Vulnerability index

Browse CVEs

1,354 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Certificate ValidationCWE-295 × clear
MEDIUM 5.4 CVE-2020-5909 In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, when users run the command displayed in NGINX Controller user interface (UI) to fetch the agent inst… Nginx Controller after 3.5.0 Fix from $1,6002020-07-02 MEDIUM 5.9 CVE-2020-15047 MSA/SMTP.cpp in Trojita before 0.8 ignores certificate-verification errors, which allows man-in-the-middle attackers to spoof SMTP servers. Trojita 0.8+ Fix from $1,6002020-06-25 HIGH 8.1 CVE-2020-5367 Dell EMC Unisphere for PowerMax versions prior to 9.1.0.17, Dell EMC Unisphere for PowerMax Virtual Appliance versions prior to 9.1.0.17, and PowerMa… Emc Unisphere For Powermax 9.1.0.17+ Fix from $1,9502020-06-23 MEDIUM 5.9 CVE-2020-14980 The Sophos Secure Email application through 3.9.4 for Android has Missing SSL Certificate Validation. Sophos Secure Email after 3.9.4 Fix from $1,6002020-06-22 MEDIUM 5.9 CVE-2020-14981 The ThreatTrack VIPRE Password Vault app through 1.100.1090 for iOS has Missing SSL Certificate Validation. Password Vault after 1.100.1090 Fix from $1,6002020-06-22 MEDIUM 5.3 CVE-2016-11076 An issue was discovered in Mattermost Server before 3.0.0. It does not ensure that a cookie is used over SSL. Mattermost Server 3.0.0+ Fix from $1,6002020-06-19 HIGH 7.5 CVE-2017-18909 An issue was discovered in Mattermost Server before 3.9.0 when SAML is used. Encryption and signature verification are not mandatory. Mattermost Server 3.9.0+ Fix from $1,9502020-06-19 CRITICAL 9.1 CVE-2017-18911 An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. The X.509 certificate validation can be skipped for a TLS-based e-mail s… Mattermost Server 3.6.7 / 3.7.5+ Fix from $2,3002020-06-19 HIGH 8.8 CVE-2020-3342 A vulnerability in the software update feature of Cisco Webex Meetings Desktop App for Mac could allow an unauthenticated, remote attacker to execute… Webex Meetings 39.5.11+ Fix from $1,9502020-06-18 MEDIUM 6.5 CVE-2020-4320 IBM MQ Appliance and IBM MQ AMQP Channels 8.0, 9.0 LTS, 9.1 LTS, and 9.1 CD do not correctly block or allow clients based on the certificate distingu… Mq 8.0.0.15 / 9.0.0.10+ Fix from $1,6002020-06-16 MEDIUM 5.9 CVE-2019-16252 Missing SSL Certificate Validation in the Nutfind.com application through 3.9.12 for Android allows a man-in-the-middle attacker to sniff and manipul… Nutfind after 3.9.12 Fix from $1,6002020-06-12 MEDIUM 5.3 CVE-2020-2033 When the pre-logon feature is enabled, a missing certification validation in Palo Alto Networks GlobalProtect app can disclose the pre-logon authenti… Globalprotect 5.0.10 / 5.1.4+ Fix from $1,6002020-06-10 MEDIUM 5.3 CVE-2020-0119 In addOrUpdateNetworkInternal and related functions of WifiConfigManager.java, there is a possible man in the middle attack due to improper certifica… Android Patch available Fix from $1,6002020-06-10 HIGH 7.5 CVE-2020-9040 Couchbase Server Java SDK before 2.7.1.1 allows a potential attacker to forge an SSL certificate and pose as the intended peer. An attacker can lever… Couchbase Server Java Sdk 2.7.1.1+ Fix from $1,9502020-06-08 HIGH 7.4 CVE-2020-8172EPSS 6% TLS session reuse can lead to host certificate