Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 5.3
CVE-2026-7009
When curl is told to use the Certificate Status Request TLS extension, often
referred to as *OCSP stapling*, to verify that the server certificate is…
Curl
8.20.0+
MEDIUM 5.9
CVE-2026-4873
A vulnerability exists where a connection requiring TLS incorrectly reuses an
existing unencrypted connection from the same connection pool. If an in…
Curl
8.20.0+
MEDIUM 6.8
CVE-2026-44305
Lemur manages TLS certificate creation. Prior to 1.9.0, when LDAP TLS is enabled (LDAP_USE_TLS = True), Lemur's LDAP authentication module unconditio…
Mitigation only
HIGH 7.4
CVE-2026-41872
"Kura Sushi Official App" provided by EPG, Inc. is vulnerable to improper certificate validation. A man-in-the-middle attack may allow eavesdropping …
Mitigation only
MEDIUM 6.8
CVE-2026-42312
pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the set_config_value() API method (@permission(Perms.SE…
Pyload Ng
0.5.0b3.dev100+
MEDIUM 5.1
CVE-2026-42213
SolidCAM-GPPL-IDE is an unofficial, independently developed extension, Postprocessor IDE for SolidCAM. From version 1.0.0 to before version 1.0.2, th…
Patch available
MEDIUM 5.9
CVE-2026-42225
PJSIP is a free and open source multimedia communication library written in C. Prior to version 2.17, on GnuTLS builds, the SIP TLS transport (sip_tr…
Pjsip
2.17+
CRITICAL 9.1
CVE-2026-7821
Improper certificate validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to enroll a …
Endpoint Manager Mobile
12.6.1.1+
CRITICAL 9.1
CVE-2026-5787
An Improper Certificate Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to impers…
Endpoint Manager Mobile
12.6.1.1+
HIGH 7.4
CVE-2026-42011
A flaw was found in gnutls. This vulnerability occurs because permitted name constraints were incorrectly ignored when previous Certificate Authoriti…
Mitigation only
MEDIUM 5.3
CVE-2026-6860
A TCP client can perform a TLS handshake and present the server name extension with a server name that is accepted by a server wildcard name, e.g. if…
Vert.x
after 5.0.11
MEDIUM 6.5
CVE-2025-42611
RouterOS provides various services that rely on correct
verification of client and server certificates to secure confidentiality and
integrity of com…
Mitigation only
HIGH 7.3
CVE-2026-43869
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift.
This issue affects Apache Thrift: before 0.23.0.
Users are re…
Thrift
0.23.0+
MEDIUM 5.9
CVE-2026-41016
Apache Airflow's SMTP provider `SmtpHook` called Python's `smtplib.SMTP.starttls()` without an SSL context, so no certificate validation was performe…
Airflow
3.0.0+
HIGH 7.4
CVE-2026-41603
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift.
This issue affects Apache Thrift: before 0.23.0.
Users are re…
Thrift
0.23.0+
CRITICAL 9.8
CVE-2026-40974
Spring Boot's Cassandra auto-configuration does not perform hostname verification when establishing an SSL connection to Cassandra.
Affected: Spring…
Spring Boot
2.7.33 / 3.3.19+
CRITICAL 9.1
CVE-2026-40971
When configured to use an SSL bundle, Spring Boot's RabbitMQ auto-configuration does not perform hostname verification when connecting to the RabbitM…
Spring Boot
3.5.14 / 4.0.6+
MEDIUM 6.8
CVE-2026-40970
When configured to use an SSL bundle, Spring Boot's Elasticsearch auto-configuration does not perform hostname verification when connecting to the El…
Spring Boot
4.0.6+
HIGH 8.1
CVE-2026-22747
Vulnerability in Spring Spring Security. SubjectX500PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which…
Spring Security
7.0.5+
MEDIUM 6.9
CVE-2026-40944
Oxia is a metadata store and coordination system. Prior to 0.16.2, the trustedCertPool() function in the TLS configuration only parses the first PEM …
Mitigation only
HIGH 8.8
CVE-2026-23776
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.…
Powerprotect Dp Series Appliance
2.7.9 / 7.13.1.70+
CRITICAL 9.8
CVE-2026-20184
A vulnerability in the integration of single sign-on (SSO) with Control Hub in Cisco Webex Services could have allowed an unauthenticated, remote att…
Mitigation only
MEDIUM 5.5
CVE-2026-39984
Sigstore Timestamp Authority is a service for issuing RFC 3161 timestamps. Versions 2.0.5 and below contain an authorization bypass vulnerability in …
Sigstore Timestamp Authority
2.0.6+
HIGH 8.8
CVE-2026-0233
A certificate validation vulnerability in Palo Alto Networks Autonomous Digital Experience Manager on Windows allows an unauthenticated attacker with…
Autonomous Digital Experience Manager
5.10.14+
MEDIUM 5.9
CVE-2026-34477
The fix for CVE-2025-68161 https://logging.apache.org/security.html#CVE-2025-68161 was incomplete: it addressed hostname verification only when ena…
Log4j
2.25.4+
HIGH 8.1
CVE-2026-5501
wolfSSL_X509_verify_cert in the OpenSSL compatibility layer accepts a certificate chain in which the leaf's signature is not checked, if the attacker…
Wolfssl
after 5.9.0
MEDIUM 6.5
CVE-2026-5263
URI nameConstraints from constrained intermediate CAs are parsed but not enforced during certificate chain verification in wolfcrypt/src/asn.c. A com…
Wolfssl
5.9.1+
CRITICAL 9.1
CVE-2026-5194
Missing hash/digest size and OID checks allow digests smaller than allowed when verifying ECDSA certificates, or smaller than is appropriate for the …
Wolfssl
5.9.1+
MEDIUM 5.4
CVE-2026-35207
dde-control-center is the control panel of DDE, the Deepin Desktop Environment. plugin-deepinid is a plugin in dde-control-center, which provides the…
Patch available
HIGH 7.5
CVE-2026-33753
rfc3161-client is a Python library implementing the Time-Stamp Protocol (TSP) described in RFC 3161. Prior to 1.0.6, an Authorization Bypass vulnerab…
Rfc3161 Client
1.0.6+