<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Cryptographic Weakness (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/crypto.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/crypto-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Cryptographic Weakness (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:41 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-47074 – Improper Certificate Validation vulnerability in ex-aws ex_aws_sns (ExAws.SNS, E...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-47074</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-47074</guid>
    <pubDate>Thu, 28 May 2026 10:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-47074</strong></p>
  <p>Improper Certificate Validation vulnerability in ex-aws ex_aws_sns (ExAws.SNS, ExAws.SNS.PublicKeyCache modules) allows Signature Spoofing by Improper Validation.  This vulnerability is associated with program files lib/ex_aws/sns.ex, lib/ex_aws/sns/public_key_cache.ex and program routines 'Elixir.ExAws.SNS':verify_message/1, 'Elixir.ExAws.SNS.PublicKeyCache':get/1.  'Elixir.ExAws.SNS':verify_mes…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-47074">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42790 – Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42790</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42790</guid>
    <pubDate>Wed, 27 May 2026 17:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42790</strong></p>
  <p>Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_cert and public_key modules) allows a DNS nameConstraints bypass via subject CommonName fallback in TLS hostname verification.  Two flaws combine to allow a subordinate CA whose DNS nameConstraints are restricted (e.g. permitted;DNS:allowed.example.com) to issue a leaf certificate that an OTP TLS client accepts as a va…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42790">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-49000 – An insecure password scheme refers to vulnerabilities arising from improper sele...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-49000</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-49000</guid>
    <pubDate>Wed, 27 May 2026 05:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-49000</strong></p>
  <p>An insecure password scheme refers to vulnerabilities arising from improper selection of encryption algorithms, inadequate key management, or flawed code implementation, which may lead to data leakage or tampering, such as hard-coded keys or the use of weak encryption algorithms.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-310</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-49000">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8992 – An improper certificate validation vulnerability in Ivanti Secure Access Client ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8992</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8992</guid>
    <pubDate>Fri, 22 May 2026 15:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8992</strong></p>
  <p>An improper certificate validation vulnerability in Ivanti Secure Access Client before 22.8R6 allows a remote unauthenticated attacker to execute arbitrary code.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8992">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41872 – "Kura Sushi Official App" provided by EPG, Inc. is vulnerable to improper certif...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41872</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41872</guid>
    <pubDate>Tue, 12 May 2026 06:16:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41872</strong></p>
  <p>"Kura Sushi Official App" provided by EPG, Inc. is vulnerable to improper certificate validation. A man-in-the-middle attack may allow eavesdropping on, or altering, the communication on push notifications between the affected application and the relevant server.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41872">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7807 – SmarterTools SmarterMail builds prior to 9560 contain a local file inclusion vul...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7807</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7807</guid>
    <pubDate>Fri, 08 May 2026 20:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7807</strong></p>
  <p>SmarterTools SmarterMail builds prior to 9560 contain a local file inclusion vulnerability in the /api/v1/report/summary/{type} API endpoint that allows authenticated users to read arbitrary .json files on the system. Attackers can exploit this vulnerability combined with weak encryption algorithms and hardcoded keys to decrypt and access stored passwords and 2FA secrets for all users.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7807">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7821 – Improper certificate validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7821</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7821</guid>
    <pubDate>Thu, 07 May 2026 16:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7821</strong></p>
  <p>Improper certificate validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to enroll a device belonging to a restricted set of unenrolled devices, leading to information disclosure about EPMM appliance and impacting on the integrity of the newly enrolled device identity.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7821">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5787 – An Improper Certificate Validation in Ivanti EPMM before versions 12.6.1.1, 12.7...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5787</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5787</guid>
    <pubDate>Thu, 07 May 2026 16:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5787</strong></p>
  <p>An Improper Certificate Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to impersonate registered Sentry hosts and obtain valid CA-signed client certificates.</p>
  <p><strong>CVSS:</strong> 8.9 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5787">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-23776 – Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Featu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23776</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23776</guid>
    <pubDate>Fri, 17 Apr 2026 10:16:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-23776</strong></p>
  <p>Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60, contain(s) an Improper Certificate Validation vulnerability in certificate-based login. A low privileged attacker with remote access could potentially exploit this vulnerabili…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23776">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-20184 – A vulnerability in the integration of single sign-on (SSO) with Control Hub in C...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20184</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20184</guid>
    <pubDate>Wed, 15 Apr 2026 17:17:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-20184</strong></p>
  <p>A vulnerability in the integration of single sign-on (SSO) with Control Hub in Cisco Webex Services could have allowed an unauthenticated, remote attacker to impersonate any user within the service.  This vulnerability existed because of improper certificate validation. Prior to this vulnerability being addressed, an attacker could have exploited this vulnerability by connecting to a service en…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20184">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32144 – Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32144</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32144</guid>
    <pubDate>Tue, 07 Apr 2026 13:16:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32144</strong></p>
  <p>Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_ocsp module) allows OCSP designated-responder authorization bypass via missing signature verification.  The OCSP response validation in public_key:pkix_ocsp_validate/5 does not verify that a CA-designated responder certificate was cryptographically signed by the issuing CA. Instead, it only checks that the responder ce…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32144">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-35560 – Improper certificate validation in the identity provider connection components i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35560</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35560</guid>
    <pubDate>Fri, 03 Apr 2026 21:17:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-35560</strong></p>
