Vulnerabilities > Improper Certificate Validation

DATE CVE VULNERABILITY TITLE RISK
2020-06-03 CVE-2020-13254 Improper Certificate Validation vulnerability in multiple products
An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7.
5.9
2020-05-28 CVE-2020-13245 Improper Certificate Validation vulnerability in Netgear products
Certain NETGEAR devices are affected by Missing SSL Certificate Validation.
network
high complexity
netgear CWE-295
5.9
2020-05-28 CVE-2020-13645 Improper Certificate Validation vulnerability in multiple products
In GNOME glib-networking through 2.64.2, the implementation of GTlsClientConnection skips hostname verification of the server's TLS certificate if the application fails to specify the expected server identity.
6.5
2020-05-26 CVE-2020-13616 Improper Certificate Validation vulnerability in Pichi Project Pichi
The boost ASIO wrapper in net/asio.cpp in Pichi before 1.3.0 lacks TLS hostname verification.
network
high complexity
pichi-project CWE-295
5.9
2020-05-26 CVE-2020-13615 Improper Certificate Validation vulnerability in Qore
lib/QoreSocket.cpp in Qore before 0.9.4.2 lacks hostname verification for X.509 certificates.
network
high complexity
qore CWE-295
5.9
2020-05-26 CVE-2020-13614 Improper Certificate Validation vulnerability in multiple products
An issue was discovered in ssl.c in Axel before 2.17.8.
network
high complexity
axel-project fedoraproject opensuse CWE-295
5.9
2020-05-25 CVE-2020-13482 Improper Certificate Validation vulnerability in multiple products
EM-HTTP-Request 1.1.5 uses the library eventmachine in an insecure way that allows an attacker to perform a man-in-the-middle attack against users of the library.
7.4
2020-05-21 CVE-2020-1113 Improper Certificate Validation vulnerability in Microsoft products
A security feature bypass vulnerability exists in Microsoft Windows when the Task Scheduler service fails to properly verify client connections over RPC, aka 'Windows Task Scheduler Security Feature Bypass Vulnerability'.
network
high complexity
microsoft CWE-295
7.5
2020-05-19 CVE-2020-13163 Improper Certificate Validation vulnerability in Em-Imap Project Em-Imap 0.5
em-imap 0.5 uses the library eventmachine in an insecure way that allows an attacker to perform a man-in-the-middle attack against users of the library.
network
high complexity
em-imap-project CWE-295
7.4
2020-05-15 CVE-2020-1758 Improper Certificate Validation vulnerability in Redhat Keycloak
A flaw was found in Keycloak in versions before 10.0.0, where it does not perform the TLS hostname verification while sending emails using the SMTP server.
network
high complexity
redhat CWE-295
5.9