Vulnerability index

Browse CVEs

1,344 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Certificate ValidationCWE-295 × clear
HIGH 8.1 CVE-2026-1530 A flaw was found in fog-kubevirt. This vulnerability allows a remote attacker to perform a Man-in-the-Middle (MITM) attack due to disabled certificat… Mitigation only Fix from $1,9502026-02-02 HIGH 8.1 CVE-2026-1531 A flaw was found in foreman_kubevirt. When configuring the connection to OpenShift, the system disables SSL verification if a Certificate Authority (… Mitigation only Fix from $1,9502026-02-02 HIGH 7.7 CVE-2022-40620 FunJSQ, a third-party module integrated on some NETGEAR routers and Orbi WiFi Systems, does not properly validate TLS certificates when downloading u… Rbr20 Firmware 1.0.5.42 / 1.0.11.134+ Fix from $1,9502026-01-28 CRITICAL 9.3 CVE-2026-22696 dcap-qvl implements the quote verification logic for DCAP (Data Center Attestation Primitives). A vulnerability present in versions prior to 0.3.9 in… Mitigation only Fix from $2,3002026-01-26 CRITICAL 9.8 CVE-2025-67229 An improper certificate validation vulnerability exists in ToDesktop Builder v0.32.1 This vulnerability allows an unauthenticated, on-path attacker t… Builder 0.32.1+ Fix from $2,3002026-01-23 MEDIUM 6.5 CVE-2025-32057 The Infotainment ECU manufactured by Bosch which is installed in Nissan Leaf ZE1 – 2020 uses a Redbend service for over-the-air provisioning and upda… Mitigation only Fix from $1,6002026-01-22 MEDIUM 5.3 CVE-2025-27377 Altium Designer version 24.9.0 does not validate self-signed server certificates for cloud connections. An attacker capable of performing a man-in-th… Designer 25.2.0+ Fix from $1,6002026-01-22 HIGH 7.5 CVE-2026-21945 Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supp… Graalvm Mitigation only Fix from $1,9502026-01-20 HIGH 7.4 CVE-2025-11043 An Improper Certificate Validation vulnerability in the OPC-UA client and ANSL over TLS client used in Automation Studio versions before 6.5 could al… Mitigation only Fix from $1,9502026-01-19 MEDIUM 5.5 CVE-2026-22250 wlc is a Weblate command-line client using Weblate's REST API. Prior to 1.17.0, the SSL verification would be skipped for some crafted URLs. This vul… Wlc 1.17.0+ Fix from $1,6002026-01-12 CRITICAL 9.8 CVE-2025-46070 An issue in Automai BotManager v.25.2.0 allows a remote attacker to execute arbitrary code via the BotManager.exe component Botmanager Mitigation only Fix from $2,3002026-01-12 HIGH 7.5 CVE-2025-71063 Errands before 46.2.10 does not verify TLS certificates for CalDAV servers. Errands 46.2.10+ Fix from $1,9502026-01-12 HIGH 8.8 CVE-2025-66001 NeuVector supports login authentication through OpenID Connect. However, the TLS verification (which verifies the remote server's authenticity and in… Mitigation only Fix from $1,9502026-01-08 MEDIUM 5.3 CVE-2025-14819 When doing TLS related transfers with reused easy or multi handles and altering the `CURLSSLOPT_NO_PARTIALCHAIN` option, libcurl could accidentally … Curl 8.18.0+ Fix from $1,6002026-01-08 MEDIUM 5.9 CVE-2025-13034 When using `CURLOPT_PINNEDPUBLICKEY` option with libcurl or `--pinnedpubkey` with the curl tool,curl should check the public key of the server certif… Curl 8.18.0+ Fix from $1,6002026-01-08 MEDIUM 6.8 CVE-2025-14022 LINE client for iOS prior to 15.4 allows man-in-the-middle attacks due to improper SSL/TLS certificate validation in an integrated financial SDK. The… Line 15.4.0+ Fix from $1,6002025-12-15 MEDIUM 5.9 CVE-2025-13052 When the user set the Notification's sender to send emails to the SMTP server via msmtp, an improper validated TLS/SSL certificates allows an attacke… Data Master 4.3.3.ROF1 / 5.1.1.RCI1+ Fix from $1,6002025-12-12 HIGH 7.4 CVE-2025-65290 Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 fail to validate server certificates during HTTPS firm… Hub M2 Firmware No fix yet Fix from $1,9502025-12-10 HIGH 7.4 CVE-2025-65291 Aqara Hub devices including Hub M2 4.3.6_0027, Hub M3 4.3.6_0025, Camera Hub G3 4.1.9_0027 fail to validate server certificates in TLS connections fo… Hub M2 Firmware No fix yet Fix from $1,9502025-12-10 CRITICAL 9.1 CVE-2025-65830 Due to a lack of certificate validation, all traffic from the mobile application can be intercepted. As a result, an adversary located "upstream" can… Meatmeet Mitigation only Fix from $2,3002025-12-10 HIGH 7.4 CVE-2025-40800 A vulnerability has been identified in COMOS V10.6 (All versions < V10.6.1), COMOS V10.6 (All versions < V10.6.1), NX V2412 (All versions < V2412.870… Mitigation only Fix from $1,9502025-12-09 HIGH 8.1 CVE-2025-40801 A vulnerability has been identified in COMOS V10.6 (All versions < V10.6.1), COMOS V10.6 (All versions < V10.6.1), JT Bi-Directional Translator for S… Mitigation only Fix from $1,9502025-12-09 MEDIUM 5.9 CVE-2025-66491 Traefik is an HTTP reverse proxy and load balancer. Versions 3.5.0 through 3.6.2 have inverted TLS verification logic in the nginx.ingress.kubernetes… Traefik 3.6.3+ Fix from $1,6002025-12-09 MEDIUM 6.5 CVE-2025-61727 An excluded subdomain constraint in a certificate chain does not restrict the usage of wildcard SANs in the leaf certificate. For example a constrain… Go 1.24.11 / 1.25.5+ Fix from $1,6002025-12-03 HIGH 7.5 CVE-2025-61729 Within HostnameError.Error(), when constructing an error string, there is no limit to the number of hosts that will be printed out. Furthermore, the … Go 1.24.11 / 1.25.5+ Fix from $1,9502025-12-02 MEDIUM 5.4 CVE-2025-12893 Clients may successfully perform a TLS handshake with a MongoDB server despite presenting a client certificate not aligning with the documented Exten… MongoDB 7.0.26 / 8.0.16+ Fix from $1,6002025-11-25 HIGH 8.3 CVE-2025-44018 A firmware downgrade vulnerability exists in the OTA Update functionality of GL-Inet GL-AXT1800 4.7.0. A specially crafted .tar file can lead to a fi… Mitigation only Fix from $1,9502025-11-24 MEDIUM 6.5 CVE-2025-30669 Improper certificate validation in certain Zoom Clients may allow an unauthenticated user to conduct a disclosure of information via adjacent access. Meeting Software Development Kit 6.3.14 / 6.4.12+ Fix from $1,6002025-11-13 HIGH 7.4 CVE-2025-12765 pgAdmin <= 9.9  is affected by a vulnerability in the LDAP authentication mechanism allows bypassing TLS certificate verification. Pgadmin 4 9.10+ Fix from $1,9502025-11-13 MEDIUM 5.3 CVE-2025-12047 A vulnerability was reported in the Lenovo Scanner pro application during an internal security assessment that, under certain circumstances, could al… Mitigation only Fix from $1,6002025-11-12