  <p>Improper certificate validation in the identity provider connection components in Amazon Athena ODBC driver before 2.1.0.0 might allow a man-in-the-middle threat actor to intercept authentication credentials due to insufficient default transport security when connecting to identity providers. This only applies to connections with external identity providers and does not apply to connections with…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35560">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-4434 – Improper certificate validation in the PAM propagation WinRM connections
 allows...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4434</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4434</guid>
    <pubDate>Fri, 20 Mar 2026 13:16:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-4434</strong></p>
  <p>Improper certificate validation in the PAM propagation WinRM connections  allows a network attacker to perform a man-in-the-middle attack via  disabled TLS certificate verification.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4434">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-4396 – Improper certificate validation in Devolutions Hub Reporting Service 
2025.3.1.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4396</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4396</guid>
    <pubDate>Wed, 18 Mar 2026 20:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-4396</strong></p>
  <p>Improper certificate validation in Devolutions Hub Reporting Service  2025.3.1.1 and earlier allows a network attacker to perform a  man-in-the-middle attack via disabled TLS certificate verification.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4396">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-2368 – An improper certificate validation vulnerability was reported in the Lenovo File...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2368</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2368</guid>
    <pubDate>Wed, 11 Mar 2026 21:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-2368</strong></p>
  <p>An improper certificate validation vulnerability was reported in the Lenovo Filez application that could allow a user capable of intercepting network traffic to execute arbitrary code.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2368">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-30794 – Improper Certificate Validation vulnerability in rustdesk-client RustDesk Client...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30794</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30794</guid>
    <pubDate>Thu, 05 Mar 2026 16:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-30794</strong></p>
  <p>Improper Certificate Validation vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (HTTP API client, TLS transport modules) allows Adversary in the Middle (AiTM). This vulnerability is associated with program files src/hbbs_http/http_client.Rs and program routines TLS retry with danger_accept_invalid_certs(true).  This issue affects RustDesk Cl…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30794">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-3336 – Improper certificate validation in PKCS7_verify() in AWS-LC allows an unauthenti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3336</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3336</guid>
    <pubDate>Mon, 02 Mar 2026 22:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-3336</strong></p>
  <p>Improper certificate validation in PKCS7_verify() in AWS-LC allows an unauthenticated user to bypass certificate chain verification when processing PKCS7 objects with multiple signers, except the final signer.  Customers of AWS services do not need to take action. Applications using AWS-LC should upgrade to AWS-LC version 1.69.0.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3336">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-70058 – An issue pertaining to CWE-295: Improper Certificate Validation was discovered i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-70058</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-70058</guid>
    <pubDate>Mon, 23 Feb 2026 16:29:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-70058</strong></p>
  <p>An issue pertaining to CWE-295: Improper Certificate Validation was discovered in YMFE yapi v1.12.0. The application disables TLS/SSL certificate validation by setting 'rejectUnauthorized': false in the HTTPS agent configuration for Axios requests</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-70058">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-70045 – An issue pertaining to CWE-295: Improper Certificate Validation was discovered i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-70045</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-70045</guid>
    <pubDate>Mon, 23 Feb 2026 16:29:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-70045</strong></p>
  <p>An issue pertaining to CWE-295: Improper Certificate Validation was discovered in jxcore jxm master. The application disables TLS/SSL certificate validation by setting 'rejectUnauthorized': false in HTTPS request options when 'jx_obj.IsSecure' is true</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-70045">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-70043 – An issue pertaining to CWE-295: Improper Certificate Validation was discovered i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-70043</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-70043</guid>
    <pubDate>Mon, 23 Feb 2026 16:29:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-70043</strong></p>
  <p>An issue pertaining to CWE-295: Improper Certificate Validation was discovered in Ayms node-To master. The application disables TLS/SSL certificate validation by setting 'rejectUnauthorized': false in TLS socket options</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-70043">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-21228 – Improper certificate validation in Azure Local allows an unauthorized attacker t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21228</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-21228</guid>
    <pubDate>Tue, 10 Feb 2026 18:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-21228</strong></p>
  <p>Improper certificate validation in Azure Local allows an unauthorized attacker to execute code over a network.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21228">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-15557 – An Improper Certificate Validation vulnerability in TP-Link Tapo H100 v1 and Tap...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-15557</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-15557</guid>
    <pubDate>Thu, 05 Feb 2026 18:16:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-15557</strong></p>
  <p>An Improper Certificate Validation vulnerability in TP-Link Tapo H100 v1 and Tapo P100 v1 allows an on-path attacker on the same network segment to intercept and modify encrypted device-cloud communications.  This may compromise the confidentiality and integrity of device-to-cloud communication, enabling manipulation of device data or operations.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-15557">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-67229 – An improper certificate validation vulnerability exists in ToDesktop Builder v0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-67229</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-67229</guid>
    <pubDate>Fri, 23 Jan 2026 17:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-67229</strong></p>
  <p>An improper certificate validation vulnerability exists in ToDesktop Builder v0.32.1 This vulnerability allows an unauthenticated, on-path attacker to spoof backend responses by exploiting insufficient certificate validation.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-67229">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-11043 – An Improper Certificate Validation vulnerability in the OPC-UA client and ANSL o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-11043</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-11043</guid>
    <pubDate>Mon, 19 Jan 2026 16:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-11043</strong></p>
  <p>An Improper Certificate Validation vulnerability in the OPC-UA client and ANSL over TLS client used in Automation Studio versions before 6.5 could allow an unauthenticated attacker on the network to position themselves to intercept and interfere with data exchanges.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-11043">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-22079 – This vulnerability exists in Tenda wireless routers (300Mbps Wireless Router F3 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22079</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22079</guid>
