Vulnerability index

Browse CVEs

1,354 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Certificate ValidationCWE-295 × clear
CRITICAL 9.8 CVE-2020-1952 An issue was found in Apache IoTDB .9.0 to 0.9.1 and 0.8.0 to 0.8.2. When starting IoTDB, the JMX port 31999 is exposed with no certification.Then, c… Iotdb after 0.9.1 Fix from $2,3002020-04-27 HIGH 7.4 CVE-2020-5864 In versions of NGINX Controller prior to 3.2.0, communication between NGINX Controller and NGINX Plus instances skip TLS verification by default. Nginx Controller 3.3.0+ Fix from $1,9502020-04-23 MEDIUM 5.9 CVE-2020-11806 In MailStore Outlook Add-in (and Email Archive Outlook Add-in) through 12.1.2, the login process does not validate the validity of the certificate pr… Mailstore Server after 12.1.2 Fix from $1,6002020-04-23 HIGH 7.5 CVE-2020-11792 NETGEAR R8900, R9000, RAX120, and XR700 devices before 2020-01-20 are affected by Transport Layer Security (TLS) certificate private key disclosure. R8900 Firmware Mitigation only Fix from $1,9502020-04-15 MEDIUM 6.5 CVE-2020-7922 X.509 certificates generated by the MongoDB Enterprise Kubernetes Operator may allow an attacker with access to the Kubernetes cluster improper acces… Mongodb Enterprise Kubernetes Operator after 1.4.4 Fix from $1,6002020-04-09 CRITICAL 9.1 CVE-2020-11580 An issue was discovered in Pulse Secure Pulse Connect Secure (PCS) through 2020-04-06. The applet in tncc.jar, executed on macOS, Linux, and Solaris … Pulse Connect Secure after 2020-04-06 Fix from $2,3002020-04-06 CRITICAL 9.1 CVE-2019-17560 The "Apache NetBeans" autoupdate system does not validate SSL certificates and hostnames for https based downloads. This allows an attacker to interc… Netbeans after 11.2 Fix from $2,3002020-03-30 HIGH 7.5 CVE-2019-3762 Data Protection Central versions 1.0, 1.0.1, 18.1, 18.2, and 19.1 contains an Improper Certificate Chain of Trust Vulnerability. A remote unauthentic… Emc Data Protection Central Mitigation only Fix from $1,9502020-03-18 HIGH 7.4 CVE-2019-11688 An issue was discovered in ASUSTOR exFAT Driver through 1.0.0.r20. When conducting license validation, exfat.cgi and exfatctl accept any certificate … Exfat Driver No fix yet Fix from $1,9502020-03-18 MEDIUM 5.9 CVE-2020-6175 Citrix SD-WAN 10.2.x before 10.2.6 and 11.0.x before 11.0.3 has Missing SSL Certificate Validation. Citrix Sd Wan Center 10.2.6 / 11.0.3+ Fix from $1,6002020-03-16 HIGH 7.5 CVE-2020-7919 Go before 1.12.16 and 1.13.x before 1.13.7 (and the crypto/cryptobyte package before 0.0.0-20200124225646-8b5121be2f68 for Go) allows attacks on clie… Go 1.12.6 / 1.13.7+ Fix from $1,9502020-03-16 HIGH 7.5 CVE-2020-9321 configurationwatcher.go in Traefik 2.x before 2.1.4 and TraefikEE 2.0.0 mishandles the purging of certificate contents from providers before logging. Traefik after 2.1.4 Fix from $1,9502020-03-16 HIGH 7.4 CVE-2019-10091 When TLS is enabled with ssl-endpoint-identification-enabled set to true, Apache Geode fails to perform hostname verification of the entries in the c… Geode Mitigation only Fix from $1,9502020-03-16 CRITICAL 9.1 CVE-2020-1887 Incorrect validation of the TLS SNI hostname in osquery versions after 2.9.0 and before 4.2.0 could allow an attacker to MITM osquery traffic in the … Osquery 4.2.0+ Fix from $2,3002020-03-13 MEDIUM 5.5 CVE-2012-1096 NetworkManager 0.9 and earlier allows local users to use other