Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.4
CVE-2020-5523
Android App 'MyPallete' and some of the Android banking applications based on 'MyPallete' do not verify X.509 certificates from servers, and also do …
77 Bank
after 3.0.4
HIGH 7.5
CVE-2015-0294
GnuTLS before 3.3.13 does not validate that the signature algorithms match when importing a certificate.
Debian Linux
3.3.13+
MEDIUM 6.8
CVE-2006-7246
NetworkManager 0.9.x does not pin a certificate's subject to an ESSID when 802.11X authentication is used.
Networkmanager
after 0.9.9.98
HIGH 7.4
CVE-2020-5521
The kantan netprint App for iOS 2.0.2 and earlier does not verify X.509 certificates from servers, which allows man-in-the-middle attackers to spoof …
Easy Netprint
after 2.0.2
HIGH 7.4
CVE-2020-5522
The kantan netprint App for Android 2.0.3 and earlier does not verify X.509 certificates from servers, which allows man-in-the-middle attackers to sp…
Easy Netprint
after 2.0.3
MEDIUM 5.9
CVE-2017-14806
A Improper Certificate Validation vulnerability in susestudio-common of SUSE Studio onsite allows remote attackers to MITM connections to the reposit…
Studio Onsite
after 1.3.17-56.6.3
HIGH 7.4
CVE-2020-5520
The netprint App for iOS 3.2.3 and earlier does not verify X.509 certificates from servers, which allows man-in-the-middle attackers to spoof servers…
Netprint
after 3.2.3
MEDIUM 6.5
CVE-2011-2669
Mozilla Firefox prior to 3.6 has a DoS vulnerability due to an issue in the validation of certificates.
Firefox
3.6+
MEDIUM 5.9
CVE-2020-3940
VMware Workspace ONE SDK and dependent mobile application updates address sensitive information disclosure vulnerability.
Workspace One Boxer
1.2.1 / 1.3.2+
HIGH 7.5
CVE-2020-1929
The Apache Beam MongoDB connector in versions 2.10.0 to 2.16.0 has an option to disable SSL trust verification. However this configuration is not res…
Beam
after 2.16.0
MEDIUM 5.9
CVE-2012-1316
Cisco IronPort Web Security Appliance does not check for certificate revocation which could lead to MITM attacks
Ironport Web Security Appliance
Mitigation only
HIGH 8.1
CVE-2020-0601 KEVEPSS 89%
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates.An attacker could…
Go
1.12.16 / 1.13.7+
MEDIUM 5.9
CVE-2014-0161
ovirt-engine-sdk-python before 3.4.0.7 and 3.5.0.4 does not verify that the hostname of the remote endpoint matches the Common Name (CN) or subjectAl…
Ovirt Engine Sdk Python
3.4.0.7 / 3.5.0.4+
MEDIUM 5.9
CVE-2014-0104
In fence-agents before 4.0.17 does not verify remote SSL certificates in the fence_cisco_ucs.py script which can potentially allow for man-in-the-mid…
Fence Agents
4.0.17+
HIGH 7.5
CVE-2013-0264
An import error was introduced in Cumin in the code refactoring in r5310. Server certificate validation is always disabled when connecting to Aviary …
Mrg Management Console
Patch available
HIGH 7.4
CVE-2019-6032
The NTV News24 prior to Ver.3.0.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and …
News 24
3.0.0+
HIGH 7.4
CVE-2019-6687
On versions 15.0.0-15.0.1.1, the BIG-IP ASM Cloud Security Services profile uses a built-in verification mechanism that fails to properly authenticat…
Big Ip Application Security Manager
15.1.0+
HIGH 7.1
CVE-2019-16561
Jenkins WebSphere Deployer Plugin 1.6.1 and earlier allows users with Overall/Read access to disable SSL/TLS certificate and hostname validation for …
Websphere Deployer
after 1.6.1
HIGH 8.2
CVE-2019-16558
Jenkins Spira Importer Plugin 3.2.3 and earlier disables SSL/TLS certificate validation for the Jenkins master JVM.
Spira Importer
after 3.2.3
MEDIUM 5.4
CVE-2018-11751
Previous versions of Puppet Agent didn't verify the peer in the SSL connection prior to downloading the CRL. This issue is resolved in Puppet Agent 6…
Puppet Server
6.4.0+
CRITICAL 9.8
CVE-2019-18826
Barco ClickShare Button R9861500D01 devices before 1.9.0 have Improper Following of a Certificate's Chain of Trust. The embedded 'dongle_bridge' prog…
Clickshare Cs 100 Firmware
1.9.0+
HIGH 7.5
CVE-2014-3495
duplicity 0.6.24 has improper verification of SSL certificates
Duplicity
No fix yet
MEDIUM 5.9
CVE-2019-11554
The Audible application through 2.34.0 for Android has Missing SSL Certificate Validation for Adobe SDKs, allowing MITM attackers to cause a denial o…
Audible
after 2.34.0
CRITICAL 9.8
CVE-2019-14910
A vulnerability was found in keycloak 7.x, when keycloak is configured with LDAP user federation and StartTLS is used instead of SSL/TLS from the LDA…
Keycloak
Mitigation only
MEDIUM 5.3
CVE-2011-2207
dirmngr before 2.1.0 improperly handles certain system calls, which allows remote attackers to cause a denial of service (DOS) via a specially-crafte…
Enterprise Linux
2.1.0+
HIGH 7.5
CVE-2019-19271
An issue was discovered in tls_verify_crl in ProFTPD before 1.3.6. A wrong iteration variable, used when checking a client certificate against CRL en…
Proftpd
1.3.6+
HIGH 7.5
CVE-2019-19270
An issue was discovered in tls_verify_crl in ProFTPD through 1.3.6b. Failure to check for the appropriate field of a CRL entry (checking twice for su…
Fedora
after 1.3.5
HIGH 7.5
CVE-2012-5518
vdsm: certificate generation upon node creation allowing vdsm to start and serve requests from anyone who has a matching key (and certificate)
Vdsm
Mitigation only
HIGH 7.5
CVE-2014-2901
wolfssl before 3.2.0 does not properly issue certificates for a server's hostname.
Wolfssl
3.2.0+
HIGH 7.5
CVE-2014-2902
wolfssl before 3.2.0 does not properly authorize CA certificate for signing other certificates.
Wolfssl
3.2.0+