    <pubDate>Fri, 09 Jan 2026 11:15:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-22079</strong></p>
  <p>This vulnerability exists in Tenda wireless routers (300Mbps Wireless Router F3 and N300 Easy Setup Router) due to the plaintext transmission of login credentials during the initial login or post-factory reset setup through the web-based administrative interface. An attacker on the same network could exploit this vulnerability by intercepting network traffic and capturing the credentials transmit…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-319</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22079">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-54981 – Weak Encryption Algorithm in StreamPark, The use of an AES cipher in ECB mode an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54981</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54981</guid>
    <pubDate>Fri, 12 Dec 2025 15:15:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-54981</strong></p>
  <p>Weak Encryption Algorithm in StreamPark, The use of an AES cipher in ECB mode and a weak random number generator for encrypting sensitive data, including JWT tokens, may have risked exposing sensitive authentication data  This issue affects Apache StreamPark: from 2.0.0 before 2.1.7.  Users are recommended to upgrade to version 2.1.7, which fixes the issue.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-327</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54981">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-12943 – Improper certificate
validation in firmware update logic in NETGEAR RAX30 (Night...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-12943</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-12943</guid>
    <pubDate>Tue, 11 Nov 2025 17:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-12943</strong></p>
  <p>Improper certificate validation in firmware update logic in NETGEAR RAX30 (Nighthawk AX5 5-Stream AX2400 WiFi 6 Router) and RAXE300 (Nighthawk AXE7800 Tri-Band WiFi 6E Router) allows attackers with the ability to intercept and tamper traffic destined to the device to execute arbitrary commands on the device.  Devices with automatic updates enabled may already have this patch applied. If not, plea…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-12943">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-11619 – Improper certificate validation when connecting to gateways in Devolutions Serve...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-11619</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-11619</guid>
    <pubDate>Wed, 15 Oct 2025 20:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-11619</strong></p>
  <p>Improper certificate validation when connecting to gateways in Devolutions Server 2025.3.2 and earlier allows attackers in MitM position to intercept traffic.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-11619">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-30278 – An improper certificate validation vulnerability has been reported to affect Qsy...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-30278</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-30278</guid>
    <pubDate>Fri, 29 Aug 2025 18:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-30278</strong></p>
  <p>An improper certificate validation vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to compromise the security of the system.  We have already fixed the vulnerability in the following version: Qsync Central 4.5.0.7 ( 2025/04/23 ) and later</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-30278">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-30277 – An improper certificate validation vulnerability has been reported to affect Qsy...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-30277</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-30277</guid>
    <pubDate>Fri, 29 Aug 2025 18:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-30277</strong></p>
  <p>An improper certificate validation vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to compromise the security of the system.  We have already fixed the vulnerability in the following version: Qsync Central 4.5.0.7 ( 2025/04/23 ) and later</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-30277">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-8393 – A TLS vulnerability exists in the phone application used to manage a 
connected ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-8393</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-8393</guid>
    <pubDate>Fri, 08 Aug 2025 17:15:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-8393</strong></p>
  <p>A TLS vulnerability exists in the phone application used to manage a  connected device. The phone application accepts self-signed certificates  when establishing TLS communication which may result in  man-in-the-middle attacks on untrusted networks. Captured communications  may include user credentials and sensitive session tokens.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-8393">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-45765 – ruby-jwt v3.0.0.beta1 was discovered to contain weak encryption. NOTE: the Suppl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-45765</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-45765</guid>
    <pubDate>Thu, 07 Aug 2025 21:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-45765</strong></p>
  <p>ruby-jwt v3.0.0.beta1 was discovered to contain weak encryption. NOTE: the Supplier's perspective is "keysize is not something that is enforced by this library. Currently more recent versions of OpenSSL are enforcing some key sizes and those restrictions apply to the users of this gem also."</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-326</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-45765">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-45766 – poco v1.14.1-release was discovered to contain weak encryption. NOTE: this issue...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-45766</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-45766</guid>
    <pubDate>Wed, 06 Aug 2025 20:15:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-45766</strong></p>
  <p>poco v1.14.1-release was discovered to contain weak encryption. NOTE: this issue has been disputed on the basis that key lengths are expected to be set by an application, not by this library. This dispute is subject to review under CNA rules 4.1.4, 4.1.14, and other rules; the dispute tagging is not meant to recommend an outcome for this CVE Record.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-327</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-45766">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-8476 – Alpine iLX-507 TIDAL Improper Certificate Validation Vulnerability. This vulnera...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-8476</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-8476</guid>
    <pubDate>Fri, 01 Aug 2025 18:15:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-8476</strong></p>
  <p>Alpine iLX-507 TIDAL Improper Certificate Validation Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Alpine iLX-507 devices. Authentication is not required to exploit this vulnerability.  The specific flaw exists within the TIDAL music streaming application. The issue results from improper certificate validation. An attack…</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-8476">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-45767 – jose v6.0.10 was discovered to contain weak encryption. NOTE: this is disputed b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-45767</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-45767</guid>
    <pubDate>Fri, 01 Aug 2025 15:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-45767</strong></p>
  <p>jose v6.0.10 was discovered to contain weak encryption. NOTE: this is disputed by a third party because the claim of "do not meet recommended security standards" does not reflect guidance in a final publication.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-327</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-45767">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-45768 – pyjwt v2.10.1 was discovered to contain weak encryption. NOTE: this is disputed ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-45768</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-45768</guid>
    <pubDate>Thu, 31 Jul 2025 21:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-45768</strong></p>
