificate on an OCSP response. In the case where the (non-default) flag OCSP_NOCHECKS is used … OpenSSL 3.0.3+ Fix from $1,6002022-05-03 MEDIUM 6.5 CVE-2021-3898 Versions of Motorola Ready For and Motorola Device Help Android applications prior to 2021-04-08 do not properly verify the server certificate which … Device Help 2021-04-08+ Fix from $1,6002022-04-22 HIGH 7.5 CVE-2022-27536 Certificate.Verify in crypto/x509 in Go 1.18.x before 1.18.1 can be caused to panic on macOS when presented with certain malformed certificates. This… Go 1.18.1+ Fix from $1,9502022-04-20 HIGH 8.1 CVE-2022-22549 Dell PowerScale OneFS, 8.2.x-9.3.x, contains a Improper Certificate Validation. A unauthenticated remote attacker could potentially exploit this vuln… Emc Powerscale Onefs after 9.3.0 Fix from $1,9502022-04-12 MEDIUM 6.7 CVE-2022-20071 In ccu, there is a possible escalation of privilege due to a missing certificate validation. This could lead to local escalation of privilege with Sy… Android Mitigation only Fix from $1,6002022-04-11 MEDIUM 5.9 CVE-2022-20081 In A-GPS, there is a possible man in the middle attack due to improper certificate validation. This could lead to remote information disclosure with … Android Mitigation only Fix from $1,6002022-04-11 HIGH 7.5 CVE-2022-28142 Jenkins Proxmox Plugin 0.6.0 and earlier disables SSL/TLS certificate validation globally for the Jenkins controller JVM when configured to ignore SS… Proxmox after 0.6.0 Fix from $1,9502022-03-29 MEDIUM 6.8 CVE-2022-0123 An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. GitLab does not val… GitLab 14.4.5 / 14.5.3+ Fix from $1,6002022-03-28 CRITICAL 9.1 CVE-2021-45490 The client applications in 3CX on Windows, the 3CX app for iOS, and the 3CX application for Android through 2022-03-17 lack SSL certificate validatio… 3cx after 2022-03-17 Fix from $2,3002022-03-28 HIGH 8.1 CVE-2022-0759 A flaw was found in all versions of kubeclient up to (but not including) v4.9.3, the Ruby client for Kubernetes REST API, in the way it parsed kubeco… Kubeclient 4.9.3+ Fix from $1,9502022-03-25 HIGH 7.4 CVE-2021-3618 ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocols but using compatible certif… Nginx 1.21.0 / 3.0.4+ Fix from $1,9502022-03-23 MEDIUM 6.5 CVE-2022-25243 "Vault and Vault Enterprise 1.8.0 through 1.8.8, and 1.9.3 allowed the PKI secrets engine under certain configurations to issue wildcard certificates… Vault 1.8.9 / 1.9.4+ Fix from $1,6002022-03-10 HIGH 7.5 CVE-2021-3698 A flaw was found in Cockpit in versions prior to 260 in the way it handles the certificate verification performed by the System Security Services Dae… Enterprise Linux 260+ Fix from $1,9502022-03-10 MEDIUM 5.9 CVE-2021-42017 A vulnerability has been identified in RUGGEDCOM i800, RUGGEDCOM i801, RUGGEDCOM i802, RUGGEDCOM i803, RUGGEDCOM M2100, RUGGEDCOM M2100F, RUGGEDCOM M… Ruggedcom Ros 5.6.0+ Fix from $1,6002022-03-08 MEDIUM 5.5 CVE-2022-22946 In spring cloud gateway versions prior to 3.1.1+ , applications that are configured to enable HTTP2 and no key store or trusted certificates are set … Spring Cloud Gateway Patch available Fix from $1,6002022-03-04 HIGH 7.4 CVE-2021-44531EPSS 8% Accepting arbitrary Subject Alternative Name (SAN) types, unless a PKI is specifically defined to use a particular SAN type, can result in bypassing … Node.js 12.22.9 / 14.18.3+ Fix from $1,9502022-02-24