Vulnerability index

Browse CVEs

1,344 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Certificate ValidationCWE-295 × clear
HIGH 8.7 CVE-2026-47074 Improper Certificate Validation vulnerability in ex-aws ex_aws_sns (ExAws.SNS, ExAws.SNS.PublicKeyCache modules) allows Signature Spoofing by Imprope… Patch available Fix from $1,9502026-05-28 HIGH 8.1 CVE-2026-42790 Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_cert and public_key modules) allows a DNS nameConstraints bypass via s… Erlang\/otp 26.2.5.21 / 27.3.4.12+ Fix from $1,9502026-05-27 HIGH 8.1 CVE-2026-45574 epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. Prior to 1.2.2, an attacker on the network path between the e… Patch available Fix from $1,9502026-05-26 HIGH 8.2 CVE-2026-42013 A flaw was found in gnutls. When validating certificates, an oversized Subject Alternative Name (SAN) could cause the validation process to incorrect… Mitigation only Fix from $1,9502026-05-26 MEDIUM 6.5 CVE-2026-44213 The OpenTelemetry.Exporter.Instana exports telemetry to Instana backend. Prior to 1.1.0, the OpenTelemetry.Exporter.Instana NuGet package does not va… Mitigation only Fix from $1,6002026-05-26 HIGH 8.1 CVE-2026-44900 epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. Prior to 1.2.1, in SignedPublicKeysTrustValidatorImpl.isTrus… Patch available Fix from $1,9502026-05-26 HIGH 7.1 CVE-2026-42012 A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted certificate that contains Uniform Re… Mitigation only Fix from $1,9502026-05-26 HIGH 7.4 CVE-2026-48697 FastNetMon Community Edition through 1.2.9 does not verify TLS certificates on outbound HTTPS connections. The execute_web_request_secure() function … Fastnetmon after 1.2.9 Fix from $1,9502026-05-26 CRITICAL 9.3 CVE-2026-9058 For untrusted certificates that contain the "Authority Information Access - caIssuers URI" extension, Szafir SDK will automatically download the pare… Mitigation only Fix from $2,3002026-05-25 CRITICAL 9.8 CVE-2026-32253 Sunshine is a self-hosted game stream host for Moonlight. In versions prior to 2026.516.143833, the client-certificate authentication can be bypassed… Sunshine 2026.516.143833+ Fix from $2,3002026-05-22 HIGH 8.8 CVE-2026-8992 An improper certificate validation vulnerability in Ivanti Secure Access Client before 22.8R6 allows a remote unauthenticated attacker to execute arb… Secure Access Client after 22.7 Fix from $1,9502026-05-22 MEDIUM 6.5 CVE-2025-32745 Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent ne… Powerflex Appliance Intelligent Catalog 3.7.8.0 / 48.383.00+ Fix from $1,6002026-05-22 CRITICAL 9.1 CVE-2026-42508 Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now, both the 'key' and 'key.SignatureKey' are check… Crypto 0.52.0+ Fix from $2,3002026-05-22 MEDIUM 5.3 CVE-2026-39835 SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be caused to panic by a client pr… Crypto 0.52.0+ Fix from $1,6002026-05-22 MEDIUM 6.3 CVE-2026-39828 When an SSH server authentication callback returned PartialSuccessError with non-nil Permissions, those permissions were silently discarded, potentia… Crypto 0.52.0+ Fix from $1,6002026-05-22 MEDIUM 5.9 CVE-2026-48248 Open ISES Tickets before 3.44.2 disables TLS certificate verification in incs/login.inc.php by setting CURLOPT_SSL_VERIFYPEER to false (and not setti… Patch available Fix from $1,6002026-05-21 MEDIUM 5.9 CVE-2026-48249 Open ISES Tickets before 3.44.2 disables TLS certificate verification in rm/incs/mobile_login.inc.php by setting CURLOPT_SSL_VERIFYPEER to false (and… Patch available Fix from $1,6002026-05-21 MEDIUM 5.9 CVE-2026-48246 Open ISES Tickets before 3.44.2 disables TLS certificate verification in ajax/reports.php by setting CURLOPT_SSL_VERIFYPEER to false (and not setting… Patch available Fix from $1,6002026-05-21 MEDIUM 5.9 CVE-2026-48247 Open ISES Tickets before 3.44.2 disables TLS certificate verification in incs/functions.inc.php by setting CURLOPT_SSL_VERIFYPEER to false (and not s… Patch available Fix from $1,6002026-05-21 MEDIUM 6.8 CVE-2026-41119 Dell Live Optics Windows and Personal Edition collectors contain an improper certificate validation vulnerability. A remote unauthenticated attacker … Mitigation only Fix from $1,6002026-05-18 MEDIUM 5.3 CVE-2026-44309 Gitsign is a keyless Sigstore to signing tool for Git commits with your a GitHub / OIDC identity. Prior to 0.16.0, gitsign verify and gitsign verify-… Mitigation only Fix from $1,6002026-05-15 HIGH 8.7 CVE-2026-44700 Elixir WebRTC is an Elixir implementation of the W3C WebRTC API. Prior to 0.15.1 and 0.16.1, missing DTLS peer certificate fingerprint validation in … Patch available Fix from $1,9502026-05-14 HIGH 7.5 CVE-2026-23998 Fleet is open source device management software. Prior to version 4.81.0, a vulnerability in Fleet’s Windows MDM management endpoint could allow requ… Fleet 4.81.0+ Fix from $1,9502026-05-14 MEDIUM 5.8 CVE-2026-44312 css_parser is a Ruby CSS parser. Prior to 2.1.0 and 1.22.0, the CSS Parser gem does not validate HTTPS connections, allowing a Man-in-the-Middle (MIT… Patch available Fix from $1,6002026-05-14 HIGH 8.2 CVE-2026-32992 SSL verification is disabled in the DNS Cluster system. This could allow for a malicious server to man-in-the-middle the request and capture credenti… Wp Squared 126.0.59 / 130.0.23+ Fix from $1,9502026-05-13 MEDIUM 5.8 CVE-2026-44363 MISP modules are autonomous modules that can be used to extend MISP for new services. Prior to 3.0.7, an unsafe remote resource fetching vulnerabilit… Patch available Fix from $1,6002026-05-13 HIGH 7.4 CVE-2026-41132 CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Prior to 2.10.10 and 2.11.5, the configured SMTP server … Ckan 2.10.10 / 2.11.5+ Fix from $1,9502026-05-13 MEDIUM 6.5 CVE-2026-0249 Multiple improper certificate validation vulnerabilities in the Palo Alto Networks GlobalProtect™ app enables an attacker to intercept encrypted comm… Globalprotect 6.0.13 / 6.0.14+ Fix from $1,6002026-05-13 HIGH 8.1 CVE-2026-0244 An improper certificate validation vulnerability in the Palo Alto Networks Prisma SD-WAN ION enables man-in-the-middle (MitM) attacker to impersonate… Prisma Sd Wan 6.3.6 / 6.4.3+ Fix from $1,9502026-05-13 MEDIUM 5.9 CVE-2026-0248 An improper certificate validation vulnerability in the Prisma Access Agent® for Android and Chrome OS enables an attacker to perform a man-in-the-mi… Prisma Access Agent 26.2.1+ Fix from $1,6002026-05-13