  <p>pyjwt v2.10.1 was discovered to contain weak encryption. NOTE: this is disputed by the Supplier because the key length is chosen by the application that uses the library (admittedly, library users may benefit from a minimum value and a mechanism for opting in to strict enforcement).</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-311</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-45768">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-45770 – jwt v5.4.3 was discovered to contain weak encryption. NOTE: this issue has been ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-45770</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-45770</guid>
    <pubDate>Thu, 31 Jul 2025 20:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-45770</strong></p>
  <p>jwt v5.4.3 was discovered to contain weak encryption. NOTE: this issue has been disputed on the basis that key lengths are expected to be set by an application, not by this library. This dispute is subject to review under CNA rules 4.1.4, 4.1.14, and other rules; the dispute tagging is not meant to recommend an outcome for this CVE Record.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-326</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-45770">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-46788 – Improper certificate validation in Zoom Workplace for Linux before version 6.4.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-46788</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-46788</guid>
    <pubDate>Thu, 10 Jul 2025 16:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-46788</strong></p>
  <p>Improper certificate validation in Zoom Workplace for Linux before version 6.4.13 may allow an unauthorized user to conduct an information disclosure via network access.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-46788">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-34066 – An improper certificate validation vulnerability exists in AVTECH IP cameras, DV...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-34066</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-34066</guid>
    <pubDate>Tue, 01 Jul 2025 15:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-34066</strong></p>
  <p>An improper certificate validation vulnerability exists in AVTECH IP cameras, DVRs, and NVRs due to the use of wget with --no-check-certificate in scripts like SyncCloudAccount.sh and SyncPermit.sh. This exposes HTTPS communications to man-in-the-middle (MITM) attacks.</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-34066">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-33031 – An improper certificate validation vulnerability has been reported to affect Fil...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-33031</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-33031</guid>
    <pubDate>Fri, 06 Jun 2025 16:15:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-33031</strong></p>
  <p>An improper certificate validation vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to compromise the security of the system.  We have already fixed the vulnerability in the following version: File Station 5 5.5.6.4847 and later</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-33031">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-30279 – An improper certificate validation vulnerability has been reported to affect Fil...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-30279</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-30279</guid>
    <pubDate>Fri, 06 Jun 2025 16:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-30279</strong></p>
  <p>An improper certificate validation vulnerability has been reported to affect File Station 5. If a remote  attacker gains a user account, they can then exploit the vulnerability to compromise the security of the system.  We have already fixed the vulnerability in the following version: File Station 5 5.5.6.4847 and later</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-30279">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-29885 – An improper certificate validation vulnerability has been reported to affect Fil...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-29885</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-29885</guid>
    <pubDate>Fri, 06 Jun 2025 16:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-29885</strong></p>
  <p>An improper certificate validation vulnerability has been reported to affect File Station 5. If exploited, the vulnerability could allow remote attackers who have gained user access to compromise the security of the system.  We have already fixed the vulnerability in the following versions: File Station 5 5.5.6.4791 and later   and later</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-29885">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-29884 – An improper certificate validation vulnerability has been reported to affect Fil...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-29884</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-29884</guid>
    <pubDate>Fri, 06 Jun 2025 16:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-29884</strong></p>
  <p>An improper certificate validation vulnerability has been reported to affect File Station 5. If exploited, the vulnerability could allow remote attackers who have gained user access to compromise the security of the system.  We have already fixed the vulnerability in the following versions: File Station 5 5.5.6.4791 and later   and later</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-29884">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-29883 – An improper certificate validation vulnerability has been reported to affect Fil...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-29883</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-29883</guid>
    <pubDate>Fri, 06 Jun 2025 16:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-29883</strong></p>
  <p>An improper certificate validation vulnerability has been reported to affect File Station 5. If exploited, the vulnerability could allow remote attackers who have gained user access to compromise the security of the system.  We have already fixed the vulnerability in the following versions: File Station 5 5.5.6.4791 and later   and later</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-29883">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-22486 – An improper certificate validation vulnerability has been reported to affect Fil...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-22486</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-22486</guid>
    <pubDate>Fri, 06 Jun 2025 16:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-22486</strong></p>
  <p>An improper certificate validation vulnerability has been reported to affect File Station 5. If exploited, the vulnerability could allow remote attackers who have gained user access to compromise the security of the system.  We have already fixed the vulnerability in the following versions: File Station 5 5.5.6.4791 and later   and later</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22486">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-10444 – Improper certificate validation vulnerability in the LDAP utilities in Synology ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-10444</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-10444</guid>
    <pubDate>Wed, 19 Mar 2025 02:15:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-10444</strong></p>
  <p>Improper certificate validation vulnerability in the LDAP utilities in Synology DiskStation Manager (DSM) before 7.1.1-42962-8, 7.2.1-69057-7 and 7.2.2-72806-3 allows man-in-the-middle attackers to hijack the authentication of administrators via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-10444">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-43107 – Improper Certificate Validation (CWE-295) in the Gallagher Milestone Integration...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-43107</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-43107</guid>
    <pubDate>Mon, 10 Mar 2025 03:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-43107</strong></p>
  <p>Improper Certificate Validation (CWE-295) in the Gallagher Milestone Integration Plugin (MIP) permits unauthenticated messages (e.g. alarm events) to be sent to the Plugin. This issue effects Gallagher MIPS Plugin v4.0 prior to v4.0.32, all versions of v3.0 and prior.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-43107">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-41724 – Improper Certificate Validation (CWE-295) in the Gallagher Command Centre SALTO ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-41724</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-41724</guid>
