Vulnerability index

Browse CVEs

1,354 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Certificate ValidationCWE-295 × clear
HIGH 7.5 CVE-2021-29495 Nim is a statically typed compiled systems programming language. In Nim standard library before 1.4.2, httpClient SSL/TLS certificate verification wa… Nim 1.4.2+ Fix from $1,9502021-05-07 MEDIUM 6.5 CVE-2020-36127 Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by an information disclosure vulnerability. Through the PUK signature functionali… Paxstore after 7.0.8_20200511171508 Fix from $1,6002021-05-07 HIGH 8.8 CVE-2021-20695 Improper following of a certificate's chain of trust vulnerability in DAP-1880AC firmware version 1.21 and earlier allows a remote authenticated atta… Dap 1880ac Firmware after 1.21 Fix from $1,9502021-04-26 CRITICAL 9.4 CVE-2021-31597 The xmlhttprequest-ssl package before 1.6.1 for Node.js disables SSL certificate validation by default, because rejectUnauthorized (when the property… Xmlhttprequest Ssl 1.6.1+ Fix from $2,3002021-04-23 HIGH 7.5 CVE-2021-27400 HashiCorp Vault and Vault Enterprise Cassandra integrations (storage backend and database secrets engine plugin) did not validate TLS certificates wh… Vault 1.6.4 / 1.7.1+ Fix from $1,9502021-04-22 HIGH 7.5 CVE-2021-29653 HashiCorp Vault and Vault Enterprise 1.5.1 and newer, under certain circumstances, may exclude revoked but unexpired certificates from the CRL. Fixed… Vault 1.5.8 / 1.6.4+ Fix from $1,9502021-04-22 MEDIUM 5.9 CVE-2021-20989 Fibaro Home Center 2 and Lite devices with firmware version 4.600 and older initiate SSH connections to the Fibaro cloud to provide remote access and… Home Center 2 Firmware after 4.600 Fix from $1,6002021-04-19 CRITICAL 9.8 CVE-2021-3460 The Motorola MH702x devices, prior to version 2.0.0.301, do not properly verify the server certificate during communication with the support server w… Mh702x Firmware 2.0.0.301+ Fix from $2,3002021-04-13 MEDIUM 6.5 CVE-2020-7924 Usage of specific command line parameter in MongoDB Tools which was originally intended to just skip hostname checks, may result in MongoDB skipping … Database Tools 0.6.0 / 3.6.21+ Fix from $1,6002021-04-12 MEDIUM 6.5 CVE-2021-22511 Improper Certificate Validation vulnerability in Micro Focus Application Automation Tools Plugin - Jenkins plugin. The vulnerability affects version … Application Automation Tools after 6.7 Fix from $1,6002021-04-08 HIGH 7.4 CVE-2021-27899 The Proofpoint Insider Threat Management Agents (formerly ObserveIT Agent) for MacOS and Linux perform improper validation of the ITM Server's certif… Insider Threat Management 7.9.3 / 7.10.3+ Fix from $1,9502021-04-06 MEDIUM 5.9 CVE-2021-21373 Nimble is a package manager for the Nim programming language. In Nim release versions before versions 1.2.10 and 1.4.4, "nimble refresh" fetches a li… Nim 1.2.10 / 1.4.4+ Fix from $1,6002021-03-26 HIGH 8.1 CVE-2021-21374 Nimble is a package manager for the Nim programming language. In Nim release versions before versions 1.2.10 and 1.4.4, "nimble refresh" fetches a li… Nim 1.2.10 / 1.4.4+ Fix from $1,9502021-03-26 HIGH 7.4 CVE-2021-3450EPSS 18% The X509_V_FLAG_X509_STRICT flag enables additional security checks of the certificates present in a certificate chain. It is not set by default. Sta… OpenSSL 1.1.1k / 10.24.1+ Fix from $1,9502021-03-25 HIGH 7.4 CVE-2021-21385 Mifos-Mobile Android Application