Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.3
CVE-2021-44532EPSS 10%
Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 converts SANs (Subject Alternative Names) to a string format. It uses this string to check peer…
Node.js
12.22.9 / 14.18.3+
MEDIUM 5.3
CVE-2021-44533EPSS 9%
Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 did not handle multi-value Relative Distinguished Names correctly. Attackers could craft certif…
Node.js
8.0.29 / 12.22.9+
MEDIUM 6.5
CVE-2022-25638
In wolfSSL before 5.2.0, certificate validation may be bypassed during attempted authentication by a TLS 1.3 client to a TLS 1.3 server. This occurs …
Wolfssl
5.2.0+
HIGH 7.5
CVE-2022-25640
In wolfSSL before 5.2.0, a TLS 1.3 server cannot properly enforce a requirement for mutual authentication. A client can simply omit the certificate_v…
Wolfssl
5.2.0+
HIGH 7.5
CVE-2021-25636
LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occur…
Fedora
7.2.5+
CRITICAL 9.8
CVE-2022-21654
Envoy is an open source edge and service proxy, designed for cloud-native applications. Envoy's tls allows re-use when some cert validation settings …
Envoy
1.18.6 / 1.19.3+
MEDIUM 5.9
CVE-2022-21656
Envoy is an open source edge and service proxy, designed for cloud-native applications. The default_validator.cc implementation used to implement the…
Envoy
1.20.2+
MEDIUM 6.5
CVE-2022-21657
Envoy is an open source edge and service proxy, designed for cloud-native applications. In affected versions Envoy does not restrict the set of certi…
Envoy
1.18.6 / 1.19.3+
CRITICAL 9.8
CVE-2021-29656
Pexip Infinity Connect before 1.8.0 mishandles TLS certificate validation. The allow list is not properly checked.
Infinity Connect
1.8.0+
HIGH 7.5
CVE-2022-23632
Traefik is an HTTP reverse proxy and load balancer. Prior to version 2.6.1, Traefik skips the router transport layer security (TLS) configuration whe…
Traefik
2.6.1+
CRITICAL 9.8
CVE-2022-22885
Hutool v5.7.18's HttpRequest was discovered to ignore all TLS/SSL certificate validation.
Hutool
No fix yet
MEDIUM 5.9
CVE-2022-24968
In Mellium mellium.im/xmpp through 0.21.0, an attacker capable of spoofing DNS TXT records can redirect a WebSocket connection request to a server un…
Xmpp
0.21.1+
HIGH 8.0
CVE-2022-20703 KEVEPSS 9%
Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Ex…
Rv340 Firmware
after 1.0.03.24
MEDIUM 5.9
CVE-2022-24319
A CWE-295: Improper Certificate Validation vulnerability exists that could allow a Man-in-theMiddle attack when communications between the client and…
Clearscada
Patch available
MEDIUM 5.9
CVE-2022-24320
A CWE-295: Improper Certificate Validation vulnerability exists that could allow a Man-in-theMiddle attack when communications between the client and…
Clearscada
Patch available
MEDIUM 6.8
CVE-2022-20034
In Preloader XFLASH, there is a possible escalation of privilege due to an improper certificate validation. This could lead to local escalation of pr…
Android
Mitigation only
HIGH 8.1
CVE-2021-21959
A misconfiguration exists in the MQTTS functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. This misconfiguration significantly simplifie…
Seaconnect 370w Firmware
No fix yet
CRITICAL 9.8
CVE-2021-40855
The EU Technical Specifications for Digital COVID Certificates before 1.1 mishandle certificate governance. A non-production public key certificate c…
Technical Specifications For Digital Covid Certificates
1.1+
HIGH 7.4
CVE-2022-22156
An Improper Certificate Validation weakness in the Juniper Networks Junos OS allows an attacker to perform Person-in-the-Middle (PitM) attacks when a…
Junos
after 18.3
HIGH 7.8
CVE-2022-21836
Windows Certificate Spoofing Vulnerability
Windows 10
No fix yet
HIGH 7.4
CVE-2021-44273
e2guardian v5.4.x <= v5.4.3r is affected by missing SSL certificate validation in the SSL MITM engine. In standalone mode (i.e., acting as a proxy or…
E2guardian
after 5.4.3r
HIGH 7.5
CVE-2021-41028
A combination of a use of hard-coded cryptographic key vulnerability [CWE-321] in FortiClientEMS 7.0.1 and below, 6.4.6 and below and an improper cer…
Forticlient
after 6.4.6
CRITICAL 9.8
CVE-2021-43882
Microsoft Defender for IoT Remote Code Execution Vulnerability
Defender For Iot
10.5.3+
HIGH 7.4
CVE-2021-44549
Apache Sling Commons Messaging Mail provides a simple layer on top of JavaMail/Jakarta Mail for OSGi to send mails via SMTPS. To reduce the risk of "…
Sling Commons Messaging Mail
Mitigation only
HIGH 7.4
CVE-2021-42027
A vulnerability has been identified in SINUMERIK Edge (All versions < V3.2). The affected software does not properly validate the server certificate …
Sinumerik Edge
3.2+
MEDIUM 5.9
CVE-2020-4496
The IBM Spectrum Protect Plus 10.1.0.0 through 10.1.8.x server connection to an IBM Spectrum Protect Plus workload agent is subject to a man-in-the-m…
Spectrum Protect Plus
after 10.1.8.1
HIGH 7.4
CVE-2021-34599
Affected versions of CODESYS Git in Versions prior to V1.1.0.0 lack certificate validation in HTTPS handshakes. CODESYS Git does not implement certif…
Git
1.1.0.0+
HIGH 8.8
CVE-2021-40828
Connections initialized by the AWS IoT Device SDK v2 for Java (versions prior to 1.3.3), Python (versions prior to 1.5.18), C++ (versions prior to 1.…
Amazon Web Services Aws C Io
0.9.13 / 1.3.3+
HIGH 8.8
CVE-2021-40829
Connections initialized by the AWS IoT Device SDK v2 for Java (versions prior to 1.4.2), Python (versions prior to 1.6.1), C++ (versions prior to 1.1…
Amazon Web Services Internet Of Things Device Software Development Kit V2
1.4.2 / 1.5.3+
HIGH 8.8
CVE-2021-40830
The AWS IoT Device SDK v2 for Java, Python, C++ and Node.js appends a user supplied Certificate Authority (CA) to the root CAs instead of overriding …
Amazon Web Services Aws C Io
1.5.0 / 1.5.3+