    <pubDate>Mon, 10 Mar 2025 03:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-41724</strong></p>
  <p>Improper Certificate Validation (CWE-295) in the Gallagher Command Centre SALTO integration allowed an attacker to spoof the SALTO server.      This issue affects all versions of Gallagher Command Centre prior to 9.20.1043.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-41724">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-50394 – An improper certificate validation vulnerability has been reported to affect Hel...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-50394</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-50394</guid>
    <pubDate>Fri, 07 Mar 2025 17:15:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-50394</strong></p>
  <p>An improper certificate validation vulnerability has been reported to affect Helpdesk. If exploited, the vulnerability could allow remote attackers to compromise the security of the system.  We have already fixed the vulnerability in the following version: Helpdesk 3.3.3 and later</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-50394">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-47092 – Insecure deserialization and improper certificate validation in Checkmk Exchange...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47092</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47092</guid>
    <pubDate>Mon, 03 Mar 2025 14:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-47092</strong></p>
  <p>Insecure deserialization and improper certificate validation in Checkmk Exchange plugin check-mk-api prior to 5.8.1</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47092">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-54089 – A vulnerability has been identified in APOGEE PXC Series (BACnet) (All versions)...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-54089</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-54089</guid>
    <pubDate>Tue, 11 Feb 2025 11:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-54089</strong></p>
  <p>A vulnerability has been identified in APOGEE PXC Series (BACnet) (All versions), APOGEE PXC Series (P2 Ethernet) (All versions), TALON TC Series (BACnet) (All versions). Affected devices contain a weak encryption mechanism based on a hard-coded key. This could allow an attacker to guess or decrypt the password from the cyphertext.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-326</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-54089">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-0477 – An encryption vulnerability exists in all versions prior to V15.00.001 of Rockwe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-0477</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-0477</guid>
    <pubDate>Thu, 30 Jan 2025 18:15:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-0477</strong></p>
  <p>An encryption vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation FactoryTalk® AssetCentre. The vulnerability exists due to a weak encryption methodology and could allow a threat actor to extract passwords belonging to other users of the application.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-522</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-0477">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-40702 – IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 could allo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-40702</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-40702</guid>
    <pubDate>Tue, 07 Jan 2025 16:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-40702</strong></p>
  <p>IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 could allow an unauthorized user to obtain valid tokens to gain access to protected resources due to improper certificate validation.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-40702">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-6001 – An improper certificate validation vulnerability was reported in LADM that could...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-6001</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-6001</guid>
    <pubDate>Mon, 16 Dec 2024 17:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-6001</strong></p>
  <p>An improper certificate validation vulnerability was reported in LADM that could allow a network attacker with the ability to redirect an update request to a remote server and execute code with elevated privileges.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-6001">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-48865 – An improper certificate validation vulnerability has been reported to affect sev...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-48865</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-48865</guid>
    <pubDate>Fri, 06 Dec 2024 17:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-48865</strong></p>
  <p>An improper certificate validation vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow attackers with local network access to compromise the security of the system.  We have already fixed the vulnerability in the following versions: QTS 5.1.9.2954 build 20241120 and later QTS 5.2.2.2950 build 20241114 and later QuTS hero h5…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-48865">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-45205 – An Improper Certificate Validation on the UniFi iOS App managing a standalone Un...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-45205</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-45205</guid>
    <pubDate>Wed, 04 Dec 2024 02:15:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-45205</strong></p>
  <p>An Improper Certificate Validation on the UniFi iOS App managing a standalone UniFi Access Point (not using UniFi Network Application) could allow a malicious actor with access to an adjacent network to take control of this UniFi Access Point.   Affected Products: UniFi iOS App (Version 10.17.7 and earlier)    Mitigation: UniFi iOS App (Version 10.18.0 or later).</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-45205">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-51634 – NETGEAR RAX30 Improper Certificate Validation Remote Code Execution Vulnerabilit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-51634</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-51634</guid>
    <pubDate>Fri, 22 Nov 2024 20:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-51634</strong></p>
  <p>NETGEAR RAX30 Improper Certificate Validation Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to compromise the integrity of downloaded information on affected installations of NETGEAR RAX30  routers. Authentication is not required to exploit this vulnerability.  The specific flaw exists within the downloading of files via HTTPS. The issue results from th…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-51634">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-38861 – Improper Certificate Validation in Checkmk Exchange plugin MikroTik allows attac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-38861</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-38861</guid>
    <pubDate>Fri, 27 Sep 2024 09:15:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-38861</strong></p>
  <p>Improper Certificate Validation in Checkmk Exchange plugin MikroTik allows attackers in MitM position to intercept traffic. This issue affects MikroTik: from 2.0.0 through 2.5.5, from 0.4a_mk through 2.0a.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-38861">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-41612 – Victure PC420 1.1.39 was discovered to use a weak encryption key for the file en...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-41612</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-41612</guid>
    <pubDate>Wed, 18 Sep 2024 18:15:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-41612</strong></p>
  <p>Victure PC420 1.1.39 was discovered to use a weak encryption key for the file enabled_telnet.dat on the Micro SD card.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-41612">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-40714 – An improper certificate validation vulnerability in TLS certificate validation a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-40714</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-40714</guid>
    <pubDate>Sat, 07 Sep 2024 17:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-40714</strong></p>
