Vulnerability index

Browse CVEs

1,344 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Certificate ValidationCWE-295 × clear
HIGH 7.5 CVE-2026-27137 When verifying a certificate chain which contains a certificate containing multiple email address constraints which share common local portions but d… Go Mitigation only Fix from $1,9502026-03-06 MEDIUM 5.9 CVE-2026-27138 Certificate verification can panic when a certificate in the chain has an empty DNS name and another certificate in the chain has excluded name const… Go Mitigation only Fix from $1,6002026-03-06 MEDIUM 5.3 CVE-2026-2748 SEPPmail Secure Email Gateway before version 15.0.1 improperly validates S/MIME certificates issued for email addresses containing whitespaces, allow… Seppmail 15.0.1+ Fix from $1,6002026-03-04 CRITICAL 9.8 CVE-2026-2590 Improper enforcement of the Disable password saving in vaults setting in the connection entry component in Devolutions Remote Desktop Manager 2025.… Remote Desktop Manager after 2025.3.30.0 Fix from $2,3002026-03-03 HIGH 7.5 CVE-2026-3336 Improper certificate validation in PKCS7_verify() in AWS-LC allows an unauthenticated user to bypass certificate chain verification when processing P… Aws Lc Sys 0.38.0 / 1.69.0+ Fix from $1,9502026-03-02 MEDIUM 6.5 CVE-2026-3100 The FTP Backup on the ADM will not properly strictly enforce TLS certificate verification while connecting to an FTP server using FTPES/FTPS. An impr… Data Master 5.1.2.reo1+ Fix from $1,6002026-02-25 HIGH 8.1 CVE-2025-67752 OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 7.0.4, OpenEMR's HTTP clien… Openemr 7.0.4+ Fix from $1,9502026-02-25 CRITICAL 9.1 CVE-2025-70043 An issue pertaining to CWE-295: Improper Certificate Validation was discovered in Ayms node-To master. The application disables TLS/SSL certificate v… No fix yet Fix from $2,3002026-02-23 MEDIUM 6.5 CVE-2025-70044 An issue pertaining to CWE-295: Improper Certificate Validation was discovered in fofolee uTools-quickcommand 5.0.3. Utools Quickcommand No fix yet Fix from $1,6002026-02-23 HIGH 7.4 CVE-2025-70045 An issue pertaining to CWE-295: Improper Certificate Validation was discovered in jxcore jxm master. The application disables TLS/SSL certificate val… Jxm No fix yet Fix from $1,9502026-02-23 HIGH 7.4 CVE-2025-70058 An issue pertaining to CWE-295: Improper Certificate Validation was discovered in YMFE yapi v1.12.0. The application disables TLS/SSL certificate val… Yapi No fix yet Fix from $1,9502026-02-23 HIGH 8.1 CVE-2026-27134 Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. In versions 0.49.0 through 0.… Strimzi Kafka Operator 0.50.1+ Fix from $1,9502026-02-21 MEDIUM 5.9 CVE-2026-27133 Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. From 0.47.0 to before 0.50.1, … Strimzi 0.50.1+ Fix from $1,6002026-02-20 HIGH 7.5 CVE-2026-24734 Improper Input Validation vulnerability in Apache Tomcat Native, Apache Tomcat. When using an OCSP responder, Tomcat Native (and Tomcat's FFM port o… Tomcat 1.3.5 / 2.0.12+ Fix from $1,9502026-02-17 CRITICAL 9.1 CVE-2025-66614 Improper Input Validation vulnerability. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-M1 through 10.1.49, from 9.0.… Tomcat 9.0.113 / 10.1.50+ Fix from $2,3002026-02-17 HIGH 7.5 CVE-2025-65753 An issue in the TLS certification mechanism of Guardian Gryphon v01.06.0006.22 allows attackers to execute commands as root. No fix yet Fix from $1,9502026-02-17 HIGH 8.1 CVE-2025-9293 A vulnerability in the certificate validation logic may allow applications to accept untrusted or improperly validated server identities during TLS c… Aginet 1.1.21 / 1.1.28+ Fix from $1,9502026-02-13 CRITICAL 9.4 CVE-2025-15573 The affected devices do not validate the server certificate when connecting to the SolaX Cloud MQTTS server hosted in the Alibaba Cloud (mqtt001.sola… Mitigation only Fix from $2,3002026-02-12 HIGH 7.5 CVE-2025-70029 An issue in Sunbird-Ed SunbirdEd-portal v1.13.4 allows attackers to obtain sensitive information. The application disables TLS/SSL certificate valida… Sunbirded Portal No fix yet Fix from $1,9502026-02-11 HIGH 8.1 CVE-2026-21228 Improper certificate validation in Azure Local allows an unauthorized attacker to execute code over a network. Azure Local 2510.0.3002+ Fix from $1,9502026-02-10 HIGH 7.5 CVE-2026-25961 SumatraPDF is a multi-format reader for Windows. In 3.5.0 through 3.5.2, SumatraPDF's update mechanism disables TLS hostname verification (INTERNET_F… Sumatrapdf after 3.5.2 Fix from $1,9502026-02-09 MEDIUM 5.7 CVE-2026-22613 The server identity check mechanism for firmware upgrade performed via command shell is insecurely implemented potentially allowing an attacker to pe… Mitigation only Fix from $1,6002026-02-09 HIGH 7.5 CVE-2026-25644 DataHub is an open-source metadata platform. Prior to version 1.3.1.8, the LDAP ingestion source is vulnerable to MITM attack through TLS downgrade. … Datahub 1.3.1.8+ Fix from $1,9502026-02-06 CRITICAL 10.0 CVE-2025-68121 During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between the initial handshake and the r… Go 1.24.13 / 1.25.7+ Fix from $2,3002026-02-05 HIGH 8.8 CVE-2025-15557 An Improper Certificate Validation vulnerability in TP-Link Tapo H100 v1 and Tapo P100 v1 allows an on-path attacker on the same network segment to i… Tapo H100 Firmware 1.2.6 / 1.6.1+ Fix from $1,9502026-02-05 HIGH 7.4 CVE-2026-25160 Alist is a file list program that supports multiple storages, powered by Gin and Solidjs. Prior to version 3.57.0, the application disables TLS certi… Alist 3.57.0+ Fix from $1,9502026-02-04 MEDIUM 5.9 CVE-2026-24932 The DDNS update function in ADM fails to properly validate the hostname of the DDNS server's TLS/SSL certificate. Although the connection uses HTTPS,… Data Master 5.1.2.re51+ Fix from $1,6002026-02-03 MEDIUM 5.9 CVE-2026-24933 The API communication component fails to validate the SSL/TLS certificate when sending HTTPS requests to the server. An improper certificates validat… Data Master 5.1.2.re51+ Fix from $1,6002026-02-03 MEDIUM 5.6 CVE-2026-24935 A third-party NAT traversal module fails to validate SSL/TLS certificates when connecting to the signaling server. While subsequent access to device … Data Master 5.1.2.re51+ Fix from $1,6002026-02-03 MEDIUM 5.9 CVE-2026-1778 Amazon SageMaker Python SDK before v3.1.1 or v2.256.0 disables TLS certificate verification for HTTPS connections made by the service when a Triton P… Mitigation only Fix from $1,6002026-02-02