Vulnerability index

Browse CVEs

1,344 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Certificate ValidationCWE-295 × clear
HIGH 7.5 CVE-2026-32281 Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a very large number of policy map… Go 1.25.9 / 1.26.2+ Fix from $1,9502026-04-08 HIGH 8.2 CVE-2026-33810 When verifying a certificate chain containing excluded DNS constraints, these constraints are not correctly applied to wildcard DNS SANs which use a … Go 1.26.2+ Fix from $1,9502026-04-08 HIGH 7.5 CVE-2026-34580 Botan is a C++ cryptography library. In 3.11.0, the function Certificate_Store::certificate_known had a misleading name; it would return true if any … Botan Mitigation only Fix from $1,9502026-04-07 HIGH 8.2 CVE-2026-4740 A flaw was found in Open Cluster Management (OCM), the technology underlying Red Hat Advanced Cluster Management (ACM). Improper validation of Kubern… Advanced Cluster Management For Kubernetes No fix yet Fix from $1,9502026-04-07 HIGH 7.4 CVE-2026-32144 Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_ocsp module) allows OCSP designated-responder authorization bypass via… Erlang\/otp 1.17.1.2 / 1.20.3+ Fix from $1,9502026-04-07 HIGH 7.5 CVE-2026-35389 Bulwark Webmail is a self-hosted webmail client for Stalwart Mail Server. Prior to 1.4.11, S/MIME signature verification did not validate the certifi… Webmail 1.4.11+ Fix from $1,9502026-04-06 MEDIUM 5.9 CVE-2026-35560 Improper certificate validation in the identity provider connection components in Amazon Athena ODBC driver before 2.1.0.0 might allow a man-in-the-m… Athena Odbc 2.1.0.0+ Fix from $1,6002026-04-03 MEDIUM 5.3 CVE-2026-29140 SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to cause attacker-controlled certificates to be used for future encryption to … Secure Email Gateway 15.0.3+ Fix from $1,6002026-04-02 MEDIUM 6.5 CVE-2026-25834 Mbed TLS v3.3.0 up to 3.6.5 and 4.0.0 allows Algorithm Downgrade. Mbed Tls 3.6.6+ Fix from $1,6002026-04-01 MEDIUM 6.5 CVE-2026-20042 A vulnerability in the configuration backup feature of Cisco Nexus Dashboard could allow an attacker who has the encryption password and access to Fu… Nexus Dashboard 4.2.1+ Fix from $1,6002026-04-01 CRITICAL 10.0 CVE-2026-4370 A vulnerability was identified in Juju from version 3.2.0 until 3.6.19 and from version 4.0 until 4.0.4, where the internal Dqlite database cluster f… Juju 3.6.20 / 4.0.5+ Fix from $2,3002026-04-01 MEDIUM 5.3 CVE-2026-34073 cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to version 46.0.6, DNS name constraints… Cryptography 46.0.6+ Fix from $1,6002026-03-31 MEDIUM 5.9 CVE-2026-32884 Botan is a C++ cryptography library. Prior to version 3.11.0, during processing of an X.509 certificate path using name constraints which restrict th… Botan 3.11.0+ Fix from $1,6002026-03-30 HIGH 7.5 CVE-2019-25652 UniFi Network Controller before version 5.10.22 and 5.11.x before 5.11.18 contains an improper certificate verification vulnerability that allows adj… Mitigation only Fix from $1,9502026-03-27 CRITICAL 9.1 CVE-2026-33896 Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, `pki.verifyCertificate… Forge after 1.3.3 Fix from $2,3002026-03-27 HIGH 8.1 CVE-2025-15612 Wazuh provisioning scripts and Dockerfiles contain an insecure transport vulnerability where curl is invoked with the -k/--insecure flag, disabling S… Wazuh 4.14.0+ Fix from $1,9502026-03-27 MEDIUM 5.9 CVE-2026-33308 Mod_gnutls is a TLS module for Apache HTTPD based on GnuTLS. Prior to version 0.13.0, code for client certificate verification did not check the key … Mod Gnutls 0.13.0+ Fix from $1,6002026-03-24 HIGH 8.1 CVE-2026-4434 Improper certificate validation in the PAM propagation WinRM connections allows a network attacker to perform a man-in-the-middle attack via disabl… Devolutions Server 2026.1.6.0+ Fix from $1,9502026-03-20 CRITICAL 10.0 CVE-2026-30836 Step CA is an online certificate authority for secure, automated certificate management for DevOps. Versions 0.30.0-rc6 and below do not safeguard ag… Step Ca 0.30.0+ Fix from $2,3002026-03-19 HIGH 8.1 CVE-2026-4396 Improper certificate validation in Devolutions Hub Reporting Service 2025.3.1.1 and earlier allows a network attacker to perform a man-in-the-middl… Hub Reporting Service 2026.1.1.0+ Fix from $1,9502026-03-18 HIGH 8.1 CVE-2026-32627 cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.37.2, when a cpp-httplib client is configured with a pro… Cpp Httplib 0.37.2+ Fix from $1,9502026-03-16 MEDIUM 5.0 CVE-2026-31798 JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to v4.10.16-lts, JumpServer improperly valida… Jumpserver 4.10.16+ Fix from $1,6002026-03-13 HIGH 7.1 CVE-2026-2368 An improper certificate validation vulnerability was reported in the Lenovo Filez application that could allow a user capable of intercepting network… Mitigation only Fix from $1,9502026-03-11 MEDIUM 5.3 CVE-2026-1068 An improper certificate validation vulnerability was reported in the Lenovo Filez application that could allow a user capable of intercepting network… Mitigation only Fix from $1,6002026-03-11 MEDIUM 5.5 CVE-2026-24508 Dell Alienware Command Center (AWCC), versions prior to 6.12.24.0, contain an Improper Certificate Validation vulnerability. A low privileged attacke… Alienware Command Center 6.12.24.0+ Fix from $1,6002026-03-11 MEDIUM 6.7 CVE-2024-14024 An improper certificate validation vulnerability has been reported to affect Video Station. If an attacker gains local network access who have also g… Video Station 5.8.2+ Fix from $1,6002026-03-11 MEDIUM 5.5 CVE-2026-27221 Acrobat Reader versions 24.001.30307, 24.001.30308, 25.001.21265 and earlier are affected by an Improper Certificate Validation vulnerability that co… Acrobat Dc 24.001.30356 / 25.001.21288+ Fix from $1,6002026-03-10 MEDIUM 5.9 CVE-2025-68482 A improper certificate validation vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.8, FortiAnalyzer 7.2 a… Fortimanager 7.4.9 / 7.6.5+ Fix from $1,6002026-03-10 HIGH 7.4 CVE-2026-24281 Hostname verification in Apache ZooKeeper ZKTrustManager falls back to reverse DNS (PTR) when IP SAN validation fails, allowing attackers who control… Zookeeper 3.8.6 / 3.9.5+ Fix from $1,9502026-03-07 HIGH 8.8 CVE-2026-30840 Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, there is a server-side request forgery vulnerability i… Wallos 4.6.2+ Fix from $1,9502026-03-07