  <p>An improper certificate validation vulnerability in TLS certificate validation allows an attacker on the same network to intercept sensitive credentials during restore operations.</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-40714">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-38642 – An improper certificate validation vulnerability has been reported to affect QuM...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-38642</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-38642</guid>
    <pubDate>Fri, 06 Sep 2024 17:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-38642</strong></p>
  <p>An improper certificate validation vulnerability has been reported to affect QuMagie. If exploited, the vulnerability could allow local network users to compromise the security of the system via unspecified vectors.  We have already fixed the vulnerability in the following version: QuMagie 2.3.1 and later</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-38642">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-7570 – Improper certificate validation in Ivanti ITSM on-prem and Neurons for ITSM Vers...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-7570</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-7570</guid>
    <pubDate>Tue, 13 Aug 2024 19:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-7570</strong></p>
  <p>Improper certificate validation in Ivanti ITSM on-prem and Neurons for ITSM Versions 2023.4 and earlier allows a remote attacker in a MITM position to craft a token that would allow access to ITSM as any user.</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-7570">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-50178 – An improper certificate validation vulnerability [CWE-295] in FortiADC 7.4.0, 7...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-50178</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-50178</guid>
    <pubDate>Tue, 09 Jul 2024 16:15:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-50178</strong></p>
  <p>An improper certificate validation vulnerability [CWE-295] in FortiADC 7.4.0, 7.2.0 through 7.2.3, 7.1 all versions, 7.0 all versions, 6.2 all versions, 6.1 all versions and 6.0 all versions may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the communication channel between the device and various remote servers such as private SDN connectors and FortiToken C…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-50178">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-20080 – In gnss service, there is a possible escalation of privilege due to improper cer...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-20080</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-20080</guid>
    <pubDate>Mon, 01 Jul 2024 05:15:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-20080</strong></p>
  <p>In gnss service, there is a possible escalation of privilege due to improper certificate validation. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08720039; Issue ID: MSV-1424.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-20080">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-5261 – Improper Certificate Validation vulnerability in LibreOffice "LibreOfficeKit" mo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-5261</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-5261</guid>
    <pubDate>Tue, 25 Jun 2024 13:15:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-5261</strong></p>
  <p>Improper Certificate Validation vulnerability in LibreOffice "LibreOfficeKit" mode disables TLS certification verification  LibreOfficeKit can be used for accessing LibreOffice functionality  through C/C++. Typically this is used by third party components to reuse  LibreOffice as a library to convert, view or otherwise interact with  documents.  LibreOffice internally makes use of "curl" to fetch…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-5261">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-35140 – IBM Security Verify Access Docker 10.0.0 through 10.0.6 could allow a local user...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-35140</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-35140</guid>
    <pubDate>Fri, 31 May 2024 17:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-35140</strong></p>
  <p>IBM Security Verify Access Docker 10.0.0 through 10.0.6 could allow a local user to escalate their privileges due to improper certificate validation.  IBM X-Force ID:  292416.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-35140">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-29207 – An Improper Certificate Validation could allow a malicious actor with access to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-29207</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-29207</guid>
    <pubDate>Tue, 07 May 2024 17:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-29207</strong></p>
  <p>An Improper Certificate Validation could allow a malicious actor with access to an adjacent network to take control of the system.      Affected Products:  UniFi Connect Application (Version 3.7.9 and earlier)   UniFi Connect EV Station (Version 1.1.18 and earlier)   UniFi Connect EV Station Pro (Version 1.1.18 and earlier)  UniFi Connect Display (Version 1.9.324 and earlier)  UniFi Connect Displ…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-29207">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-35721 – NETGEAR Multiple Routers curl_post Improper Certificate Validation Remote Code E...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-35721</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-35721</guid>
    <pubDate>Fri, 03 May 2024 02:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-35721</strong></p>
  <p>NETGEAR Multiple Routers curl_post Improper Certificate Validation Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to compromise the integrity of downloaded information on affected installations of multiple NETGEAR routers. Authentication is not required to exploit this vulnerability.  The specific flaw exists within the update functionality, which operat…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-35721">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-3738 – A vulnerability classified as critical has been found in cym1102 nginxWebUI up t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-3738</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-3738</guid>
    <pubDate>Sat, 13 Apr 2024 18:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-3738</strong></p>
  <p>A vulnerability classified as critical has been found in cym1102 nginxWebUI up to 3.9.9. This affects the function handlePath of the file /adminPage/conf/saveCmd. The manipulation of the argument nginxPath leads to improper certificate validation. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-260577 was assigned to…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-3738">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-31871 – IBM Security Verify Access Appliance 10.0.0 through 10.0.7 could allow a malicio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-31871</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-31871</guid>
    <pubDate>Wed, 10 Apr 2024 16:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-31871</strong></p>
  <p>IBM Security Verify Access Appliance 10.0.0 through 10.0.7 could allow a malicious actor to conduct a man in the middle attack when deploying Python scripts due to improper certificate validation.  IBM X-Force ID:  287306.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-31871">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-27323 – PDF-XChange Editor Updater Improper Certificate Validation Remote Code Execution...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-27323</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-27323</guid>
    <pubDate>Mon, 01 Apr 2024 22:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-27323</strong></p>
  <p>PDF-XChange Editor Updater Improper Certificate Validation Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is not required to exploit this vulnerability.  The specific flaw exists within the update functionality. The issue results from the lack of proper validation…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-27323">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-50481 – An issue was discovered in blinksocks version 3.3.8, allows remote attackers to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-50481</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-50481</guid>
    <pubDate>Thu, 21 Dec 2023 11:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-50481</strong></p>
