Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.4
CVE-2021-26911
core/imap/MCIMAPSession.cpp in Canary Mail before 3.22 has Missing SSL Certificate Validation for IMAP in STARTTLS mode.
Canary Mail
Patch available
HIGH 7.5
CVE-2021-0341
In verifyHostName of OkHostnameVerifier.java, there is a possible way to accept a certificate for the wrong domain due to improperly used crypto. Thi…
Android
Patch available
MEDIUM 5.3
CVE-2020-4791
IBM Security Identity Governance and Intelligence 5.2.6 could allow an attacker to obtain sensitive information using main in the middle attacks due …
Security Identity Governance And Intelligence
Patch available
MEDIUM 5.9
CVE-2020-5812
Nessus AMI versions 8.12.0 and earlier were found to either not validate, or incorrectly validate, a certificate which could allow an attacker to spo…
Nessus Amazon Machine Image
after 8.12.0
HIGH 8.1
CVE-2021-3336
DoTls13CertificateVerify in tls13.c in wolfSSL before 4.7.0 does not cease processing for certain anomalous peer behavior (sending an ED22519, ED448,…
Wolfssl
4.7.0+
HIGH 8.1
CVE-2021-3309
packages/wekan-ldap/server/ldap.js in Wekan before 4.87 can process connections even though they are not authorized by the Certification Authority tr…
Wekan
4.87+
MEDIUM 5.3
CVE-2021-3285
jxbrowser in TI Code Composer Studio IDE 8.x through 10.x before 10.1.1 does not verify X.509 certificates for HTTPS.
Code Composer Studio Intgrated Development Environment
10.1.1+
MEDIUM 6.5
CVE-2021-1276
Multiple vulnerabilities in Cisco Data Center Network Manager (DCNM) could allow an attacker to spoof a trusted host or construct a man-in-the-middle…
Data Center Network Manager
11.5+
MEDIUM 6.5
CVE-2021-1277
Multiple vulnerabilities in Cisco Data Center Network Manager (DCNM) could allow an attacker to spoof a trusted host or construct a man-in-the-middle…
Data Center Network Manager
11.5+
HIGH 7.8
CVE-2021-3162
Docker Desktop Community before 2.5.0.0 on macOS mishandles certificate checking, leading to local privilege escalation.
Docker
2.5.0.0+
HIGH 7.5
CVE-2020-35733
An issue was discovered in Erlang/OTP before 23.2.2. The ssl application 10.2 accepts and trusts an invalid X.509 certificate chain to a trusted root…
Fedora
23.2.2+
MEDIUM 5.3
CVE-2020-24025
Certificate validation in node-sass 2.0.0 to 4.14.1 is disabled when requesting binaries even if the user is not specifying an alternative download p…
Node Sass
after 4.14.1
MEDIUM 5.4
CVE-2020-25680
A flaw was found in JBCS httpd in version 2.4.37 SP3, where it uses a back-end worker SSL certificate with the keystore file's ID is 'unknown'. The v…
Jboss Core Services Httpd
Mitigation only
HIGH 7.5
CVE-2019-16281
Ptarmigan before 0.2.3 lacks API token validation, e.g., an "if (token === apiToken) {return true;} return false;" code block.
Ptarmigan
0.2.3+
HIGH 7.8
CVE-2020-8289
Backblaze for Windows before 7.0.1.433 and Backblaze for macOS before 7.0.1.434 suffer from improper certificate validation in `bztransmit` helper du…
Backblaze
7.0.1.433 / 7.0.1.434+
CRITICAL 9.1
CVE-2020-29663
Icinga 2 v2.8.0 through v2.11.7 and v2.12.2 has an issue where revoked certificates due for renewal will automatically be renewed, ignoring the CRL. …
Icinga
after 2.11.7
HIGH 7.5
CVE-2020-8286
curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to insufficient verification of the OCSP response.
Fedora
7.74.0+
HIGH 7.4
CVE-2012-0955
software-properties was vulnerable to a person-in-the-middle attack due to incorrect TLS certificate validation in softwareproperties/ppa.py. softwar…
Software Properties
0.92+
HIGH 7.4
CVE-2020-8279
Missing validation of server certificates for out-going connections in Nextcloud Social < 0.4.0 allowed a man-in-the-middle attack.
Social
0.4.0+
HIGH 7.5
CVE-2020-28362
Go before 1.14.12 and 1.15.x before 1.15.4 allows Denial of Service.
Go
1.14.12 / 1.15.5+
HIGH 7.5
CVE-2020-27589
Synopsys hub-rest-api-python (aka blackduck on PyPI) version 0.0.25 - 0.0.52 does not validate SSL certificates in certain cases.
Hub Rest Api Python
after 0.0.52
CRITICAL 9.0
CVE-2020-27648
Improper certificate validation vulnerability in OpenVPN client in Synology DiskStation Manager (DSM) before 6.2.3-25426-2 allows man-in-the-middle a…
Diskstation Manager
6.2.3-25426 / 6.2.3-25426-2+
CRITICAL 9.0
CVE-2020-27649
Improper certificate validation vulnerability in OpenVPN client in Synology Router Manager (SRM) before 1.2.4-8081 allows man-in-the-middle attackers…
Router Manager
1.2.4-8081+
CRITICAL 9.8
CVE-2019-8531
A validation issue existed in Trust Anchor Management. This issue was addressed with improved validation. This issue is fixed in watchOS 5.2, macOS M…
Iphone Os
5.2 / 10.14.4+
HIGH 7.5
CVE-2019-17007
In Network Security Services before 3.44, a malformed Netscape Certificate Sequence can cause NSS to crash, resulting in a denial of service.
Network Security Services
2.14.0 / 3.44+
CRITICAL 9.1
CVE-2020-9868
A certificate validation issue existed when processing administrator added certificates. This issue was addressed with improved certificate validatio…
Ipados
6.2.8 / 10.15.6+
MEDIUM 5.3
CVE-2020-3557
A vulnerability in the host input API daemon of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to c…
Secure Firewall Management Center
6.6.1+
HIGH 7.4
CVE-2020-3994
VMware vCenter Server (6.7 before 6.7u3, 6.6 before 6.5u3k) contains a session hijack vulnerability in the vCenter Server Appliance Management Interf…
Cloud Foundation
3.9+
HIGH 8.3
CVE-2020-1675
When Security Assertion Markup Language (SAML) authentication is enabled, Juniper Networks Mist Cloud UI might incorrectly process invalid authentica…
Mist Cloud Ui
2020-09-02+
MEDIUM 5.9
CVE-2020-13955
HttpUtils#getURLConnection method disables explicitly hostname verification for HTTPS connections making clients vulnerable to man-in-the-middle atta…
Calcite
1.26+