Vulnerability index

Browse CVEs

1,344 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Certificate ValidationCWE-295 × clear
HIGH 7.5 CVE-2025-10495 A potential vulnerability was reported in the Lenovo PC Manager, Lenovo App Store, Lenovo Browser, and Lenovo Legion Zone client applications that, u… Mitigation only Fix from $1,9502025-11-12 HIGH 7.5 CVE-2025-40744 A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 11). Affected applications do not properly validate client cer… Mitigation only Fix from $1,9502025-11-11 HIGH 7.5 CVE-2025-12943 Improper certificate validation in firmware update logic in NETGEAR RAX30 (Nighthawk AX5 5-Stream AX2400 WiFi 6 Router) and RAXE300 (Nighthawk AXE780… Rax30 Firmware 1.0.9.82 / 1.0.14.108+ Fix from $1,9502025-11-11 HIGH 7.5 CVE-2025-64685 In JetBrains YouTrack before 2025.3.104432 missing TLS certificate validation enabled data disclosure Youtrack 2025.3.104432+ Fix from $1,9502025-11-10 CRITICAL 9.1 CVE-2025-56231 Tonec Internet Download Manager 6.42.41.1 and earlier suffers from Missing SSL Certificate Validation, which allows attackers to bypass update protec… Internet Download Manager after 6.42.41.1 Fix from $2,3002025-11-05 HIGH 8.6 CVE-2025-54470 This vulnerability affects NeuVector deployments only when the Report anonymous cluster data option is enabled. When this option is enabled, NeuVecto… Mitigation only Fix from $1,9502025-10-30 HIGH 7.5 CVE-2025-58188 Validating certificate chains which contain DSA public keys can cause programs to panic, due to a interface cast that assumes they implement the Equa… Go 1.24.8 / 1.25.2+ Fix from $1,9502025-10-29 MEDIUM 6.9 CVE-2025-62375 go-witness and witness are Go modules for generating attestations. In go-witness versions 0.8.6 and earlier and witness versions 0.9.2 and earlier th… Patch available Fix from $1,6002025-10-15 HIGH 8.8 CVE-2025-11619 Improper certificate validation when connecting to gateways in Devolutions Server 2025.3.2 and earlier allows attackers in MitM position to intercept… Devolutions Server 2025.2.15.0 / 2025.3.3.0+ Fix from $1,9502025-10-15 HIGH 7.4 CVE-2025-62371 OpenSearch Data Prepper as an open source data collector for observability data. In versions prior to 2.12.2, the OpenSearch sink and source plugins … Opensearch Data Prepper 2.12.2+ Fix from $1,9502025-10-15 MEDIUM 5.3 CVE-2025-10699 A vulnerability was reported in the Lenovo LeCloud client application that, under certain conditions, could allow information disclosure. No fix yet Fix from $1,6002025-10-15 HIGH 7.5 CVE-2025-11695 When tlsInsecure=False appears in a connection string, certificate validation is disabled. This vulnerability affects MongoDB Rust Driver versions p… Rust Driver 3.2.5+ Fix from $1,9502025-10-13 MEDIUM 5.9 CVE-2025-11633 A vulnerability was identified in Tomofun Furbo 360 and Furbo Mini. Affected by this issue is the function upload_file_to_s3 of the file collect_logs… Furbo Mini Firmware after 074 Fix from $1,6002025-10-12 CRITICAL 9.3 CVE-2025-61778 Akka.NET is a .NET port of the Akka project from the Scala / Java community. In all versions of Akka.Remote from v1.2.0 to v1.5.51, TLS could be enab… Patch available Fix from $2,3002025-10-06 HIGH 7.8 CVE-2025-34235 Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.1.102 and Application prior to version 25.1.1413 (Windows client depl… Virtual Appliance Application 25.1.102 / 25.1.1413+ Fix from $1,9502025-09-29 MEDIUM 6.5 CVE-2025-10548 The CleverControl employee monitoring software (v11.5.1041.6) fails to validate TLS server certificates during the installation process. The installe… Mitigation only Fix from $1,6002025-09-23 HIGH 8.1 CVE-2025-34199 Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22.0.1049 and Application versions prior to 20.0.2786 (VA and SaaS depl… Virtual Appliance Application 20.0.2786 / 22.0.1049+ Fix from $1,9502025-09-19 CRITICAL 9.3 CVE-2024-13990 MicroWorld eScan AV's update mechanism failed to ensure authenticity and integrity of updates: update packages were delivered and accepted without ro… Mitigation only Fix from $2,3002025-09-19 HIGH 7.5 CVE-2025-59353 Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, a peer can obtain a valid TLS certificate for … Dragonfly 2.1.0+ Fix from $1,9502025-09-17 MEDIUM 6.5 CVE-2025-59347 Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, The Manager disables TLS certificate verificat… Dragonfly 2.1.0+ Fix from $1,6002025-09-17 CRITICAL 9.8 CVE-2025-35434 CISA Thorium does not validate TLS certificates when connecting to Elasticsearch. An unauthenticated attacker with access to a Thorium cluster could … Thorium 1.1.2+ Fix from $2,3002025-09-17 MEDIUM 6.8 CVE-2025-9708 A vulnerability exists in the Kubernetes C# client where the certificate validation logic accepts properly constructed certificates from any Certific… Mitigation only Fix from $1,6002025-09-16 CRITICAL 9.0 CVE-2025-55109 An authentication bypass vulnerability exists in the out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 and potentially earlier unsupported ver… Control M\/agent after 9.0.22 Fix from $2,3002025-09-16 HIGH 8.8 CVE-2025-50944 An issue was discovered in the method push.lite.avtech.com.MySSLSocketFactoryNew.checkServerTrusted in AVTECH EagleEyes 2.0.0. The custom X509TrustMa… Eagleeyes\(lite\) No fix yet Fix from $1,9502025-09-15 HIGH 7.7 CVE-2025-9785 PaperCut Print Deploy is an optional component that integrates with PaperCut NG/MF which simplifies printer deployment and management. When the compo… Mitigation only Fix from $1,9502025-09-03 MEDIUM 5.9 CVE-2025-33099 IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to perform unauthorized actions using man in the middle techniques due to impr… Concert 2.0.0+ Fix from $1,6002025-09-01 HIGH 8.8 CVE-2025-30277 An improper certificate validation vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then … Qsync Central 4.5.0.7+ Fix from $1,9502025-08-29 HIGH 8.8 CVE-2025-30278 An improper certificate validation vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then … Qsync Central 4.5.0.7+ Fix from $1,9502025-08-29 CRITICAL 9.1 CVE-2025-7390 A malicious client can bypass the client certificate trust check of an opc.https server when the server endpoint is configured to allow only secure c… Mitigation only Fix from $2,3002025-08-21 HIGH 7.5 CVE-2025-33142 IBM WebSphere Application Server 8.5 and 9.0 could provide weaker than expected security for TLS connections. Websphere Application Server 8.5.5.29 / 9.0.5.25+ Fix from $1,9502025-08-14