Export limit exceeded: 401118 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (1685 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-11999 | 1 Wolfssl | 1 Wolfssl | 2026-06-25 | 7.5 High |
| X.509 trust-chain bypass (path-depth exhaustion) in the OpenSSL compatibility certificate verifier (wolfSSL_X509_verify_cert()). This affects only builds with --enable-opensslextra whose application calls X509_verify_cert() with caller-supplied untrusted intermediates; for those users it is critical, otherwise the library is unaffected. Native wolfSSL TLS/DTLS usage is not impacted. X509_verify_cert() returned success based only on the last verified link rather than on reaching a trust anchor: when the supplied chain is deeper than the verifier's maximum path depth (default 100), path building runs out of depth while still walking untrusted intermediates and the chain is accepted even though it never reaches a configured trust anchor, allowing acceptance of an attacker-controlled certificate. The default TLS handshake (WOLFSSL_VERIFY_PEER) is not affected; only applications doing manual or deferred verification through this API are. | ||||
| CVE-2026-57289 | 2 Jenkins, Jenkins Project | 2 Bitbucket Push And Pull Request, Jenkins Bitbucket Push And Pull Request Plugin | 2026-06-24 | 4.8 Medium |
| Jenkins Bitbucket Push and Pull Request Plugin 3.3.8 and earlier unconditionally disables SSL/TLS certificate and hostname validation for connections sending Bearer token authenticated requests to the configured Bitbucket Server endpoint, allowing attackers able to intercept network traffic to capture the token. | ||||
| CVE-2026-54323 | 1 Daytonaio | 1 Daytona | 2026-06-24 | 5.9 Medium |
| Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. Prior to 0.185.0, the daemon's git clone implementation disabled TLS certificate verification. When a clone request carried Git credentials, the daemon sent the HTTP Basic Authorization header to the remote over a connection whose certificate was never validated, on both the go-git and native git CLI code paths. An attacker able to intercept clone traffic could present any TLS certificate, capture the Git credentials supplied for the clone, and serve tampered repository content into the sandbox. This vulnerability is fixed in 0.185.0. | ||||
| CVE-2026-9258 | 3 Apple, Canon, Microsoft | 5 Macos, Eos Network Setting Tool, Eos Network Setting Tool For Macos and 2 more | 2026-06-23 | 6.5 Medium |
| Improper validation of SSH host keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier | ||||
| CVE-2026-9259 | 3 Apple, Canon, Microsoft | 5 Macos, Eos Network Setting Tool, Eos Network Setting Tool For Macos and 2 more | 2026-06-23 | 6.5 Medium |
| Improper validation of server certificates in Canon EOS Network Setting Tool Version 1.5.0 or earlier | ||||
| CVE-2026-45170 | 3 Cyberark, Cyberark Software A Palo Alto Networks Company, Paloaltonetworks | 3 Pam Sh Connector, Vendor Pam, Idira Privilege Cloud Connector | 2026-06-23 | 8.8 High |
| Idira Vendor PAM - Self-Hosted Connector versions prior 1.1.100504 under specific conditions and configuration scenarios, TLS certificate validation may not be fully enforced. CyberArk Security Bulletin: CA26-17 | ||||
| CVE-2025-2669 | 1 Ibm | 5 Cloud Pak For Data, Db2, Db2 On Cloud Pak For Data and 2 more | 2026-06-22 | 6 Medium |
| IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions 4.8, 5.0, 5.1, 5.2, 5.3 could allow a privileged user to perform operations and obtain sensitive information outside of their authority due to improper token validation. | ||||
| CVE-2024-47477 | 1 Dell | 1 Powerflex Manager | 2026-06-18 | 6.5 Medium |
| Dell PowerFlex Manager, versions prior to 4.5.1.1, contain an improper certificate validation vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability leading to man-in-the-middle attack in tandem with DNS cache poisoning. | ||||
| CVE-2026-45388 | 1 Ocaml | 1 Ocaml | 2026-06-17 | 9.1 Critical |
| In OCaml-TLS before 2.1.0, the client implementation does insufficient checks of the certificate provided by the server, which allows impersonation with certificates that are not meant for server authentication (because of KeyUsage and ExtendedKeyUsage). | ||||
| CVE-2026-45389 | 1 Ocaml | 1 Ocaml | 2026-06-17 | 7.4 High |
| In OCaml-TLS before 2.1.0, the server implementation does insufficient checks of the certificate provided by the client (when doing client authentication), which allows impersonation with certificates that are not meant for client authentication (because of KeyUsage and ExtendedKeyUsage). | ||||
| CVE-2025-71261 | 1 Suse | 1 Harvester | 2026-06-16 | 8.6 High |
| An attacker with network-level access between the SUSE Virtualization and Rancher Manager in SUSE Harvester before 1.8.0 could interfere with the TLS handshake and abuse it to bypass TLS as a security control. | ||||
| CVE-2026-53475 | 1 Kubev2v | 2 Assisted-migration-agent, Assisted Migration Agent | 2026-06-16 | 9.3 Critical |