  <p>An issue was discovered in blinksocks version 3.3.8, allows remote attackers to obtain sensitive information via weak encryption algorithms in the component /presets/ssr-auth-chain.js.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-327</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-50481">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-6680 – An improper certificate validation issue in Smartcard authentication in GitLab E...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-6680</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-6680</guid>
    <pubDate>Fri, 15 Dec 2023 16:15:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-6680</strong></p>
  <p>An improper certificate validation issue in Smartcard authentication in GitLab EE affecting all versions from 11.6 prior to 16.4.4, 16.5 prior to 16.5.4, and 16.6 prior to 16.6.2 allows an attacker to authenticate as another user given their public key if they use Smartcard authentication. Smartcard authentication is an experimental feature and has to be manually enabled by an administrator.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-6680">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-48051 – An issue in /upydev/keygen.py in upydev v0.4.3 allows attackers to decrypt sensi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-48051</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-48051</guid>
    <pubDate>Mon, 20 Nov 2023 23:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-48051</strong></p>
  <p>An issue in /upydev/keygen.py in upydev v0.4.3 allows attackers to decrypt sensitive information via weak encryption padding.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-326</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-48051">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-30729 – Improper Certificate Validation in Samsung Email prior to version 6.1.82.0 allow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-30729</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-30729</guid>
    <pubDate>Wed, 06 Sep 2023 04:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-30729</strong></p>
  <p>Improper Certificate Validation in Samsung Email prior to version 6.1.82.0 allows remote attacker to intercept the network traffic including sensitive information.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-30729">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-45453 – TLS/SSL weak cipher suites enabled. The following products are affected: Acronis...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-45453</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-45453</guid>
    <pubDate>Thu, 18 May 2023 10:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-45453</strong></p>
  <p>TLS/SSL weak cipher suites enabled. The following products are affected: Acronis Cyber Protect 15 (Windows, Linux) before build 30984.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-310</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-45453">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-30351 – Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 was discovered to co...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-30351</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-30351</guid>
    <pubDate>Wed, 10 May 2023 16:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-30351</strong></p>
  <p>Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 was discovered to contain a hard-coded default password for root which is stored using weak encryption. This vulnerability allows attackers to connect to the TELNET service (or UART) by using the exposed credentials.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-326</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-30351">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-24461 – An improper certificate validation vulnerability exists in the BIG-IP Edge Clien...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-24461</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-24461</guid>
    <pubDate>Wed, 03 May 2023 15:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-24461</strong></p>
  <p>An improper certificate validation vulnerability exists in the BIG-IP Edge Client for Windows and macOS and may allow an attacker to impersonate a BIG-IP APM system.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-24461">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-22642 – An improper certificate validation vulnerability [CWE-295] in FortiAnalyzer and ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-22642</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-22642</guid>
    <pubDate>Tue, 11 Apr 2023 17:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-22642</strong></p>
  <p>An improper certificate validation vulnerability [CWE-295] in FortiAnalyzer and FortiManager 7.2.0 through 7.2.1, 7.0.0 through 7.0.5, 6.4.8 through 6.4.10 may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the communication channel between the device and the remote FortiGuard server hosting outbreakalert ressources.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-22642">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-28509 – Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-28509</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-28509</guid>
    <pubDate>Wed, 29 Mar 2023 21:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-28509</strong></p>
  <p>Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 use weak encryption for packet-level security and passwords transferred on the wire.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-327</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-28509">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-21548 – Dell EMC Unisphere for PowerMax versions before 9.1.0.27, Dell EMC Unisphere for...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-21548</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-21548</guid>
    <pubDate>Fri, 17 Mar 2023 06:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-21548</strong></p>
  <p>Dell EMC Unisphere for PowerMax versions before 9.1.0.27, Dell EMC Unisphere for PowerMax Virtual Appliance versions before 9.1.0.27, and PowerMax OS Release 5978 contain an improper certificate validation vulnerability. An unauthenticated remote attacker may potentially exploit this vulnerability to carry out a man-in-the-middle attack by supplying a crafted certificate and intercepting the vict…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-21548">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-0353 – Akuvox E11 uses a weak encryption algorithm for stored passwords and uses a hard...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-0353</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-0353</guid>
    <pubDate>Mon, 13 Mar 2023 21:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-0353</strong></p>
  <p>Akuvox E11 uses a weak encryption algorithm for stored passwords and uses a hard-coded password for decryption which could allow the encrypted passwords to be decrypted from the configuration file.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-0353">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-4895 – Improper Certificate Validation vulnerability in Hitachi Infrastructure Analytic...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-4895</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-4895</guid>
    <pubDate>Tue, 28 Feb 2023 03:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-4895</strong></p>
  <p>Improper Certificate Validation vulnerability in Hitachi Infrastructure Analytics Advisor on Linux (Analytics probe component), Hitachi Ops Center Analyzer on Linux (Analyzer probe component) allows Man in the Middle Attack.This issue affects Hitachi Infrastructure Analytics Advisor: from 2.0.0-00 through 4.4.0-00; Hitachi Ops Center Analyzer: from 10.0.0-00 before 10.9.1-00.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-4895">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-45100 – Dell PowerScale OneFS, versions 8.2.x-9.3.x, contains an Improper Certificate Va...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-45100</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-45100</guid>
    <pubDate>Wed, 01 Feb 2023 06:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-45100</strong></p>
  <p>Dell PowerScale OneFS, versions 8.2.x-9.3.x, contains an Improper Certificate Validation vulnerability. An remote unauthenticated attacker could potentially exploit this vulnerability, leading to a full compromise of the system.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-45100">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-32748 – A CWE-295: Improper Certificate Validation vulnerability exists that could cause...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-32748</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-32748</guid>
    <pubDate>Mon, 30 Jan 2023 23:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-32748</strong></p>
