Vulnerability index

Browse CVEs

1,344 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Certificate ValidationCWE-295 × clear
HIGH 7.5 CVE-2026-6731 X.509 name constraint bypass via the Subject Common Name when treated as a DNS-type name. A certificate whose Subject CN violates an issuing CA's DNS… Wolfssl 5.9.2+ Fix from $1,9502026-06-25 MEDIUM 5.3 CVE-2026-6450 A CRL critical extension bypass exists in ParseCRL_Extensions where critical extensions are not properly enforced, allowing a crafted CRL with an unh… Wolfssl 5.9.2+ Fix from $1,6002026-06-25 HIGH 7.5 CVE-2026-55960 Un-negotiated Raw Public Key (RFC 7250) accepted in place of an X.509 certificate, bypassing chain validation. A raw public key has no chain, so Pars… Wolfssl 5.9.2+ Fix from $1,9502026-06-25 MEDIUM 5.3 CVE-2026-55964 Chain intermediate CA:TRUE without keyCertSign accepted as a signing CA. Intermediate CA certificates are required to have the keyCertSign key usage … Wolfssl 5.9.2+ Fix from $1,6002026-06-25 MEDIUM 5.3 CVE-2026-10592 Certificates with wildcard DNS SANs (e.g. *.example.com) bypassed CA name-constraint checks. A certificate with a wildcard DNS SAN that should be rej… Wolfssl 5.9.2+ Fix from $1,6002026-06-25 HIGH 7.5 CVE-2026-11310 X.509 trust-chain bypass in the OpenSSL compatibility certificate verifier (wolfSSL_X509_verify_cert()). This affects only builds with --enable-opens… Wolfssl 5.9.2+ Fix from $1,9502026-06-25 MEDIUM 6.5 CVE-2026-6091 Partial-chain certificate verification may accept chains that terminate at a peer-supplied, untrusted intermediate certificate rather than a trusted … Wolfssl 5.9.2+ Fix from $1,6002026-06-25 HIGH 7.5 CVE-2026-11999 X.509 trust-chain bypass (path-depth exhaustion) in the OpenSSL compatibility certificate verifier (wolfSSL_X509_verify_cert()). This affects only bu… Wolfssl 5.9.2+ Fix from $1,9502026-06-25 HIGH 7.8 CVE-2026-46734 Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3, contain an Improper Certificate Validation vulnerability. A low privileged att… Display And Peripheral Manager 2.3.0+ Fix from $1,9502026-06-25 MEDIUM 5.9 CVE-2026-54323 Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. Prior to 0.185.0, the daemon's git clone … Mitigation only Fix from $1,6002026-06-23 HIGH 8.3 CVE-2026-54100 A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. WMCO establishes SSH connections to Windows … Openshift Container Platform after 4.22.1 Fix from $1,9502026-06-22 MEDIUM 6.5 CVE-2025-2669 IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions 4.8, 5.0, 5.1, 5.2, 5.3 could allow a privileged user to perform opera… Db2 5.4+ Fix from $1,6002026-06-22 HIGH 7.4 CVE-2026-9697 Impact: undici's ProxyAgent silently drops the requestTls option when configured with a SOCKS5 proxy URI (socks5:// or socks://). The target HTTPS co… Undici 7.28.0 / 8.5.0+ Fix from $1,9502026-06-17 MEDIUM 6.5 CVE-2024-47477 Dell PowerFlex Manager, versions prior to 4.5.1.1, contain an improper certificate validation vulnerability. A remote unauthenticated attacker could … Powerflex Manager 4.5.1.1+ Fix from $1,6002026-06-17 HIGH 8.6 CVE-2025-71261 An attacker with network-level access between the SUSE Virtualization and Rancher Manager in SUSE Harvester before 1.8.0 could interfere with the TL… Mitigation only Fix from $1,9502026-06-16 CRITICAL 9.8 CVE-2026-9258 Improper validation of SSH host keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier Eos Network Setting Tool 1.5.1+ Fix from $2,3002026-06-16 CRITICAL 9.8 CVE-2026-9259 Improper validation of server certificates in Canon EOS Network Setting Tool Version 1.5.0 or earlier Eos Network Setting Tool 1.5.1+ Fix from $2,3002026-06-16 CRITICAL 9.1 CVE-2026-45388 In OCaml-TLS before 2.1.0, the client implementation does insufficient checks of the certificate provided by the server, which allows impersonation w… Mitigation only Fix from $2,3002026-06-15 HIGH 7.4 CVE-2026-45389 In OCaml-TLS before 2.1.0, the server implementation does insufficient checks of the certificate provided by the client (when doing client authentica… Mitigation only Fix from $1,9502026-06-15 HIGH 8.8 CVE-2026-45170 Idira Vendor PAM - Self-Hosted Connector versions prior 1.1.100504 under specific conditions and configuration scenarios, TLS certificate validation … Idira Privilege Cloud Connector 1.1.100504+ Fix from $1,9502026-06-12 HIGH 7.8 CVE-2026-45175 Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within internal agent validation processes. A local att… Idira Endpoint Privilege Manager 26.5.0+ Fix from $1,9502026-06-11 MEDIUM 5.0 CVE-2026-40992 Spring Boot's Mail auto-configuration does not enable hostname verification. Applications that set the relevant JavaMail property, such as spring.mai… Mitigation only Fix from $1,6002026-06-11 HIGH 7.4 CVE-2026-53475 A flaw was found in assisted-migration-agent. The application hardcodes insecure Transport Layer Security (TLS) connections when communicating with v… Assisted Migration Agent 2026-06-10+ Fix from $1,9502026-06-10 HIGH 7.3 CVE-2026-9758 Improper comparison with the certificates trusted list in S2OPC allows an attacker well-formed untrusted certificate to be considered trusted Mitigation only Fix from $1,9502026-06-10 MEDIUM 5.3 CVE-2026-42769 Issue Summary: An error in the callback used to verify the certificate provided in a Root CA key update Certificate Management Protocol (CMP) message… OpenSSL 3.4.6 / 3.5.7+ Fix from $1,6002026-06-09 HIGH 7.4 CVE-2026-50752 A weakness in the certificate validation logic of the deprecated IKEv1 key exchange may allow an unauthenticated attacker positioned as a man-in-the-… Mitigation only Fix from $1,9502026-06-08 HIGH 8.0 CVE-2026-45745 Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Starting in version 1.7.0, Termix Deskt… Termix No fix yet Fix from $1,9502026-06-05 HIGH 7.4 CVE-2026-44393 An issue was discovered in OpenStack oslo.messaging 1.0.0 through 17.3.0. The oslo.messaging RabbitMQ driver does not perform TLS hostname verificati… Mitigation only Fix from $1,9502026-06-04 HIGH 7.8 CVE-2026-41859 A network man-in-the-middle between nats-sync and the BOSH director can steal the director credentials (Basic auth header or UAA client secret) and c… Mitigation only Fix from $1,9502026-06-04 MEDIUM 5.9 CVE-2026-49267 Apache Airflow's EmailOperator and the underlying `airflow.utils.email` helpers established SMTP STARTTLS connections without verifying the remote ce… Airflow 3.2.2+ Fix from $1,6002026-06-01