| A flaw was found in assisted-migration-agent. The application hardcodes insecure Transport Layer Security (TLS) connections when communicating with vCenter. This vulnerability allows a Man-in-the-Middle (MITM) attacker to intercept and harvest vCenter administrator credentials. This can lead to unauthorized access to vCenter. | ||||
| CVE-2026-42769 | 1 Openssl | 1 Openssl | 2026-06-15 | 5.3 Medium |
| Issue Summary: An error in the callback used to verify the certificate provided in a Root CA key update Certificate Management Protocol (CMP) message response rendered the certificate validation ineffectual, which could lead to escalation of credentials from the Registration Authority (RA) level to the root Certification Authority (root CA) level. Impact Summary: The Registration Autority could replace the root CA certificate for the CMP clients with an arbitrary root CA certificate. One of the parts of the Certificate Management Protocol (CMP), specified in RFC 9810, is Root Certification Authority (root CA) key Rollover, which is sent by the server in a message with type 'id-it-rootCaKeyUpdate'. As part of these messages, 'newWithOld' certificate, the new root CA certificate signed with the old root CA key, is provided, and verifying its signature is crucial for transferring the trust from the old CA key to the new one. The 'id-it-rootCaKeyUpdate' messages are expected to be processed with OSSL_CMP_get1_rootCaKeyUpdate(), that is expected to verify the 'newWithOld' certificate. A typo in the certificate chain building code led to adding an incorrect certificate ('newWithOld' instead of 'oldRoot') to the certificate chain, rendering the certificate verification process ineffectual (only the issuer name and the algorithm OIDs were verified by other parts of the verification code). An attacker who already has credentials that satisfy the CMP message protection checks can generate a new key pair and use a crafted self-signed certificate in its 'id-it-rootCaKeyUpdate' CMP messages which affected CMP clients would accept as a new trust anchor. Significant preconditions for the attack (having valid RA-level credentials) are the reason the issue was assigned Low severity. The FIPS modules are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary. | ||||
| CVE-2026-45175 | 6 Apple, Cyberark, Cyberark Software A Palo Alto Networks Company and 3 more | 6 Macos, Endpoint Privilege Manager, Idira Endpoint Privilege Manager and 3 more | 2026-06-12 | 7.8 High |
| Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within internal agent validation processes. A local attacker could potentially bypass built-in security controls or cryptographic validations. Under specific circumstances, this could allow the attacker to circumvent agent self-defense mechanisms and execute unauthorized operations. CyberArk Security Bulletin: CA26-19 | ||||
| CVE-2026-9648 | 1 Haskell Programming Language | 1 Crypton-certificate | 2026-06-12 | 9.1 Critical |
| The crypton-x509-validation Haskell library fails to enforce X.509 NameConstraints, allowing TLS clients to accept certificates whose Subject Alternative Names fall outside the issuing CA’s permitted subtrees. This oversight enables an attacker who compromises a name-constrained sub-CA to impersonate domains beyond its intended scope. | ||||
| CVE-2026-9758 | 1 Systerel | 1 S2opc | 2026-06-10 | 7.3 High |
| Improper comparison with the certificates trusted list in S2OPC allows an attacker well-formed untrusted certificate to be considered trusted | ||||
| CVE-2026-50752 | 1 Checkpoint | 2 Quantum Security Gateway, Spark Firewalls | 2026-06-10 | 7.4 High |
| A weakness in the certificate validation logic of the deprecated IKEv1 key exchange may allow an unauthenticated attacker positioned as a man-in-the-middle to bypass certificate validation in VPN site-to-site connections that use certificate-based authentication. Successful exploitation could allow interception or modification of traffic traversing the VPN tunnel. | ||||
| CVE-2026-41714 | 2 Spring, Vmware | 2 Spring Amqp, Spring Advanced Message Queuing Protocol | 2026-06-10 | 4 Medium |
| Applications that configure their broker connection via RabbitConnectionFactoryBean.setUri("amqps://...") without also calling setUseSSL(true) get TLS encryption with no certificate validation and no hostname verification. Affected versions: Spring AMQP 4.0.0 through 4.0.3; 3.2.0 through 3.2.10; 3.1.0 through 3.1.15; 2.4.0 through 2.4.17. | ||||
| CVE-2024-43550 | 1 Microsoft | 22 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 19 more | 2026-06-09 | 7.4 High |
| Windows Secure Channel Spoofing Vulnerability | ||||
| CVE-2025-24471 | 1 Fortinet | 2 Fortios, Fortisase | 2026-06-09 | 6 Medium |
| An Improper Certificate Validation vulnerability [CWE-295] in FortiOS version 7.6.1 and below, version 7.4.7 and below may allow an EAP verified remote user to connect from FortiClient via revoked certificate. | ||||