verification bypass in node version < 12.18.0 and < 14.4.0. Node.js 12.18.0 / 14.4.0+ Fix from $1,9502020-06-08 MEDIUM 5.9 CVE-2020-13254EPSS 6% An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. In cases where a memcached backend does not perform key validation, passing… Django 2.2.13 / 3.0.7+ Fix from $1,6002020-06-03 MEDIUM 5.9 CVE-2020-13245 Certain NETGEAR devices are affected by Missing SSL Certificate Validation. This affects R7000 1.0.9.6_1.2.19 through 1.0.11.100_10.2.10, and possibl… R6120 Firmware No fix yet Fix from $1,6002020-05-28 MEDIUM 6.5 CVE-2020-13645 In GNOME glib-networking through 2.64.2, the implementation of GTlsClientConnection skips hostname verification of the server's TLS certificate if th… Ubuntu Linux 2.5.11 / 2.62.4+ Fix from $1,6002020-05-28 MEDIUM 5.9 CVE-2020-13616 The boost ASIO wrapper in net/asio.cpp in Pichi before 1.3.0 lacks TLS hostname verification. Pichi 1.3.0+ Fix from $1,6002020-05-26 MEDIUM 5.9 CVE-2020-13614 An issue was discovered in ssl.c in Axel before 2.17.8. The TLS implementation lacks hostname verification. Fedora 2.17.8+ Fix from $1,6002020-05-26 MEDIUM 5.9 CVE-2020-13615 lib/QoreSocket.cpp in Qore before 0.9.4.2 lacks hostname verification for X.509 certificates. Qore 0.9.4.2+ Fix from $1,6002020-05-26 HIGH 7.4 CVE-2020-13482 EM-HTTP-Request 1.1.5 uses the library eventmachine in an insecure way that allows an attacker to perform a man-in-the-middle attack against users of… Fedora Patch available Fix from $1,9502020-05-25 MEDIUM 5.3 CVE-2020-1113EPSS 7% A security feature bypass vulnerability exists in Microsoft Windows when the Task Scheduler service fails to properly verify client connections over … Windows 10 Patch available Fix from $1,6002020-05-21 HIGH 7.4 CVE-2020-13163 em-imap 0.5 uses the library eventmachine in an insecure way that allows an attacker to perform a man-in-the-middle attack against users of the libra… Em Imap No fix yet Fix from $1,9502020-05-19 MEDIUM 5.9 CVE-2020-1758 A flaw was found in Keycloak in versions before 10.0.0, where it does not perform the TLS hostname verification while sending emails using the SMTP s… Keycloak 10.0.0+ Fix from $1,6002020-05-15 HIGH 7.0 CVE-2020-8156 A missing verification of the TLS host in Nextcloud Mail 1.1.3 allowed a man in the middle attack. Mail 1.1.4+ Fix from $1,9502020-05-12 CRITICAL 9.8 CVE-2020-12637 Zulip Desktop before 5.2.0 has Missing SSL Certificate Validation because all validation was inadvertently disabled during an attempt to recognize th… Zulip Desktop 5.2.0+ Fix from $2,3002020-05-09 HIGH 8.1 CVE-2020-11050 In Java-WebSocket less than or equal to 1.4.1, there is an Improper Validation of Certificate with Host Mismatch where WebSocketClient does not perfo… Java Websocket after 1.4.1 Fix from $1,9502020-05-07 MEDIUM 5.6 CVE-2020-2187 Jenkins Amazon EC2 Plugin 1.50.1 and earlier unconditionally accepts self-signed certificates and does not perform hostname validation, enabling man-… Amazon Ec2 after 1.50.1 Fix from $1,6002020-05-06 MEDIUM 5.9 CVE-2019-19101 A missing secure communication definition and an incomplete TLS validation in the upgrade service in B&R Automation Studio versions 4.0.x, 4.1.x, 4.2… Automation Studio 4.3.11 / 4.4.9+ Fix from $1,6002020-04-29