Vulnerabilities > Improper Certificate Validation

DATE CVE VULNERABILITY TITLE RISK
2021-10-28 CVE-2021-22278 Improper Certificate Validation vulnerability in ABB Update Manager
A certificate validation vulnerability in PCM600 Update Manager allows attacker to get unwanted software packages to be installed on computer which has PCM600 installed.
local
low complexity
abb CWE-295
6.7
2021-10-27 CVE-2021-36756 Improper Certificate Validation vulnerability in Northern.Tech Cfengine
CFEngine Enterprise 3.15.0 through 3.15.4 has Missing SSL Certificate Validation.
network
low complexity
northern-tech CWE-295
6.5
2021-10-18 CVE-2021-41611 Improper Certificate Validation vulnerability in multiple products
An issue was discovered in Squid 5.0.6 through 5.1.x before 5.2.
network
low complexity
squid-cache fedoraproject CWE-295
7.5
2021-10-13 CVE-2021-20833 Improper Certificate Validation vulnerability in Soda-Inc Snkrdunk
The SNKRDUNK Market Place App for iOS versions prior to 2.2.0 does not verify server certificate properly, which allows man-in-the-middle attackers to eavesdrop on and/or alter encrypted communication via a crafted certificate.
network
high complexity
soda-inc CWE-295
7.4
2021-10-12 CVE-2021-25634 Improper Certificate Validation vulnerability in multiple products
LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occurred since the last signing and that the signature is valid.
network
low complexity
libreoffice debian CWE-295
7.5
2021-10-11 CVE-2021-25633 Improper Certificate Validation vulnerability in multiple products
LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occurred since the last signing and that the signature is valid.
network
low complexity
libreoffice debian CWE-295
7.5
2021-10-05 CVE-2021-35497 Improper Certificate Validation vulnerability in Tibco Activespaces, Eftl and FTL
The FTL Server (tibftlserver) and Docker images containing tibftlserver components of TIBCO Software Inc.'s TIBCO ActiveSpaces - Community Edition, TIBCO ActiveSpaces - Developer Edition, TIBCO ActiveSpaces - Enterprise Edition, TIBCO FTL - Community Edition, TIBCO FTL - Developer Edition, TIBCO FTL - Enterprise Edition, TIBCO eFTL - Community Edition, TIBCO eFTL - Developer Edition, and TIBCO eFTL - Enterprise Edition contain a vulnerability that theoretically allows a non-administrative, authenticated FTL user to trick the affected components into creating illegitimate certificates.
network
high complexity
tibco CWE-295
7.5
2021-09-27 CVE-2021-33907 Improper Certificate Validation vulnerability in Zoom Meetings
The Zoom Client for Meetings for Windows in all versions before 5.3.0 fails to properly validate the certificate information used to sign .msi files when performing an update of the client.
network
low complexity
zoom CWE-295
critical
9.8
2021-09-23 CVE-2021-20435 Improper Certificate Validation vulnerability in IBM Security Verify Bridge
IBM Security Verify Bridge 1.0.5.0 does not properly validate a certificate which could allow a local attacker to obtain sensitive information that could aid in further attacks against the system.
local
low complexity
ibm CWE-295
5.5
2021-09-23 CVE-2021-38864 Improper Certificate Validation vulnerability in IBM Security Verify Bridge
IBM Security Verify Bridge 1.0.5.0 could allow a user to obtain sensitive information due to improper certificate validation.
network
low complexity
ibm CWE-295
7.5