Vulnerabilities > Improper Certificate Validation

DATE CVE VULNERABILITY TITLE RISK
2020-07-31 CVE-2020-15134 Improper Certificate Validation vulnerability in Faye Project Faye
Faye before version 1.4.0, there is a lack of certification validation in TLS handshakes.
network
high complexity
faye-project CWE-295
8.7
2020-07-31 CVE-2020-15133 Improper Certificate Validation vulnerability in Faye-Websocket Project Faye-Websocket
In faye-websocket before version 0.11.0, there is a lack of certification validation in TLS handshakes.
network
high complexity
faye-websocket-project CWE-295
8.7
2020-07-30 CVE-2020-16164 Improper Certificate Validation vulnerability in Ripe Rpki Validator 3
An issue was discovered in RIPE NCC RPKI Validator 3.x through 3.1-2020.07.06.14.28.
network
high complexity
ripe CWE-295
7.4
2020-07-30 CVE-2020-16163 Improper Certificate Validation vulnerability in Ripe Rpki Validator 3
An issue was discovered in RIPE NCC RPKI Validator 3.x before 3.1-2020.07.06.14.28.
network
low complexity
ripe CWE-295
critical
9.1
2020-07-30 CVE-2020-16162 Improper Certificate Validation vulnerability in Ripe Rpki Validator 3
An issue was discovered in RIPE NCC RPKI Validator 3.x through 3.1-2020.07.06.14.28.
network
low complexity
ripe CWE-295
7.5
2020-07-28 CVE-2020-10925 Improper Certificate Validation vulnerability in Netgear R6700 Firmware 1.0.4.8410.0.58
This vulnerability allows network-adjacent attackers to compromise the integrity of downloaded information on affected installations of NETGEAR R6700 V1.0.4.84_10.0.58 routers.
low complexity
netgear CWE-295
8.8
2020-07-22 CVE-2020-6529 Improper Certificate Validation vulnerability in multiple products
Inappropriate implementation in WebRTC in Google Chrome prior to 84.0.4147.89 allowed an attacker in a privileged network position to leak cross-origin data via a crafted HTML page.
network
low complexity
google debian opensuse fedoraproject CWE-295
4.3
2020-07-17 CVE-2019-12000 Improper Certificate Validation vulnerability in HP MSE MSG GW Application E-Ltu
HPE has found a potential Remote Access Restriction Bypass in HPE MSE Msg Gw application E-LTU prior to version 3.2 when HTTPS is used between the USSD and an external USSD service logic application.
network
high complexity
hp CWE-295
6.6
2020-07-17 CVE-2020-15813 Improper Certificate Validation vulnerability in Graylog
Graylog before 3.3.3 lacks SSL Certificate Validation for LDAP servers.
network
high complexity
graylog CWE-295
8.1
2020-07-17 CVE-2020-14039 Improper Certificate Validation vulnerability in multiple products
In Go before 1.13.13 and 1.14.x before 1.14.5, Certificate.Verify may lack a check on the VerifyOptions.KeyUsages EKU requirements (if VerifyOptions.Roots equals nil and the installation is on Windows).
network
low complexity
golang opensuse CWE-295
5.3