Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.2
CVE-2021-40831
The AWS IoT Device SDK v2 for Java, Python, C++ and Node.js appends a user supplied Certificate Authority (CA) to the root CAs instead of overriding …
Amazon Web Services Aws C Io
1.5.0 / 1.6.0+
HIGH 8.1
CVE-2021-3935
When PgBouncer is configured to use "cert" authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first e…
Enterprise Linux
1.16.1+
MEDIUM 6.8
CVE-2021-23155
Improper validation of the cloud certificate chain in Mobile Client allows man-in-the-middle attack to impersonate the legitimate Command Centre Serv…
Command Centre Mobile Client
8.60.065+
HIGH 8.1
CVE-2021-23162
Improper validation of the cloud certificate chain in Mobile Connect allows man-in-the-middle attack to impersonate the legitimate Command Centre Ser…
Command Centre Mobile Connect
15.04.040+
MEDIUM 6.8
CVE-2021-23167
Improper certificate validation vulnerability in SMTP Client allows man-in-the-middle attack to retrieve sensitive information from the Command Centr…
Command Centre
8.30.1454 / 8.40.2063+
MEDIUM 5.5
CVE-2021-26320
Insufficient validation of the AMD SEV Signing Key (ASK) in the SEND_START command in the SEV Firmware may allow a local authenticated attacker to pe…
Epyc 7601 Firmware
Mitigation only
MEDIUM 6.5
CVE-2021-41019
An improper validation of certificate with host mismatch [CWE-297] vulnerability in FortiOS versions 6.4.6 and below may allow the connection to a ma…
Fortios
after 6.4.6
HIGH 7.5
CVE-2021-29737
IBM InfoSphere Data Flow Designer Engine (IBM InfoSphere Information Server 11.7 ) component has improper validation of the REST API server certifica…
Infosphere Information Server
Patch available
MEDIUM 6.7
CVE-2021-22278
A certificate validation vulnerability in PCM600 Update Manager allows attacker to get unwanted software packages to be installed on computer which h…
Update Manager
after 2.10
MEDIUM 6.5
CVE-2021-36756
CFEngine Enterprise 3.15.0 through 3.15.4 has Missing SSL Certificate Validation.
Cfengine
after 3.15.4
HIGH 7.5
CVE-2021-41611
An issue was discovered in Squid 5.0.6 through 5.1.x before 5.2. When validating an origin server or peer certificate, Squid may incorrectly classify…
Fedora
5.2+
HIGH 7.4
CVE-2021-20833
The SNKRDUNK Market Place App for iOS versions prior to 2.2.0 does not verify server certificate properly, which allows man-in-the-middle attackers t…
Snkrdunk
2.2.0+
HIGH 7.5
CVE-2021-25634
LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occur…
Debian Linux
7.0.6 / 7.1.2+
HIGH 7.5
CVE-2021-25633
LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occur…
Debian Linux
7.0.6 / 7.1.2+
HIGH 7.5
CVE-2021-35497
The FTL Server (tibftlserver) and Docker images containing tibftlserver components of TIBCO Software Inc.'s TIBCO ActiveSpaces - Community Edition, T…
Activespaces
Mitigation only
MEDIUM 5.9
CVE-2021-40713
Adobe Experience Manager version 6.5.9.0 (and earlier) is affected by a improper certificate validation vulnerability in the cold storage component. …
Experience Manager
after 6.5.9.0
CRITICAL 9.8
CVE-2021-33907
The Zoom Client for Meetings for Windows in all versions before 5.3.0 fails to properly validate the certificate information used to sign .msi files …
Meetings
5.3.0+
HIGH 7.5
CVE-2021-38864
IBM Security Verify Bridge 1.0.5.0 could allow a user to obtain sensitive information due to improper certificate validation. IBM X-Force ID: 208155.
Security Verify Bridge
1.0.7+
MEDIUM 5.5
CVE-2021-20435
IBM Security Verify Bridge 1.0.5.0 does not properly validate a certificate which could allow a local attacker to obtain sensitive information that c…
Security Verify Bridge
1.0.7+
CRITICAL 9.1
CVE-2021-33695
Potentially, SAP Cloud Connector, version - 2.0 communication with the backend is accepted without sufficient validation of the certificate.
Cloud Connector
Patch available
MEDIUM 5.3
CVE-2021-1837
A certificate validation issue was addressed. This issue is fixed in iOS 14.5 and iPadOS 14.5. An attacker in a privileged network position may be ab…
Ipados
14.5+
HIGH 8.8
CVE-2021-37218
HashiCorp Nomad and Nomad Enterprise Raft RPC layer allows non-server agents with a valid certificate signed by the same CA to access server-only fun…
Nomad
1.0.10 / 1.1.4+
HIGH 8.8
CVE-2021-37219
HashiCorp Consul and Consul Enterprise 1.10.1 Raft RPC layer allows non-server agents with a valid certificate signed by the same CA to access server…
Consul
1.8.15 / 1.9.9+
HIGH 7.5
CVE-2021-27018
The mechanism which performs certificate validation was discovered to have a flaw that resulted in certificates signed by an internal certificate aut…
Remediate
2.0.1+
MEDIUM 5.9
CVE-2020-36477
An issue was discovered in Mbed TLS before 2.24.0. The verification of X.509 certificates when matching the expected common name (the cn argument of …
Mbed Tls
2.24.0+
HIGH 7.5
CVE-2020-36478
An issue was discovered in Mbed TLS before 2.25.0 (and before 2.16.9 LTS and before 2.7.18 LTS). A NULL algorithm parameters entry looks identical to…
Debian Linux
2.2 / 2.7.18+
MEDIUM 5.9
CVE-2021-39365
In GNOME grilo though 0.3.13, grl-net-wc.c does not enable TLS certificate verification on the SoupSessionAsync objects it creates, leaving users vul…
Debian Linux
after 0.3.13
MEDIUM 5.9
CVE-2021-39358
In GNOME libgfbgraph through 0.2.4, gfbgraph-photo.c does not enable TLS certificate verification on the SoupSessionSync objects it creates, leaving …
Fedora
after 0.2.4
MEDIUM 5.9
CVE-2021-39359
In GNOME libgda through 6.0.0, gda-web-provider.c does not enable TLS certificate verification on the SoupSessionSync objects it creates, leaving use…
Fedora
after 6.0.0
MEDIUM 5.9
CVE-2021-39360
In GNOME libzapojit through 0.0.3, zpj-skydrive.c does not enable TLS certificate verification on the SoupSessionSync objects it creates, leaving use…
Fedora
after 0.0.3