Vulnerabilities > Improper Certificate Validation

DATE CVE VULNERABILITY TITLE RISK
2023-04-10 CVE-2023-28093 Improper Certificate Validation vulnerability in Pega Synchronization Engine
A user with a compromised configuration can start an unsigned binary as a service.
network
low complexity
pega CWE-295
6.5
2023-04-10 CVE-2023-25392 Improper Certificate Validation vulnerability in Allegro Bigflow
Allegro Tech BigFlow <1.6 is vulnerable to Missing SSL Certificate Validation.
network
high complexity
allegro CWE-295
5.9
2023-04-04 CVE-2023-29000 Improper Certificate Validation vulnerability in Nextcloud Desktop
The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server.
network
low complexity
nextcloud CWE-295
6.5
2023-03-29 CVE-2022-27644 Improper Certificate Validation vulnerability in Netgear products
This vulnerability allows network-adjacent attackers to compromise the integrity of downloaded information on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.91 routers.
low complexity
netgear CWE-295
8.8
2023-03-28 CVE-2023-0465 Improper Certificate Validation vulnerability in Openssl
Applications that use a non-default option when verifying certificates may be vulnerable to an attack from a malicious CA to circumvent certain checks. Invalid certificate policies in leaf certificates are silently ignored by OpenSSL and other certificate policy checks are skipped for that certificate. A malicious CA could use this to deliberately assert invalid certificate policies in order to circumvent policy checking on the certificate altogether. Policy processing is disabled by default but can be enabled by passing the `-policy' argument to the command line utilities or by calling the `X509_VERIFY_PARAM_set1_policies()' function.
network
low complexity
openssl CWE-295
5.3
2023-03-28 CVE-2023-0466 Improper Certificate Validation vulnerability in Openssl
The function X509_VERIFY_PARAM_add0_policy() is documented to implicitly enable the certificate policy check when doing certificate verification.
network
low complexity
openssl CWE-295
5.3
2023-03-24 CVE-2022-45597 Improper Certificate Validation vulnerability in Componentspace Saml 4.4.0
ComponentSpace.Saml2 4.4.0 Missing SSL Certificate Validation.
network
low complexity
componentspace CWE-295
critical
9.8
2023-03-24 CVE-2023-20963 Improper Certificate Validation vulnerability in Google Android
In WorkSource, there is a possible parcel mismatch.
local
low complexity
google CWE-295
7.8
2023-03-22 CVE-2023-0464 Improper Certificate Validation vulnerability in Openssl
A security vulnerability has been identified in all supported versions of OpenSSL related to the verification of X.509 certificate chains that include policy constraints.
network
low complexity
openssl CWE-295
7.5
2023-03-17 CVE-2021-21548 Improper Certificate Validation vulnerability in Dell products
Dell EMC Unisphere for PowerMax versions before 9.1.0.27, Dell EMC Unisphere for PowerMax Virtual Appliance versions before 9.1.0.27, and PowerMax OS Release 5978 contain an improper certificate validation vulnerability.
network
high complexity
dell CWE-295
7.4