Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.4
CVE-2018-15784
Dell Networking OS10 versions prior to 10.4.3.0 contain a vulnerability in the Phone Home feature which does not properly validate the server's certi…
Networking Os10
10.4.3.0+
MEDIUM 5.9
CVE-2018-16187
The RICOH Interactive Whiteboard D2200 V1.3 to V2.2, D5500 V1.3 to V2.2, D5510 V1.3 to V2.2, the display versions with RICOH Interactive Whiteboard C…
D2200 Firmware
after 3.1.10137.0
MEDIUM 5.9
CVE-2018-16179
The Mizuho Direct App for Android version 3.13.0 and earlier does not verify server certificates, which allows man-in-the-middle attackers to spoof s…
Mizuho Direct Application
after 3.13.0
HIGH 7.5
CVE-2018-1320EPSS 8%
Apache Thrift Java client library versions 0.5.0 through 0.11.0 can bypass SASL negotiation isComplete validation in the org.apache.thrift.transport.…
Thrift
11.2.0.3.23 / 12.2.0.1.19+
HIGH 8.1
CVE-2018-4015
An exploitable vulnerability exists in the HTTP client functionality of the Webroot BrightCloud SDK. The configuration of the HTTP client does not en…
Brightcloud
Mitigation only
MEDIUM 5.9
CVE-2017-1265
IBM Security Guardium 10.0, 10.0.1, 10.1, 10.1.2, 10.1.3, 10.1.4, and 10.5 does not validate, or incorrectly validates, a certificate. This weakness …
Security Guardium
after 10.5
HIGH 7.5
CVE-2018-16875EPSS 6%
The crypto/x509 package of Go before 1.10.6 and 1.11.x before 1.11.3 does not limit the amount of work performed for each chain verification, which m…
Go
1.10.6 / 1.11.3+
MEDIUM 5.3
CVE-2018-19982
An issue was discovered on KT MC01507L Z-Wave S0 devices. It occurs because HPKP is not implemented. The communication architecture is APP > Server >…
Kt Mc01507l Z Wave S0 Firmware
Mitigation only
HIGH 7.4
CVE-2017-1622
IBM QRadar SIEM 7.2.8 and 7.3 does not validate, or incorrectly validates, a certificate. This weakness might allow an attacker to spoof a trusted en…
Qradar Incident Forensics
7.2.8 / 7.3.1+
MEDIUM 5.9
CVE-2018-0691
Multiple +Message Apps (Softbank +Message App for Android prior to version 10.1.7, Softbank +Message App for iOS prior to version 1.1.23, NTT DOCOMO …
\+ Message
1.0.6 / 1.1.23+
HIGH 7.4
CVE-2018-17187
The Apache Qpid Proton-J transport includes an optional wrapper layer to perform TLS, enabled by use of the 'transport.ssl(...)' methods. Unless a ve…
Qpid Proton J
after 0.29.0
HIGH 7.5
CVE-2018-17612EPSS 7%
Sennheiser HeadSetup 7.3.4903 places Certification Authority (CA) certificates into the Trusted Root CA store of the local system, and publishes the …
Headsetup
Patch available
HIGH 7.5
CVE-2018-15326
In some situations on BIG-IP APM 14.0.0-14.0.0.2, 13.0.0-13.1.0.7, 12.1.0-12.1.3.5, or 11.6.0-11.6.3.2, the CRLDP Auth access policy agent may treat …
Big Ip Access Policy Manager
after 14.0.0.2
MEDIUM 5.9
CVE-2018-18567
AudioCodes 440HD and 450HD devices 3.1.2.89 and earlier allows man-in-the-middle attackers to obtain sensitive credential information by leveraging f…
440hd Firmware
after 3.1.2.89
MEDIUM 5.9
CVE-2018-18568
Polycom VVX 500 and 601 devices 5.8.0.12848 and earlier allows man-in-the-middle attackers to obtain sensitive credential information by leveraging f…
Unified Communications Software
after 5.8.0.12848
CRITICAL 9.8
CVE-2018-15387
A vulnerability in the Cisco SD-WAN Solution could allow an unauthenticated, remote attacker to bypass certificate validation on an affected device. …
Sd Wan
17.2.8+
HIGH 7.4
CVE-2018-0434
A vulnerability in the Zero Touch Provisioning feature of the Cisco SD-WAN Solution could allow an unauthenticated, remote attacker to gain unauthori…
Vedge 100 Firmware
18.3.0+
MEDIUM 5.3
CVE-2018-12087
Failure to validate certificates in OPC Foundation UA Client Applications communicating without security allows attackers with control over a piece o…
Ua .net Legacy
Mitigation only
HIGH 7.4
CVE-2018-1509
IBM Security Guardium EcoSystem 10.5 does not validate, or incorrectly validates, a certificate.This weakness might allow an attacker to spoof a trus…
Security Guardium
Mitigation only
HIGH 8.1
CVE-2018-17215
An information-disclosure issue was discovered in Postman through 6.3.0. It validates a server's X.509 certificate and presents an error if the certi…
Postman
after 6.3.0
MEDIUM 5.9
CVE-2018-11087
Pivotal Spring AMQP, 1.x versions prior to 1.7.10 and 2.x versions prior to 2.0.6, expose a man-in-the-middle vulnerability due to lack of hostname v…
Rabbitmq Java Client
1.7.10 / 2.0.6+
MEDIUM 5.6
CVE-2018-8479
A spoofing vulnerability exists for the Azure IoT Device Provisioning for the C SDK library using the HTTP protocol on Windows platform, aka "Azure I…
C Software Development Kit
Patch available
MEDIUM 5.9
CVE-2018-15898
The Subsonic Music Streamer application 4.4 for Android has Improper Certificate Validation of the Subsonic server certificate, which might allow man…
Music Streamer
No fix yet
MEDIUM 5.9
CVE-2018-2460
SAP Business One Android application, version 1.2, does not verify the certificate properly for HTTPS connection. This allows attacker to do MITM att…
Business One
Mitigation only
HIGH 7.4
CVE-2018-11775EPSS 7%
TLS hostname verification when using the Apache ActiveMQ Client before 5.15.6 was missing which could make the client vulnerable to a MITM attack bet…
Activemq
5.15.6+
HIGH 7.5
CVE-2018-12608
An issue was discovered in Docker Moby before 17.06.0. The Docker engine validated a client TLS certificate using both the configured client CA root …
Moby
17.06.0+
HIGH 8.1
CVE-2016-7075
It was found that Kubernetes as used by Openshift Enterprise 3 did not correctly validate X.509 client intermediate certificate host name fields. An …
Kubernetes
Patch available
HIGH 7.4
CVE-2018-0650
The LINE MUSIC for Android version 3.1.0 to versions prior to 3.6.5 does not verify X.509 certificates from SSL servers, which allows man-in-the-midd…
Line Music
3.6.5+
MEDIUM 6.8
CVE-2018-16261
In Pulse Secure Pulse Desktop Client 5.3RX before 5.3R5 and 9.0R1, there is a Privilege Escalation Vulnerability with Dynamic Certificate Trust.
Pulse Secure Desktop Client
Mitigation only
MEDIUM 5.9
CVE-2018-1000664
daneren2005 DSub for Subsonic (Android client) version 5.4.1 contains a CWE-295: Improper Certificate Validation vulnerability in HTTPS Client that c…
Dsub For Subsonic
Mitigation only