Vulnerability index

Browse CVEs

1,344 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Certificate ValidationCWE-295 × clear
MEDIUM 5.3 CVE-2026-7009 When curl is told to use the Certificate Status Request TLS extension, often referred to as *OCSP stapling*, to verify that the server certificate is… Curl 8.20.0+ Fix from $1,6002026-05-13 MEDIUM 5.9 CVE-2026-4873 A vulnerability exists where a connection requiring TLS incorrectly reuses an existing unencrypted connection from the same connection pool. If an in… Curl 8.20.0+ Fix from $1,6002026-05-13 MEDIUM 6.8 CVE-2026-44305 Lemur manages TLS certificate creation. Prior to 1.9.0, when LDAP TLS is enabled (LDAP_USE_TLS = True), Lemur's LDAP authentication module unconditio… Mitigation only Fix from $1,6002026-05-12 HIGH 7.4 CVE-2026-41872 "Kura Sushi Official App" provided by EPG, Inc. is vulnerable to improper certificate validation. A man-in-the-middle attack may allow eavesdropping … Mitigation only Fix from $1,9502026-05-12 MEDIUM 6.8 CVE-2026-42312 pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the set_config_value() API method (@permission(Perms.SE… Pyload Ng 0.5.0b3.dev100+ Fix from $1,6002026-05-11 MEDIUM 5.1 CVE-2026-42213 SolidCAM-GPPL-IDE is an unofficial, independently developed extension, Postprocessor IDE for SolidCAM. From version 1.0.0 to before version 1.0.2, th… Patch available Fix from $1,6002026-05-08 MEDIUM 5.9 CVE-2026-42225 PJSIP is a free and open source multimedia communication library written in C. Prior to version 2.17, on GnuTLS builds, the SIP TLS transport (sip_tr… Pjsip 2.17+ Fix from $1,6002026-05-07 CRITICAL 9.1 CVE-2026-7821 Improper certificate validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to enroll a … Endpoint Manager Mobile 12.6.1.1+ Fix from $2,3002026-05-07 CRITICAL 9.1 CVE-2026-5787 An Improper Certificate Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to impers… Endpoint Manager Mobile 12.6.1.1+ Fix from $2,3002026-05-07 HIGH 7.4 CVE-2026-42011 A flaw was found in gnutls. This vulnerability occurs because permitted name constraints were incorrectly ignored when previous Certificate Authoriti… Mitigation only Fix from $1,9502026-05-07 MEDIUM 5.3 CVE-2026-6860 A TCP client can perform a TLS handshake and present the server name extension with a server name that is accepted by a server wildcard name, e.g. if… Vert.x after 5.0.11 Fix from $1,6002026-05-06 MEDIUM 6.5 CVE-2025-42611 RouterOS provides various services that rely on correct verification of client and server certificates to secure confidentiality and integrity of com… Mitigation only Fix from $1,6002026-05-05 HIGH 7.3 CVE-2026-43869 Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are re… Thrift 0.23.0+ Fix from $1,9502026-05-05 MEDIUM 5.9 CVE-2026-41016 Apache Airflow's SMTP provider `SmtpHook` called Python's `smtplib.SMTP.starttls()` without an SSL context, so no certificate validation was performe… Airflow 3.0.0+ Fix from $1,6002026-04-30 HIGH 7.4 CVE-2026-41603 Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are re… Thrift 0.23.0+ Fix from $1,9502026-04-28 CRITICAL 9.8 CVE-2026-40974 Spring Boot's Cassandra auto-configuration does not perform hostname verification when establishing an SSL connection to Cassandra. Affected: Spring… Spring Boot 2.7.33 / 3.3.19+ Fix from $2,3002026-04-28 CRITICAL 9.1 CVE-2026-40971 When configured to use an SSL bundle, Spring Boot's RabbitMQ auto-configuration does not perform hostname verification when connecting to the RabbitM… Spring Boot 3.5.14 / 4.0.6+ Fix from $2,3002026-04-27 MEDIUM 6.8 CVE-2026-40970 When configured to use an SSL bundle, Spring Boot's Elasticsearch auto-configuration does not perform hostname verification when connecting to the El… Spring Boot 4.0.6+ Fix from $1,6002026-04-27 HIGH 8.1 CVE-2026-22747 Vulnerability in Spring Spring Security. SubjectX500PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which… Spring Security 7.0.5+ Fix from $1,9502026-04-22 MEDIUM 6.9 CVE-2026-40944 Oxia is a metadata store and coordination system. Prior to 0.16.2, the trustedCertPool() function in the TLS configuration only parses the first PEM … Mitigation only Fix from $1,6002026-04-21 HIGH 8.8 CVE-2026-23776 Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.… Powerprotect Dp Series Appliance 2.7.9 / 7.13.1.70+ Fix from $1,9502026-04-17 CRITICAL 9.8 CVE-2026-20184 A vulnerability in the integration of single sign-on (SSO) with Control Hub in Cisco Webex Services could have allowed an unauthenticated, remote att… Mitigation only Fix from $2,3002026-04-15 MEDIUM 5.5 CVE-2026-39984 Sigstore Timestamp Authority is a service for issuing RFC 3161 timestamps. Versions 2.0.5 and below contain an authorization bypass vulnerability in … Sigstore Timestamp Authority 2.0.6+ Fix from $1,6002026-04-15 HIGH 8.8 CVE-2026-0233 A certificate validation vulnerability in Palo Alto Networks Autonomous Digital Experience Manager on Windows allows an unauthenticated attacker with… Autonomous Digital Experience Manager 5.10.14+ Fix from $1,9502026-04-13 MEDIUM 5.9 CVE-2026-34477 The fix for CVE-2025-68161 https://logging.apache.org/security.html#CVE-2025-68161 was incomplete: it addressed hostname verification only when ena… Log4j 2.25.4+ Fix from $1,6002026-04-10 HIGH 8.1 CVE-2026-5501 wolfSSL_X509_verify_cert in the OpenSSL compatibility layer accepts a certificate chain in which the leaf's signature is not checked, if the attacker… Wolfssl after 5.9.0 Fix from $1,9502026-04-10 MEDIUM 6.5 CVE-2026-5263 URI nameConstraints from constrained intermediate CAs are parsed but not enforced during certificate chain verification in wolfcrypt/src/asn.c. A com… Wolfssl 5.9.1+ Fix from $1,6002026-04-09 CRITICAL 9.1 CVE-2026-5194 Missing hash/digest size and OID checks allow digests smaller than allowed when verifying ECDSA certificates, or smaller than is appropriate for the … Wolfssl 5.9.1+ Fix from $2,3002026-04-09 MEDIUM 5.4 CVE-2026-35207 dde-control-center is the control panel of DDE, the Deepin Desktop Environment. plugin-deepinid is a plugin in dde-control-center, which provides the… Patch available Fix from $1,6002026-04-09 HIGH 7.5 CVE-2026-33753 rfc3161-client is a Python library implementing the Time-Stamp Protocol (TSP) described in RFC 3161. Prior to 1.0.6, an Authorization Bypass vulnerab… Rfc3161 Client 1.0.6+ Fix from $1,9502026-04-08