Vulnerability index

Browse CVEs

1,354 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Certificate ValidationCWE-295 × clear
HIGH 8.1 CVE-2016-10931 An issue was discovered in the openssl crate before 0.9.0 for Rust. There is an SSL/TLS man-in-the-middle vulnerability because certificate verificat… Rust Openssl 0.9.0+ Fix from $1,9502019-08-26 HIGH 8.1 CVE-2019-15525 There is Missing SSL Certificate Validation in the pw3270 terminal emulator before version 5.1. Pw3270 5.1+ Fix from $1,9502019-08-23 MEDIUM 5.9 CVE-2019-1948 A vulnerability in Cisco Webex Meetings Mobile (iOS) could allow an unauthenticated, remote attacker to gain unauthorized read access to sensitive da… Webex Meetings after 39.5 Fix from $1,6002019-08-21 MEDIUM 6.5 CVE-2019-5280 The SIP TLS module of Huawei CloudLink Phone 7900 with V600R019C10 has a TLS certificate verification vulnerability. Due to insufficient verification… Cloudlink Phone 7900 Firmware Mitigation only Fix from $1,6002019-08-13 HIGH 7.4 CVE-2019-14516 The mAadhaar application 1.2.7 for Android lacks SSL Certificate Validation, leading to man-in-the-middle attacks against requests for FAQs or Help. Maadhaar No fix yet Fix from $1,9502019-08-13 HIGH 7.5 CVE-2019-10381 Jenkins Codefresh Integration Plugin 1.8 and earlier disables SSL/TLS and hostname verification globally for the Jenkins master JVM. Codefresh Integration after 1.8 Fix from $1,9502019-08-07 MEDIUM 6.5 CVE-2019-10382 Jenkins VMware Lab Manager Slaves Plugin 0.2.8 and earlier disables SSL/TLS and hostname verification globally for the Jenkins master JVM. Vmware Lab Manager Slaves after 0.2.8 Fix from $1,6002019-08-07 MEDIUM 6.5 CVE-2017-18479 In cPanel before 62.0.4, WHM SSL certificate generation uses an unreserved e-mail address (SEC-209). Cpanel 11.54.0.36 / 56.0.43+ Fix from $1,6002019-08-05 HIGH 8.1 CVE-2019-3890 It was discovered evolution-ews before 3.31.3 does not check the validity of SSL certificates. An attacker could abuse this flaw to get confidential … Enterprise Linux 3.31.3+ Fix from $1,9502019-08-01 MEDIUM 5.5 CVE-2019-14334 An issue was discovered on D-Link 6600-AP, DWL-3600AP, and DWL-8610AP Ax 4.2.0.14 21/03/2019 devices. There is post-authenticated Certificate and RSA… 6600 Ap Firmware No fix yet Fix from $1,6002019-08-01 HIGH 7.4 CVE-2019-7615 A TLS certificate validation flaw was found in Elastic APM agent for Ruby versions before 2.9.0. When specifying a trusted server CA certificate via … Apm Agent Ruby 2.9.0+ Fix from $1,9502019-07-30 MEDIUM 5.3 CVE-2019-11727 A vulnerability exists where it possible to force Network Security Services (NSS) to sign CertificateVerify with PKCS#1 v1.5 signatures when those ar… Firefox 68.0+ Fix from $1,6002019-07-23 MEDIUM 5.9 CVE-2019-1010206 OSS Http Request (Apache Cordova Plugin) 6 is affected by: Missing SSL certificate validation. The impact is: certificate spoofing. The component is:… Http Request Mitigation only Fix from $1,6002019-07-23 MEDIUM 5.9 CVE-2019-1940 A vulnerability in the Web Services Management Agent (WSMA) feature of Cisco Industrial Network Director (IND) could allow an unauthenticated, remote… Industrial Network Director 1.7+ Fix from $1,6002019-07-17 CRITICAL 9.8 CVE-2019-1010275 helm Before 2.7.2 is affected by: CWE-295: Improper Certificate Validation. The impact is: Unauthorized