Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.4
CVE-2020-5909
In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, when users run the command displayed in NGINX Controller user interface (UI) to fetch the agent inst…
Nginx Controller
after 3.5.0
MEDIUM 5.9
CVE-2020-15047
MSA/SMTP.cpp in Trojita before 0.8 ignores certificate-verification errors, which allows man-in-the-middle attackers to spoof SMTP servers.
Trojita
0.8+
HIGH 8.1
CVE-2020-5367
Dell EMC Unisphere for PowerMax versions prior to 9.1.0.17, Dell EMC Unisphere for PowerMax Virtual Appliance versions prior to 9.1.0.17, and PowerMa…
Emc Unisphere For Powermax
9.1.0.17+
MEDIUM 5.9
CVE-2020-14980
The Sophos Secure Email application through 3.9.4 for Android has Missing SSL Certificate Validation.
Sophos Secure Email
after 3.9.4
MEDIUM 5.9
CVE-2020-14981
The ThreatTrack VIPRE Password Vault app through 1.100.1090 for iOS has Missing SSL Certificate Validation.
Password Vault
after 1.100.1090
MEDIUM 5.3
CVE-2016-11076
An issue was discovered in Mattermost Server before 3.0.0. It does not ensure that a cookie is used over SSL.
Mattermost Server
3.0.0+
HIGH 7.5
CVE-2017-18909
An issue was discovered in Mattermost Server before 3.9.0 when SAML is used. Encryption and signature verification are not mandatory.
Mattermost Server
3.9.0+
CRITICAL 9.1
CVE-2017-18911
An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. The X.509 certificate validation can be skipped for a TLS-based e-mail s…
Mattermost Server
3.6.7 / 3.7.5+
HIGH 8.8
CVE-2020-3342
A vulnerability in the software update feature of Cisco Webex Meetings Desktop App for Mac could allow an unauthenticated, remote attacker to execute…
Webex Meetings
39.5.11+
MEDIUM 6.5
CVE-2020-4320
IBM MQ Appliance and IBM MQ AMQP Channels 8.0, 9.0 LTS, 9.1 LTS, and 9.1 CD do not correctly block or allow clients based on the certificate distingu…
Mq
8.0.0.15 / 9.0.0.10+
MEDIUM 5.9
CVE-2019-16252
Missing SSL Certificate Validation in the Nutfind.com application through 3.9.12 for Android allows a man-in-the-middle attacker to sniff and manipul…
Nutfind
after 3.9.12
MEDIUM 5.3
CVE-2020-2033
When the pre-logon feature is enabled, a missing certification validation in Palo Alto Networks GlobalProtect app can disclose the pre-logon authenti…
Globalprotect
5.0.10 / 5.1.4+
MEDIUM 5.3
CVE-2020-0119
In addOrUpdateNetworkInternal and related functions of WifiConfigManager.java, there is a possible man in the middle attack due to improper certifica…
Android
Patch available
HIGH 7.5
CVE-2020-9040
Couchbase Server Java SDK before 2.7.1.1 allows a potential attacker to forge an SSL certificate and pose as the intended peer. An attacker can lever…
Couchbase Server Java Sdk
2.7.1.1+
HIGH 7.4
CVE-2020-8172EPSS 6%
TLS session reuse can lead to host certificate verification bypass in node version < 12.18.0 and < 14.4.0.
Node.js
12.18.0 / 14.4.0+
MEDIUM 5.9
CVE-2020-13254EPSS 6%
An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. In cases where a memcached backend does not perform key validation, passing…
Django
2.2.13 / 3.0.7+
MEDIUM 5.9
CVE-2020-13245
Certain NETGEAR devices are affected by Missing SSL Certificate Validation. This affects R7000 1.0.9.6_1.2.19 through 1.0.11.100_10.2.10, and possibl…
R6120 Firmware
No fix yet
MEDIUM 6.5
CVE-2020-13645
In GNOME glib-networking through 2.64.2, the implementation of GTlsClientConnection skips hostname verification of the server's TLS certificate if th…
Ubuntu Linux
2.5.11 / 2.62.4+
MEDIUM 5.9
CVE-2020-13616
The boost ASIO wrapper in net/asio.cpp in Pichi before 1.3.0 lacks TLS hostname verification.
Pichi
1.3.0+
MEDIUM 5.9
CVE-2020-13614
An issue was discovered in ssl.c in Axel before 2.17.8. The TLS implementation lacks hostname verification.
Fedora
2.17.8+
MEDIUM 5.9
CVE-2020-13615
lib/QoreSocket.cpp in Qore before 0.9.4.2 lacks hostname verification for X.509 certificates.
Qore
0.9.4.2+
HIGH 7.4
CVE-2020-13482
EM-HTTP-Request 1.1.5 uses the library eventmachine in an insecure way that allows an attacker to perform a man-in-the-middle attack against users of…
Fedora
Patch available
MEDIUM 5.3
CVE-2020-1113EPSS 7%
A security feature bypass vulnerability exists in Microsoft Windows when the Task Scheduler service fails to properly verify client connections over …
Windows 10
Patch available
HIGH 7.4
CVE-2020-13163
em-imap 0.5 uses the library eventmachine in an insecure way that allows an attacker to perform a man-in-the-middle attack against users of the libra…
Em Imap
No fix yet
MEDIUM 5.9
CVE-2020-1758
A flaw was found in Keycloak in versions before 10.0.0, where it does not perform the TLS hostname verification while sending emails using the SMTP s…
Keycloak
10.0.0+
HIGH 7.0
CVE-2020-8156
A missing verification of the TLS host in Nextcloud Mail 1.1.3 allowed a man in the middle attack.
Mail
1.1.4+
CRITICAL 9.8
CVE-2020-12637
Zulip Desktop before 5.2.0 has Missing SSL Certificate Validation because all validation was inadvertently disabled during an attempt to recognize th…
Zulip Desktop
5.2.0+
HIGH 8.1
CVE-2020-11050
In Java-WebSocket less than or equal to 1.4.1, there is an Improper Validation of Certificate with Host Mismatch where WebSocketClient does not perfo…
Java Websocket
after 1.4.1
MEDIUM 5.6
CVE-2020-2187
Jenkins Amazon EC2 Plugin 1.50.1 and earlier unconditionally accepts self-signed certificates and does not perform hostname validation, enabling man-…
Amazon Ec2
after 1.50.1
MEDIUM 5.9
CVE-2019-19101
A missing secure communication definition and an incomplete TLS validation in the upgrade service in B&R Automation Studio versions 4.0.x, 4.1.x, 4.2…
Automation Studio
4.3.11 / 4.4.9+