Vulnerability index

Browse CVEs

23 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Certificate ValidationCWE-295 × clear
MEDIUM 6.5 CVE-2026-50302 Improper certificate validation in Windows Cryptographic Services allows an unauthorized attacker to bypass a security feature over a network. Windows 10 21h2 10.0.19044.7548 / 10.0.19045.7548+ Fix from $1,6002026-07-14 HIGH 7.8 CVE-2026-55001 Improper certificate validation in Windows Active Directory allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,9502026-07-14 HIGH 8.8 CVE-2026-47632 Improper certificate validation in Azure Connected Machine Agent allows an unauthorized attacker to elevate privileges over an adjacent network. Azure Connected Machine Agent Mitigation only Fix from $1,9502026-07-14 HIGH 8.1 CVE-2026-21228 Improper certificate validation in Azure Local allows an unauthorized attacker to execute code over a network. Azure Local 2510.0.3002+ Fix from $1,9502026-02-10 MEDIUM 6.5 CVE-2025-48802 Improper certificate validation in Windows SMB allows an authorized attacker to perform spoofing over a network. Windows 11 22h2 10.0.20348.3932 / 10.0.22621.5624+ Fix from $1,6002025-07-08 HIGH 7.4 CVE-2024-43550 Windows Secure Channel Spoofing Vulnerability Windows 10 1507 10.0.10240.20796 / 10.0.14393.7428+ Fix from $1,9502024-10-08 HIGH 8.1 CVE-2024-30020 Windows Cryptographic Services Remote Code Execution Vulnerability Windows 10 1507 10.0.10240.20651 / 10.0.14393.6981+ Fix from $1,9502024-05-14 HIGH 7.8 CVE-2024-29050 Windows Cryptographic Services Remote Code Execution Vulnerability Windows 10 1507 10.0.10240.20596 / 10.0.14393.6897+ Fix from $1,9502024-04-09 HIGH 8.8 CVE-2022-26923 KEVEPSS 83% Active Directory Domain Services Elevation of Privilege Vulnerability Windows 10 1507 10.0.10240.19297 / 10.0.14393.5850+ Fix from $1,9502022-05-10 HIGH 7.8 CVE-2022-21836 Windows Certificate Spoofing Vulnerability Windows 10 No fix yet Fix from $1,9502022-01-11 CRITICAL 9.8 CVE-2021-43882 Microsoft Defender for IoT Remote Code Execution Vulnerability Defender For Iot 10.5.3+ Fix from $2,3002021-12-15 HIGH 7.5 CVE-2020-1113EPSS 7% A security feature bypass vulnerability exists in Microsoft Windows when the Task Scheduler service fails to properly verify client connections over … Windows 10 Patch available Fix from $1,9502020-05-21 MEDIUM 5.9 CVE-2019-1231 An information disclosure vulnerability exists in the way Rome SDK handles server SSL/TLS certificate validation, aka 'Rome SDK Information Disclosur… Project Rome Patch available Fix from $1,6002019-09-11 HIGH 7.5 CVE-2019-1006EPSS 6% An authentication bypass vulnerability exists in Windows Communication Foundation (WCF) and Windows Identity Foundation (WIF), allowing signing of SA… .net Framework Patch available Fix from $1,9502019-07-15 MEDIUM 5.6 CVE-2018-8479 A spoofing vulnerability exists for the Azure IoT Device Provisioning for the C SDK library using the HTTP protocol on Windows platform, aka "Azure I… C Software Development Kit Patch available Fix from $1,6002018-09-13 MEDIUM 5.5 CVE-2018-8356 A security feature bypass vulnerability exists when Microsoft .NET Framework components do not correctly validate certificates, aka ".NET Framework S… .net Framework Patch available Fix from $1,6002018-07-11 MEDIUM 5.6 CVE-2018-8119 A spoofing vulnerability exists when the Azure IoT Device Provisioning AMQP Transport library improperly validates certificates over the AMQP protoco… C Software Development Kit Patch available Fix from $1,6002018-05-09 HIGH 7.5 CVE-2018-0786 Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2, 4.7, 4.7.1, .NET Core 1.0 and 2.0, and PowerShell Core 6.0.0 allow a… .net Core Patch available Fix from $1,9502018-01-10 HIGH 7.5 CVE-2017-11770EPSS 5% .NET Core 1.0, 1.1, and 2.0 allow an unauthenticated attacker to remotely cause a denial of service attack against a .NET Core web application by imp… Aspnetcore Patch available Fix from $1,9502017-11-15 HIGH 7.5 CVE-2017-0248EPSS 6% Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to bypass Enhanced Security Usage taggings when they pre… .net Framework Patch available Fix from $1,9502017-05-12 HIGH 7.5 CVE-2017-0129EPSS 8% Microsoft Lync for Mac 2011 fails to properly validate certificates, allowing remote attackers to alter server-client communications, aka "Microsoft … Lync For Mac Patch available Fix from $1,9502017-03-17 MEDIUM 5.9 CVE-2012-2993 Microsoft Windows Phone 7 does not verify the domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-mi… Windows Phone 7 Firmware Mitigation only Fix from $1,6002012-09-18 MEDIUM 6.8 CVE-2002-0862EPSS 16% The (1) CertGetCertificateChain, (2) CertVerifyCertificateChainPolicy, and (3) WinVerifyTrust APIs within the CryptoAPI for Microsoft products includ… Windows 2000 Patch available Fix from $1,6002002-10-04