Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 8.1
CVE-2016-10931
An issue was discovered in the openssl crate before 0.9.0 for Rust. There is an SSL/TLS man-in-the-middle vulnerability because certificate verificat…
Rust Openssl
0.9.0+
HIGH 8.1
CVE-2019-15525
There is Missing SSL Certificate Validation in the pw3270 terminal emulator before version 5.1.
Pw3270
5.1+
MEDIUM 5.9
CVE-2019-1948
A vulnerability in Cisco Webex Meetings Mobile (iOS) could allow an unauthenticated, remote attacker to gain unauthorized read access to sensitive da…
Webex Meetings
after 39.5
MEDIUM 6.5
CVE-2019-5280
The SIP TLS module of Huawei CloudLink Phone 7900 with V600R019C10 has a TLS certificate verification vulnerability. Due to insufficient verification…
Cloudlink Phone 7900 Firmware
Mitigation only
HIGH 7.4
CVE-2019-14516
The mAadhaar application 1.2.7 for Android lacks SSL Certificate Validation, leading to man-in-the-middle attacks against requests for FAQs or Help.
Maadhaar
No fix yet
HIGH 7.5
CVE-2019-10381
Jenkins Codefresh Integration Plugin 1.8 and earlier disables SSL/TLS and hostname verification globally for the Jenkins master JVM.
Codefresh Integration
after 1.8
MEDIUM 6.5
CVE-2019-10382
Jenkins VMware Lab Manager Slaves Plugin 0.2.8 and earlier disables SSL/TLS and hostname verification globally for the Jenkins master JVM.
Vmware Lab Manager Slaves
after 0.2.8
MEDIUM 6.5
CVE-2017-18479
In cPanel before 62.0.4, WHM SSL certificate generation uses an unreserved e-mail address (SEC-209).
Cpanel
11.54.0.36 / 56.0.43+
HIGH 8.1
CVE-2019-3890
It was discovered evolution-ews before 3.31.3 does not check the validity of SSL certificates. An attacker could abuse this flaw to get confidential …
Enterprise Linux
3.31.3+
MEDIUM 5.5
CVE-2019-14334
An issue was discovered on D-Link 6600-AP, DWL-3600AP, and DWL-8610AP Ax 4.2.0.14 21/03/2019 devices. There is post-authenticated Certificate and RSA…
6600 Ap Firmware
No fix yet
HIGH 7.4
CVE-2019-7615
A TLS certificate validation flaw was found in Elastic APM agent for Ruby versions before 2.9.0. When specifying a trusted server CA certificate via …
Apm Agent Ruby
2.9.0+
MEDIUM 5.3
CVE-2019-11727
A vulnerability exists where it possible to force Network Security Services (NSS) to sign CertificateVerify with PKCS#1 v1.5 signatures when those ar…
Firefox
68.0+
MEDIUM 5.9
CVE-2019-1010206
OSS Http Request (Apache Cordova Plugin) 6 is affected by: Missing SSL certificate validation. The impact is: certificate spoofing. The component is:…
Http Request
Mitigation only
MEDIUM 5.9
CVE-2019-1940
A vulnerability in the Web Services Management Agent (WSMA) feature of Cisco Industrial Network Director (IND) could allow an unauthenticated, remote…
Industrial Network Director
1.7+
CRITICAL 9.8
CVE-2019-1010275
helm Before 2.7.2 is affected by: CWE-295: Improper Certificate Validation. The impact is: Unauthorized clients could connect to the server because s…
Helm
2.7.2+
HIGH 7.5
CVE-2019-1006EPSS 6%
An authentication bypass vulnerability exists in Windows Communication Foundation (WCF) and Windows Identity Foundation (WIF), allowing signing of SA…
.net Framework
Patch available
HIGH 8.1
CVE-2019-11242
A man-in-the-middle vulnerability related to vCenter access was found in Cohesity DataPlatform version 5.x and 6.x prior to 6.1.1c. Cohesity clusters…
Dataplatform
6.1.1c+
HIGH 7.4
CVE-2019-5961
The Android App 'Tootdon for Mastodon' version 3.4.1 and earlier does not verify X.509 certificates from SSL servers, which allows man-in-the-middle …
Tootdon For Mastodon
after 3.4.1
HIGH 8.6
CVE-2019-1886
A vulnerability in the HTTPS decryption feature of Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to cause a deni…
Asyncos
10.5.5-005 / 11.5.2-020+
HIGH 7.5
CVE-2019-13050
Interaction between the sks-keyserver code through 1.2.0 of the SKS keyserver network, and GnuPG through 2.2.16, makes it risky to have a GnuPG keyse…
Fedora
after 5.1.0
CRITICAL 9.1
CVE-2017-17945
The ASUS HiVivo aspplication before 5.6.27 for ASUS Watch has Missing SSL Certificate Validation.
Hivivo
1.1.09 / 5.6.27+
CRITICAL 9.1
CVE-2017-17944
The ASUS Vivobaby application before 1.1.09 for Android has Missing SSL Certificate Validation.
Hivivo
1.1.09 / 5.6.27+
HIGH 7.4
CVE-2019-12855
In words.protocols.jabber.xmlstream in Twisted through 19.2.1, XMPP support did not verify certificates when used with TLS, allowing an attacker to M…
Twisted
after 19.2.1
MEDIUM 6.5
CVE-2019-10334
Jenkins ElectricFlow Plugin 1.1.5 and earlier disabled SSL/TLS and hostname verification globally for the Jenkins master JVM when MultipartUtility.ja…
Electricflow
after 1.1.5
HIGH 8.1
CVE-2018-20135
Samsung Galaxy Apps before 4.4.01.7 allows modification of the hostname used for load balancing on installations of applications through a man-in-the…
Galaxy Apps
4.4.01.7+
HIGH 7.5
CVE-2019-12496
An issue was discovered in Hybrid Group Gobot before 1.13.0. The mqtt subsystem skips verification of root CA certificates by default.
Gobot
1.13.0+
MEDIUM 5.9
CVE-2019-4264
IBM QRadar SIEM 7.2.8 WinCollect could allow an attacker to obtain sensitive information by spoofing a trusted entity using man in the middle techniq…
Qradar Security Information And Event Manager
7.2.8+
HIGH 7.4
CVE-2019-12098
In the client side of Heimdal before 7.6.0, failure to verify anonymous PKINIT PA-PKINIT-KX key exchange permits a man-in-the-middle attack. This iss…
Fedora
7.6.0+
MEDIUM 5.9
CVE-2019-11550
Citrix SD-WAN 10.2.x before 10.2.1 and NetScaler SD-WAN 10.0.x before 10.0.7 have Improper Certificate Validation.
Netscaler Sd Wan
10.0.7 / 10.2.1+
HIGH 7.4
CVE-2018-5408
The PrinterLogic Print Management software, versions up to and including 18.3.1.96, does not validate, or incorrectly validates, the PrinterLogic man…
Print Management
after 18.3.1.96