clients could connect to the server because s… Helm 2.7.2+ Fix from $2,3002019-07-17 HIGH 7.5 CVE-2019-1006EPSS 6% An authentication bypass vulnerability exists in Windows Communication Foundation (WCF) and Windows Identity Foundation (WIF), allowing signing of SA… .net Framework Patch available Fix from $1,9502019-07-15 HIGH 8.1 CVE-2019-11242 A man-in-the-middle vulnerability related to vCenter access was found in Cohesity DataPlatform version 5.x and 6.x prior to 6.1.1c. Cohesity clusters… Dataplatform 6.1.1c+ Fix from $1,9502019-07-12 HIGH 7.4 CVE-2019-5961 The Android App 'Tootdon for Mastodon' version 3.4.1 and earlier does not verify X.509 certificates from SSL servers, which allows man-in-the-middle … Tootdon For Mastodon after 3.4.1 Fix from $1,9502019-07-05 HIGH 8.6 CVE-2019-1886 A vulnerability in the HTTPS decryption feature of Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to cause a deni… Asyncos 10.5.5-005 / 11.5.2-020+ Fix from $1,9502019-07-04 HIGH 7.5 CVE-2019-13050 Interaction between the sks-keyserver code through 1.2.0 of the SKS keyserver network, and GnuPG through 2.2.16, makes it risky to have a GnuPG keyse… Fedora after 5.1.0 Fix from $1,9502019-06-29 CRITICAL 9.1 CVE-2017-17945 The ASUS HiVivo aspplication before 5.6.27 for ASUS Watch has Missing SSL Certificate Validation. Hivivo 1.1.09 / 5.6.27+ Fix from $2,3002019-06-24 CRITICAL 9.1 CVE-2017-17944 The ASUS Vivobaby application before 1.1.09 for Android has Missing SSL Certificate Validation. Hivivo 1.1.09 / 5.6.27+ Fix from $2,3002019-06-20 HIGH 7.4 CVE-2019-12855 In words.protocols.jabber.xmlstream in Twisted through 19.2.1, XMPP support did not verify certificates when used with TLS, allowing an attacker to M… Twisted after 19.2.1 Fix from $1,9502019-06-16 MEDIUM 6.5 CVE-2019-10334 Jenkins ElectricFlow Plugin 1.1.5 and earlier disabled SSL/TLS and hostname verification globally for the Jenkins master JVM when MultipartUtility.ja… Electricflow after 1.1.5 Fix from $1,6002019-06-11 HIGH 8.1 CVE-2018-20135 Samsung Galaxy Apps before 4.4.01.7 allows modification of the hostname used for load balancing on installations of applications through a man-in-the… Galaxy Apps 4.4.01.7+ Fix from $1,9502019-06-07 HIGH 7.5 CVE-2019-12496 An issue was discovered in Hybrid Group Gobot before 1.13.0. The mqtt subsystem skips verification of root CA certificates by default. Gobot 1.13.0+ Fix from $1,9502019-05-31 MEDIUM 5.9 CVE-2019-4264 IBM QRadar SIEM 7.2.8 WinCollect could allow an attacker to obtain sensitive information by spoofing a trusted entity using man in the middle techniq… Qradar Security Information And Event Manager 7.2.8+ Fix from $1,6002019-05-29 HIGH 7.4 CVE-2019-12098 In the client side of Heimdal before 7.6.0, failure to verify anonymous PKINIT PA-PKINIT-KX key exchange permits a man-in-the-middle attack. This iss… Fedora 7.6.0+ Fix from $1,9502019-05-15 MEDIUM 5.9 CVE-2019-11550 Citrix SD-WAN 10.2.x before 10.2.1 and NetScaler SD-WAN 10.0.x before 10.0.7 have Improper Certificate Validation. Netscaler Sd Wan 10.0.7 / 10.2.1+ Fix from $1,6002019-05-08 HIGH 7.4 CVE-2018-5408 The PrinterLogic Print Management software, versions up to and including 18.3.1.96, does not validate, or incorrectly validates, the PrinterLogic man… Print Management after 18.3.1.96 Fix from $1,9502019-05-08