Vulnerability index

Browse CVEs

23 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Certificate ValidationCWE-295 × clear
Windows 10 21h2 MEDIUM 6.5
CVE-2026-50302

Improper certificate validation in Windows Cryptographic Services allows an unauthorized attacker to bypass a security feature over a network.

Fix: 10.0.19044.7548 / 10.0.19045.7548+
Fix from $1,600 2026-07-14
Windows 10 1607 HIGH 7.8
CVE-2026-55001

Improper certificate validation in Windows Active Directory allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,950 2026-07-14
Azure Connected Machine Agent HIGH 8.8
CVE-2026-47632

Improper certificate validation in Azure Connected Machine Agent allows an unauthorized attacker to elevate privileges over an adjacent network.

Mitigation only
Fix from $1,950 2026-07-14
Azure Local HIGH 8.1
CVE-2026-21228

Improper certificate validation in Azure Local allows an unauthorized attacker to execute code over a network.

Fix: 2510.0.3002+
Fix from $1,950 2026-02-10
Windows 11 22h2 MEDIUM 6.5
CVE-2025-48802

Improper certificate validation in Windows SMB allows an authorized attacker to perform spoofing over a network.

Fix: 10.0.20348.3932 / 10.0.22621.5624+
Fix from $1,600 2025-07-08
Windows 10 1507 HIGH 7.4
CVE-2024-43550

Windows Secure Channel Spoofing Vulnerability

Fix: 10.0.10240.20796 / 10.0.14393.7428+
Fix from $1,950 2024-10-08
Windows 10 1507 HIGH 8.1
CVE-2024-30020

Windows Cryptographic Services Remote Code Execution Vulnerability

Fix: 10.0.10240.20651 / 10.0.14393.6981+
Fix from $1,950 2024-05-14
Windows 10 1507 HIGH 7.8
CVE-2024-29050

Windows Cryptographic Services Remote Code Execution Vulnerability

Fix: 10.0.10240.20596 / 10.0.14393.6897+
Fix from $1,950 2024-04-09
Windows 10 1507 HIGH 8.8
CVE-2022-26923 KEVEPSS 83%

Active Directory Domain Services Elevation of Privilege Vulnerability

Fix: 10.0.10240.19297 / 10.0.14393.5850+
Fix from $1,950 2022-05-10
Windows 10 HIGH 7.8
CVE-2022-21836

Windows Certificate Spoofing Vulnerability

No fix yet
Fix from $1,950 2022-01-11
Defender For Iot CRITICAL 9.8
CVE-2021-43882

Microsoft Defender for IoT Remote Code Execution Vulnerability

Fix: 10.5.3+
Fix from $2,300 2021-12-15
Windows 10 HIGH 7.5
CVE-2020-1113EPSS 7%

A security feature bypass vulnerability exists in Microsoft Windows when the Task Scheduler service fails to properly verify client connections over …

Patch available
Fix from $1,950 2020-05-21
Project Rome MEDIUM 5.9
CVE-2019-1231

An information disclosure vulnerability exists in the way Rome SDK handles server SSL/TLS certificate validation, aka 'Rome SDK Information Disclosur…

Patch available
Fix from $1,600 2019-09-11
.net Framework HIGH 7.5
CVE-2019-1006EPSS 6%

An authentication bypass vulnerability exists in Windows Communication Foundation (WCF) and Windows Identity Foundation (WIF), allowing signing of SA…

Patch available
Fix from $1,950 2019-07-15
C Software Development Kit MEDIUM 5.6
CVE-2018-8479

A spoofing vulnerability exists for the Azure IoT Device Provisioning for the C SDK library using the HTTP protocol on Windows platform, aka "Azure I…

Patch available
Fix from $1,600 2018-09-13
.net Framework MEDIUM 5.5
CVE-2018-8356

A security feature bypass vulnerability exists when Microsoft .NET Framework components do not correctly validate certificates, aka ".NET Framework S…

Patch available
Fix from $1,600 2018-07-11
C Software Development Kit MEDIUM 5.6
CVE-2018-8119

A spoofing vulnerability exists when the Azure IoT Device Provisioning AMQP Transport library improperly validates certificates over the AMQP protoco…

Patch available
Fix from $1,600 2018-05-09
.net Core HIGH 7.5
CVE-2018-0786

Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2, 4.7, 4.7.1, .NET Core 1.0 and 2.0, and PowerShell Core 6.0.0 allow a…

Patch available
Fix from $1,950 2018-01-10
Aspnetcore HIGH 7.5
CVE-2017-11770EPSS 5%

.NET Core 1.0, 1.1, and 2.0 allow an unauthenticated attacker to remotely cause a denial of service attack against a .NET Core web application by imp…

Patch available
Fix from $1,950 2017-11-15
.net Framework HIGH 7.5
CVE-2017-0248EPSS 6%

Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to bypass Enhanced Security Usage taggings when they pre…

Patch available
Fix from $1,950 2017-05-12
Lync For Mac HIGH 7.5
CVE-2017-0129EPSS 8%

Microsoft Lync for Mac 2011 fails to properly validate certificates, allowing remote attackers to alter server-client communications, aka "Microsoft …

Patch available
Fix from $1,950 2017-03-17
Windows Phone 7 Firmware MEDIUM 5.9
CVE-2012-2993

Microsoft Windows Phone 7 does not verify the domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-mi…

Mitigation only
Fix from $1,600 2012-09-18
Windows 2000 MEDIUM 6.8
CVE-2002-0862EPSS 16%

The (1) CertGetCertificateChain, (2) CertVerifyCertificateChainPolicy, and (3) WinVerifyTrust APIs within the CryptoAPI for Microsoft products includ…

Patch available
Fix from $1,600 2002-10-04