users' certificates or private keys when making a connection via the file path when ad… Debian Linux after 0.9.0 Fix from $1,6002020-03-10 HIGH 7.4 CVE-2020-8987 Avast AntiTrack before 1.5.1.172 and AVG Antitrack before 2.0.0.178 proxies traffic to HTTPS sites but does not validate certificates, and thus a man… Antitrack 1.5.1.172 / 2.0.0.178+ Fix from $1,9502020-03-09 HIGH 7.4 CVE-2020-3155 A vulnerability in the SSL implementation of the Cisco Intelligent Proximity solution could allow an unauthenticated, remote attacker to view or alte… Intelligence Proximity Mitigation only Fix from $1,9502020-03-04 CRITICAL 9.1 CVE-2020-9432 openssl_x509_check_host in lua-openssl 0.7.7-1 mishandles X.509 certificate validation because it uses lua_pushboolean for certain non-boolean return… Lua Openssl Patch available Fix from $2,3002020-02-27 CRITICAL 9.1 CVE-2020-9433 openssl_x509_check_email in lua-openssl 0.7.7-1 mishandles X.509 certificate validation because it uses lua_pushboolean for certain non-boolean retur… Lua Openssl Patch available Fix from $2,3002020-02-27 CRITICAL 9.1 CVE-2020-9434 openssl_x509_check_ip_asc in lua-openssl 0.7.7-1 mishandles X.509 certificate validation because it uses lua_pushboolean for certain non-boolean retu… Lua Openssl Patch available Fix from $2,3002020-02-27 MEDIUM 5.3 CVE-2020-7041 An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL 1.0.2 or later. tunnel.c mishandles certificate validation because an X509_chec… Fedora 1.12.0+ Fix from $1,6002020-02-27 MEDIUM 5.3 CVE-2020-7042 An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL 1.0.2 or later. tunnel.c mishandles certificate validation because the hostname… Fedora 1.12.0+ Fix from $1,6002020-02-27 CRITICAL 9.1 CVE-2020-7043 An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL before 1.0.2. tunnel.c mishandles certificate validation because hostname compa… Fedora 1.12.0+ Fix from $2,3002020-02-27 MEDIUM 6.5 CVE-2020-7942 Previously, Puppet operated on a model that a node with a valid certificate was entitled to all information in the system and that a compromised cert… Puppet 5.5.19 / 6.13.0+ Fix from $1,6002020-02-19 MEDIUM 5.9 CVE-2019-20455 Gateways/Gateway.php in Heartland & Global Payments PHP SDK before 2.0.0 does not enforce SSL certificate validations. Php Sdk 2.0.0+ Fix from $1,6002020-02-14 HIGH 7.5 CVE-2019-15604EPSS 20% Improper Certificate Validation in Node.js 10, 12, and 13 causes the process to abort when sending a crafted X.509 certificate Node.js 10.19.0 / 12.15.0+ Fix from $1,9502020-02-07 CRITICAL 9.8 CVE-2020-7956 HashiCorp Nomad and Nomad Enterprise up to 0.10.2 incorrectly validated role/region associated with TLS certificates used for mTLS RPC, and were susc… Nomad 0.10.3+ Fix from $2,3002020-01-31 MEDIUM 5.9 CVE-2020-5526 The AWMS Mobile App for Android 2.0.0 to 2.0.5 and for iOS 2.0.0 to 2.0.8 does not verify X.509 certificates from servers, which allows man-in-the-mi… Apeosware Management Suite after 2.0.8 Fix from $1,6002020-01-31 HIGH 7.4 CVE-2020-7904 In JetBrains IntelliJ IDEA before 2019.3, some Maven repositories were accessed via HTTP instead of HTTPS. Intellij Idea 2019.3.0+ Fix from $1,9502020-01-30 MEDIUM 5.9 CVE-2014-3230 The libwww-perl LWP::Protocol::https module 6.04 through 6.06 for Perl, when using IO::Socket::SSL as the SSL socket class, allows attackers to disab… \ after 6.06 Fix from $1,6002020-01-28