for MifosX is an Android Application built on top of the MifosX Self-Service platform. Mifos-Mobile before commit e5… Mifos Mobile 2021-03-14+ Fix from $1,9502021-03-24 MEDIUM 5.6 CVE-2021-1471 Multiple vulnerabilities in Cisco Jabber for Windows, Cisco Jabber for MacOS, and Cisco Jabber for mobile platforms could allow an attacker to execut… Jabber 12.1.5 / 12.5.4+ Fix from $1,6002021-03-24 MEDIUM 6.5 CVE-2021-28363 The urllib3 library 1.26.x before 1.26.4 for Python omits SSL certificate validation in some cases involving HTTPS to HTTPS proxies. The initial conn… Urllib3 1.26.4+ Fix from $1,6002021-03-15 MEDIUM 6.8 CVE-2020-15260 PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, S… Pjsip after 2.10 Fix from $1,6002021-03-10 MEDIUM 6.5 CVE-2021-27257 This vulnerability allows network-adjacent attackers to compromise the integrity of downloaded information on affected installations of NETGEAR R7800… Br200 Firmware 1.0.0.134 / 1.0.1.60+ Fix from $1,6002021-03-05 HIGH 8.1 CVE-2021-27098 In SPIRE 0.8.1 through 0.8.4 and before versions 0.9.4, 0.10.2, 0.11.3 and 0.12.1, specially crafted requests to the FetchX509SVID RPC of SPIRE Serve… Spire 0.9.4 / 0.10.2+ Fix from $1,9502021-03-05 HIGH 7.2 CVE-2021-22189 Starting with version 13.7 the Gitlab CE/EE editions were affected by a security issue related to the validation of the certificates for the Fortinet… GitLab 13.6.7 / 13.7.7+ Fix from $1,9502021-03-04 MEDIUM 5.9 CVE-2020-28972 In SaltStack Salt before 3002.5, authentication to VMware vcenter, vsphere, and esxi servers (in the vmware.py files) does not always validate the SS… Fedora 2015.8.10 / 2015.8.13+ Fix from $1,6002021-02-27 HIGH 7.4 CVE-2020-35662 In SaltStack Salt before 3002.5, when authenticating to services using certain modules, the SSL certificate is not always validated. Fedora 2015.8.10 / 2015.8.13+ Fix from $1,9502021-02-27 CRITICAL 9.8 CVE-2021-3406 A flaw was found in keylime 5.8.1 and older. The issue in the Keylime agent and registrar code invalidates the cryptographic chain of trust from the … Fedora after 5.8.1 Fix from $2,3002021-02-25 MEDIUM 6.8 CVE-2021-20327 A specific version of the Node.js mongodb-client-encryption module does not perform correct validation of the KMS server’s certificate. This vulnerab… Libmongocrypt Mitigation only Fix from $1,6002021-02-25 MEDIUM 6.8 CVE-2021-20328 Specific versions of the Java driver that support client-side field level encryption (CSFLE) fail to perform correct host name verification on the KM… Java Driver 1.13.3 / 3.11.3+ Fix from $1,6002021-02-25 HIGH 7.5 CVE-2021-20230 A flaw was found in stunnel before 5.57, where it improperly validates client certificates when it is configured to use both redirect and verifyChain… Stunnel 5.57+ Fix from $1,9502021-02-23 MEDIUM 5.9 CVE-2021-27189 The CIRA Canadian Shield app before 4.0.13 for iOS lacks SSL Certificate Validation. Canadian Shield 4.0.13+ Fix from $1,6002021-02-23 MEDIUM 5.9 CVE-2020-24392 In voloko twitter-stream 0.1.10, missing TLS hostname validation allows an attacker to perform a man-in-the-middle attack against users of the librar… Twitter Stream No fix yet Fix from $1,6002021-02-19 MEDIUM 5.9 CVE-2020-24393 TweetStream 2.6.1 uses the library eventmachine in an insecure way that does not have TLS hostname validation. This allows an attacker to perform a m… Tweetstream No fix yet Fix from $1,6002021-02-19