The product does not validate, or incorrectly validates, a certificate.
1,400 vulnerabilities with CWE-295
CVE-2022-25243
MEDIUM
Vault 1.8.0-1.8.8 and 1.9.3 - Improper Certificate Validation in PKI Secrets Engine
CVSS 6.5
CVE-2022-21170
LOW
DAJ I-filter Browser & Cloud Multiagent < 4.93r04 - Improper Certificate Validation
CVSS 3.7
CVE-2022-22946
MEDIUM
Spring Cloud Gateway - Improper Certificate Validation
CVSS 5.5
CVE-2022-25640
HIGH
wolfssl < 5.2.0 - Improper Certificate Validation
CVSS 7.5
CVE-2022-25638
MEDIUM
wolfssl < 5.2.0 - Certificate Validation Bypass via TLS 1.3 sig_algo Field Mismatch
CVSS 6.5
CVE-2022-21657
MEDIUM
envoyproxy/envoy < 1.18.6 - Improper Certificate Validation
CVSS 6.8
CVE-2022-21656
HIGH
envoyproxy/envoy < 1.20.2 - Improper Certificate Validation via subjectAltNames Type Confusion
CVSS 7.4
CVE-2022-21654
HIGH
Envoy 1.7.0-1.18.5 - Improper Certificate Validation in TLS Reuse
CVSS 7.4
CVE-2022-23649
LOW
sigstore cosign < 1.5.2 - Improper Certificate Validation via Rekor Transparency Log Bypass
CVSS 3.3
CVE-2022-23632
HIGH
Traefik < 2.6.1 - Improper Certificate Validation via FQDN Host Header
CVSS 7.4
CVE-2022-22885
CRITICAL
Hutool < 5.7.19 - Improper Certificate Validation
CVSS 9.8
CVE-2022-24968
MEDIUM
mellium/xmpp 0.18.0-0.21.0 - Improper Certificate Validation via DNS TXT Record Spoofing
CVSS 5.9
CVE-2022-20703
CRITICAL
KEV
Cisco RV Routers - Code Execution, Privilege, Auth Bypass, and DoS
CVSS 10.0
CVE-2022-24320
MEDIUM
ClearSCADA, EcoStruxure Geo SCADA Expert - Info Disclosure
CVSS 5.9
CVE-2022-24319
MEDIUM
ClearSCADA, EcoStruxure Geo SCADA Expert - Info Disclosure
CVSS 5.9
CVE-2022-20034
MEDIUM
Preloader XFLASH - Privilege Escalation
CVSS 6.8
CVE-2022-22156
MEDIUM
Juniper Networks Junos OS - Privilege Escalation
CVSS 6.5
CVE-2022-21836
HIGH
Windows - Certificate Spoofing via Improper Certificate Validation
CVSS 7.8
CVE-2021-25635
MEDIUM
LibreOffice 7.0.0-7.0.5 - Improper Certificate Validation in ODF Document Signatures
CVSS 5.5
CVE-2021-46880
CRITICAL
LibreSSL <3.4.2/OpenBSD <7.0 - Auth Bypass
CVSS 9.8
CVE-2021-21548
HIGH
Dell EMC Unisphere for PowerMax < 9.1.0.27 - Unauthenticated Man-in-the-Middle via Improper Certificate Validation
CVSS 7.4
CVE-2021-45035
MEDIUM
Velneo vClient 28.1.3 - Improper Certificate Validation
CVSS 6.3
CVE-2021-43767
MEDIUM
PostgreSQL 9.6.0-9.6.23 - Improper Certificate Validation
CVSS 5.9
CVE-2021-43766
HIGH
Odyssey - SQL Injection via Man-in-the-Middle Attack on Certificate Common Name Authentication
CVSS 8.1
CVE-2021-29755
HIGH
IBM QRadar SIEM 7.3-7.5 - Improper Certificate Validation
CVSS 7.5
Details
Vulnerabilities
1,400