İçeriğe atla
Noroxi

CWE-296 · 14 kayıt

Improper Following of a Certificate's Chain of Trust

Bu sınıftaki CVE’ler

14 kayıt

  • CVE-2025-48057
    37İzleyin

    Icinga 2 certificate renewal might incorrectly renew an invalid certificate

    KritikCVSS 9,3İstismar yokEPSS %0

    icinga · icinga27 May 2025

  • CVE-2026-96770
    37İzleyin

    s2s-proxy accepts untrusted client certificates

    KritikCVSS 9,3İstismar yokEPSS %0

    temporal technologies, inc. · s2s-proxy23 Eyl 2026

  • CVE-2026-33779
    33İzleyin

    Junos OS: SRX Series: Insufficient certificate verification for device to SD cloud communication

    YüksekCVSS 8,3İstismar yokEPSS %0

    juniper · junos9 Nis 2026

  • CVE-2026-24066
    33İzleyin

    Slate Digital Connect macOS XPC certificate validation privilege escalation

    YüksekCVSS 8,4İstismar yokEPSS %0

    slate digital llc · slate digital connect10 Haz 2026

  • CVE-2021-23162
    32İzleyin

    Improper validation of the cloud certificate chain in Mobile Connect allows man-in-the-middle attack to impersonate the legitimate Command C

    YüksekCVSS 8,1İstismar yokEPSS %0

    gallagher · command centre mobile connect18 Kas 2021

  • CVE-2025-1146
    32İzleyin

    CrowdStrike Falcon Sensor for Linux TLS Issue

    YüksekCVSS 8,1İstismar yokEPSS %0

    crowdstrike · falcon sensor for linux12 Şub 2025

  • CVE-2019-3762
    30İzleyin

    Data Protection Central versions 1.0, 1.0.1, 18.1, 18.2, and 19.1 contains an Improper Certificate Chain of Trust Vulnerability.

    YüksekCVSS 7,5İstismar yokEPSS %1

    dell · emc data protection central18 Mar 2020

  • CVE-2021-1566
    29İzleyin

    Cisco Email Security Appliance and Cisco Web Security Appliance Certificate Validation Vulnerability

    YüksekCVSS 7,4İstismar yokEPSS %1

    cisco · email security appliance16 Haz 2021

  • CVE-2026-44852
    28İzleyin

    Authenticated Remote Code Execution via Arbitrary File Overwrite in the AOS-8 and AOS-10 Web-Based Management Interface

    YüksekCVSS 7,2İstismar yokEPSS %1

    arubanetworks · arubaos12 May 2026

  • CVE-2021-23155
    27İzleyin

    Improper validation of the cloud certificate chain in Mobile Client allows man-in-the-middle attack to impersonate the legitimate Command Ce

    OrtaCVSS 6,8İstismar yokEPSS %0

    gallagher · command centre mobile client18 Kas 2021

  • CVE-2026-73542
    25İzleyin

    Multiple SEIKO EPSON printers and scanners contain revoked root certificates.

    OrtaCVSS 6,3İstismar yokEPSS %0

    seiko epson corporation · multiple seiko epson printers and scanners20 Ağu 2026

  • CVE-2021-44532
    24İzleyin

    Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 converts SANs (Subject Alternative Names) to a string format.

    OrtaCVSS 5,3İstismar yokEPSS %10

    nodejs · node.js24 Şub 2022

  • CVE-2025-22459
    19İzleyin

    Improper certificate validation in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows a remote unauthenticate

    OrtaCVSS 4,8İstismar yokEPSS %0

    ivanti · endpoint manager8 Nis 2025

  • CVE-2024-43196
    17İzleyin

    IBM OpenPages data manipulation

    OrtaCVSS 4,3İstismar yokEPSS %0

    ibm · openpages with watson20 Şub 2025

Tüm zafiyet sınıfları