Vulnerabilities > Improper Certificate Validation

DATE CVE VULNERABILITY TITLE RISK
2023-04-29 CVE-2023-31485 Improper Certificate Validation vulnerability in Gitlab::Api::V4 Project Gitlab::Api::V4
GitLab::API::v4 through 0.26 does not verify TLS certificates when connecting to a GitLab server, enabling machine-in-the-middle attacks.
network
high complexity
gitlab CWE-295
5.9
2023-04-29 CVE-2023-31486 Improper Certificate Validation vulnerability in multiple products
HTTP::Tiny before 0.083, a Perl core module since 5.13.9 and available standalone on CPAN, has an insecure default TLS configuration where users must opt in to verify certificates.
network
high complexity
http perl CWE-295
8.1
2023-04-27 CVE-2022-47758 Improper Certificate Validation vulnerability in Nanoleaf Firmware 7.1.1
Nanoleaf firmware v7.1.1 and below is missing TLS verification, allowing attackers to execute arbitrary code via a DNS hijacking attack.
network
low complexity
nanoleaf CWE-295
critical
9.8
2023-04-15 CVE-2021-46880 Improper Certificate Validation vulnerability in Openbsd
x509/x509_verify.c in LibreSSL before 3.4.2, and OpenBSD before 7.0 errata 006, allows authentication bypass because an error for an unverified certificate chain is sometimes discarded.
network
low complexity
openbsd CWE-295
critical
9.8
2023-04-15 CVE-2023-26463 Improper Certificate Validation vulnerability in Strongswan 5.9.8/5.9.9
strongSwan 5.9.8 and 5.9.9 potentially allows remote code execution because it uses a variable named "public" for two different purposes within the same function.
network
low complexity
strongswan CWE-295
critical
9.8
2023-04-12 CVE-2023-30516 Improper Certificate Validation vulnerability in Jenkins Image TAG Parameter
Jenkins Image Tag Parameter Plugin 2.0 improperly introduces an option to opt out of SSL/TLS certificate validation when connecting to Docker registries, resulting in job configurations using Image Tag Parameters that were created before 2.0 having SSL/TLS certificate validation disabled by default.
network
low complexity
jenkins CWE-295
6.5
2023-04-12 CVE-2023-30517 Improper Certificate Validation vulnerability in Jenkins Neuvector vulnerability Scanner
Jenkins NeuVector Vulnerability Scanner Plugin 1.22 and earlier unconditionally disables SSL/TLS certificate and hostname validation when connecting to a configured NeuVector Vulnerability Scanner server.
network
low complexity
jenkins CWE-295
5.3
2023-04-12 CVE-2022-48437 Improper Certificate Validation vulnerability in Openbsd
An issue was discovered in x509/x509_verify.c in LibreSSL before 3.6.1, and in OpenBSD before 7.2 errata 001.
network
low complexity
openbsd CWE-295
5.3
2023-04-11 CVE-2023-22642 Improper Certificate Validation vulnerability in Fortinet Fortianalyzer and Fortimanager
An improper certificate validation vulnerability [CWE-295] in FortiAnalyzer and FortiManager 7.2.0 through 7.2.1, 7.0.0 through 7.0.5, 6.4.8 through 6.4.10 may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the communication channel between the device and the remote FortiGuard server hosting outbreakalert ressources.
network
high complexity
fortinet CWE-295
8.1
2023-04-11 CVE-2023-23588 Improper Certificate Validation vulnerability in multiple products
A vulnerability has been identified in SIMATIC IPC1047 (All versions), SIMATIC IPC1047E (All versions with maxView Storage Manager < 4.09.00.25611 on Windows), SIMATIC IPC647D (All versions), SIMATIC IPC647E (All versions with maxView Storage Manager < 4.09.00.25611 on Windows), SIMATIC IPC847D (All versions), SIMATIC IPC847E (All versions with maxView Storage Manager < 4.09.00.25611 on Windows).
local
high complexity
siemens microchip CWE-295
6.3