Vulnerability index

Browse CVEs

1,354 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Certificate ValidationCWE-295 × clear
MEDIUM 5.3 CVE-2021-44532EPSS 10% Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 converts SANs (Subject Alternative Names) to a string format. It uses this string to check peer… Node.js 12.22.9 / 14.18.3+ Fix from $1,6002022-02-24 MEDIUM 5.3 CVE-2021-44533EPSS 9% Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 did not handle multi-value Relative Distinguished Names correctly. Attackers could craft certif… Node.js 8.0.29 / 12.22.9+ Fix from $1,6002022-02-24 MEDIUM 6.5 CVE-2022-25638 In wolfSSL before 5.2.0, certificate validation may be bypassed during attempted authentication by a TLS 1.3 client to a TLS 1.3 server. This occurs … Wolfssl 5.2.0+ Fix from $1,6002022-02-24 HIGH 7.5 CVE-2022-25640 In wolfSSL before 5.2.0, a TLS 1.3 server cannot properly enforce a requirement for mutual authentication. A client can simply omit the certificate_v… Wolfssl 5.2.0+ Fix from $1,9502022-02-24 HIGH 7.5 CVE-2021-25636 LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occur… Fedora 7.2.5+ Fix from $1,9502022-02-24 CRITICAL 9.8 CVE-2022-21654 Envoy is an open source edge and service proxy, designed for cloud-native applications. Envoy's tls allows re-use when some cert validation settings … Envoy 1.18.6 / 1.19.3+ Fix from $2,3002022-02-22 MEDIUM 5.9 CVE-2022-21656 Envoy is an open source edge and service proxy, designed for cloud-native applications. The default_validator.cc implementation used to implement the… Envoy 1.20.2+ Fix from $1,6002022-02-22 MEDIUM 6.5 CVE-2022-21657 Envoy is an open source edge and service proxy, designed for cloud-native applications. In affected versions Envoy does not restrict the set of certi… Envoy 1.18.6 / 1.19.3+ Fix from $1,6002022-02-22 CRITICAL 9.8 CVE-2021-29656 Pexip Infinity Connect before 1.8.0 mishandles TLS certificate validation. The allow list is not properly checked. Infinity Connect 1.8.0+ Fix from $2,3002022-02-18 HIGH 7.5 CVE-2022-23632 Traefik is an HTTP reverse proxy and load balancer. Prior to version 2.6.1, Traefik skips the router transport layer security (TLS) configuration whe… Traefik 2.6.1+ Fix from $1,9502022-02-17 CRITICAL 9.8 CVE-2022-22885 Hutool v5.7.18's HttpRequest was discovered to ignore all TLS/SSL certificate validation. Hutool No fix yet Fix from $2,3002022-02-16 MEDIUM 5.9 CVE-2022-24968 In Mellium mellium.im/xmpp through 0.21.0, an attacker capable of spoofing DNS TXT records can redirect a WebSocket connection request to a server un… Xmpp 0.21.1+ Fix from $1,6002022-02-11 HIGH 8.0 CVE-2022-20703 KEVEPSS 9% Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Ex… Rv340 Firmware after 1.0.03.24 Fix from $1,9502022-02-10 MEDIUM 5.9 CVE-2022-24319 A CWE-295: Improper Certificate Validation vulnerability exists that could allow a Man-in-theMiddle attack when communications between the client and… Clearscada Patch available Fix from $1,6002022-02-09 MEDIUM 5.9 CVE-2022-24320 A CWE-295: Improper Certificate Validation vulnerability exists that could allow a Man-in-theMiddle attack when communications between the client and… Clearscada Patch available Fix from $1,6002022-02-09 MEDIUM 6.8 CVE-2022-20034 In Preloader XFLASH, there is a possible escalation of privilege due to an improper certificate validation. This could lead to local escalation of pr… Android Mitigation only Fix from $1,6002022-02-09 HIGH 8.1 CVE-2021-21959 A misconfiguration exists in the MQTTS functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. This misconfiguration significantly simplifie… Seaconnect 370w Firmware No fix yet Fix from $1,9502022-02-04 CRITICAL 9.8 CVE-2021-40855 The EU Technical Specifications for Digital COVID Certificates before 1.1 mishandle certificate governance. A non-production public key certificate c… Technical Specifications For Digital Covid Certificates 1.1+ Fix from $2,3002022-01-21 HIGH 7.4 CVE-2022-22156 An Improper Certificate Validation weakness in the Juniper Networks Junos OS allows an attacker to perform Person-in-the-Middle (PitM) attacks when a… Junos after 18.3 Fix from $1,9502022-01-19 HIGH 7.8 CVE-2022-21836 Windows Certificate Spoofing Vulnerability Windows 10 No fix yet Fix from $1,9502022-01-11 HIGH 7.4 CVE-2021-44273 e2guardian v5.4.x <= v5.4.3r is affected by missing SSL certificate validation in the SSL MITM engine. In standalone mode (i.e., acting as a proxy or… E2guardian after 5.4.3r Fix from $1,9502021-12-23 HIGH 7.5 CVE-2021-41028 A combination of a use of hard-coded cryptographic key vulnerability [CWE-321] in FortiClientEMS 7.0.1 and below, 6.4.6 and below and an improper cer… Forticlient after 6.4.6 Fix from $1,9502021-12-16 CRITICAL 9.8 CVE-2021-43882 Microsoft Defender for IoT Remote Code Execution Vulnerability Defender For Iot 10.5.3+ Fix from $2,3002021-12-15 HIGH 7.4 CVE-2021-44549 Apache Sling Commons Messaging Mail provides a simple layer on top of JavaMail/Jakarta Mail for OSGi to send mails via SMTPS. To reduce the risk of "… Sling Commons Messaging Mail Mitigation only Fix from $1,9502021-12-14 HIGH 7.4 CVE-2021-42027 A vulnerability has been identified in SINUMERIK Edge (All versions < V3.2). The affected software does not properly validate the server certificate … Sinumerik Edge 3.2+ Fix from $1,9502021-12-14 MEDIUM 5.9 CVE-2020-4496 The IBM Spectrum Protect Plus 10.1.0.0 through 10.1.8.x server connection to an IBM Spectrum Protect Plus workload agent is subject to a man-in-the-m… Spectrum Protect Plus after 10.1.8.1 Fix from $1,6002021-12-13 HIGH 7.4 CVE-2021-34599 Affected versions of CODESYS Git in Versions prior to V1.1.0.0 lack certificate validation in HTTPS handshakes. CODESYS Git does not implement certif… Git 1.1.0.0+ Fix from $1,9502021-12-01 HIGH 8.8 CVE-2021-40828 Connections initialized by the AWS IoT Device SDK v2 for Java (versions prior to 1.3.3), Python (versions prior to 1.5.18), C++ (versions prior to 1.… Amazon Web Services Aws C Io 0.9.13 / 1.3.3+ Fix from $1,9502021-11-23 HIGH 8.8 CVE-2021-40829 Connections initialized by the AWS IoT Device SDK v2 for Java (versions prior to 1.4.2), Python (versions prior to 1.6.1), C++ (versions prior to 1.1… Amazon Web Services Internet Of Things Device Software Development Kit V2 1.4.2 / 1.5.3+ Fix from $1,9502021-11-23 HIGH 8.8 CVE-2021-40830 The AWS IoT Device SDK v2 for Java, Python, C++ and Node.js appends a user supplied Certificate Authority (CA) to the root CAs instead of overriding … Amazon Web Services Aws C Io 1.5.0 / 1.5.3+ Fix from $1,9502021-11-23