  <p>A CWE-295: Improper Certificate Validation vulnerability exists that could cause the CAE software to give wrong data to end users when using CAE to configure devices. Additionally, credentials could leak which would enable an attacker the ability to log into the configuration tool and compromise other devices in the network. Affected Products: EcoStruxure™ Cybersecurity Admin Expert (CAE) (Versio…</p>
  <p><strong>CVSS:</strong> 7.9 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-32748">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-0509 – Improper Certificate Validation in GitHub repository pyload/pyload prior to 0.5...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-0509</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-0509</guid>
    <pubDate>Thu, 26 Jan 2023 22:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-0509</strong></p>
  <p>Improper Certificate Validation in GitHub repository pyload/pyload prior to 0.5.0b3.dev44.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-0509">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-38241 – Deserialization issue discovered in Ruoyi before 4.6.1 allows remote attackers t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-38241</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-38241</guid>
    <pubDate>Fri, 16 Dec 2022 22:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-38241</strong></p>
  <p>Deserialization issue discovered in Ruoyi before 4.6.1 allows remote attackers to run arbitrary code via weak cipher in Shiro framework.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-38241">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-26305 – An Improper Certificate Validation vulnerability in LibreOffice existed where de...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-26305</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-26305</guid>
    <pubDate>Mon, 25 Jul 2022 15:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-26305</strong></p>
  <p>An Improper Certificate Validation vulnerability in LibreOffice existed where determining if a macro was signed by a trusted author was done by only matching the serial number and issuer string of the used certificate with that of a trusted certificate. This is not sufficient to verify that the macro was actually signed with the certificate. An adversary could therefore create an arbitrary certif…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-26305">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-31105 – Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo C...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31105</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31105</guid>
    <pubDate>Tue, 12 Jul 2022 22:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-31105</strong></p>
  <p>Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo CD starting with version 0.4.0 and prior to 2.2.11, 2.3.6, and 2.4.5 is vulnerable to an improper certificate validation bug which could cause Argo CD to trust a malicious (or otherwise untrustworthy) OpenID Connect (OIDC) provider. A patch for this vulnerability has been released in Argo CD versions 2.4.5, 2.3.6, and…</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31105">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-26184 – Dell BSAFE Micro Edition Suite, versions prior to 4.5.1, contain an Improper Cer...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-26184</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-26184</guid>
    <pubDate>Wed, 01 Jun 2022 15:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-26184</strong></p>
  <p>Dell BSAFE Micro Edition Suite, versions prior to 4.5.1, contain an Improper Certificate Validation vulnerability.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-26184">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-32997 – The affected Baker Hughes Bentley Nevada products (3500 System 1 6.x, Part No. 3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-32997</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-32997</guid>
    <pubDate>Wed, 25 May 2022 14:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-32997</strong></p>
  <p>The affected Baker Hughes Bentley Nevada products (3500 System 1 6.x, Part No. 3060/00 versions 6.98 and prior, 3500 System 1, Part No. 3071/xx & 3072/xx versions 21.1 HF1 and prior, 3500 Rack Configuration, Part No. 129133-01 versions 6.4 and prior, and 3500/22M Firmware, Part No. 288055-01 versions 5.05 and prior) utilize a weak encryption algorithm for storage and transmission of sensitive dat…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-916</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-32997">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-22549 – Dell PowerScale OneFS, 8.2.x-9.3.x, contains a Improper Certificate Validation. ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-22549</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-22549</guid>
    <pubDate>Tue, 12 Apr 2022 18:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-22549</strong></p>
  <p>Dell PowerScale OneFS, 8.2.x-9.3.x, contains a Improper Certificate Validation. A unauthenticated remote attacker could potentially exploit this vulnerability, leading to a man-in-the-middle capture of administrative credentials.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-22549">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-1252 – Use of a Broken or Risky Cryptographic Algorithm in GitHub repository gnuboard/g...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-1252</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-1252</guid>
    <pubDate>Mon, 11 Apr 2022 11:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-1252</strong></p>
  <p>Use of a Broken or Risky Cryptographic Algorithm in GitHub repository gnuboard/gnuboard5 prior to and including 5.5.5. A vulnerability in gnuboard v5.5.5 and below uses weak encryption algorithms leading to sensitive information exposure. This allows an attacker to derive the email address of any user, including when the 'Let others see my information.' box is ticked off. Or to send emails to any…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-327</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-1252">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-14481 – The DeskLock tool provided with FactoryTalk View SE uses a weak encryption algor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-14481</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-14481</guid>
    <pubDate>Thu, 24 Feb 2022 19:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-14481</strong></p>
  <p>The DeskLock tool provided with FactoryTalk View SE uses a weak encryption algorithm that may allow a local, authenticated attacker to decipher user credentials, including the Windows user or Windows DeskLock passwords. If the compromised user has an administrative account, an attacker could gain full access to the user’s operating system and certain components of FactoryTalk View SE.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-261</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-14481">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-25636 – LibreOffice supports digital signatures of ODF documents and macros within docum...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-25636</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-25636</guid>
    <pubDate>Thu, 24 Feb 2022 15:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-25636</strong></p>
  <p>LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occurred since the last signing and that the signature is valid. An Improper Certificate Validation vulnerability in LibreOffice allowed an attacker to create a digitally signed ODF document, by manipulating the documentsignatures.xml or macrosignatures.x…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-347</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-25636">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-41028 – A combination of a use of hard-coded cryptographic key vulnerability [CWE-321] i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-41028</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-41028</guid>
    <pubDate>Thu, 16 Dec 2021 19:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-41028</strong></p>
  <p>A combination of a use of hard-coded cryptographic key vulnerability [CWE-321] in FortiClientEMS 7.0.1 and below, 6.4.6 and below and an improper certificate validation vulnerability [CWE-297] in FortiClientWindows, FortiClientLinux and FortiClientMac 7.0.1 and below, 6.4.6 and below may allow an unauthenticated and network adjacent attacker to perform a man-in-the-middle attack between the EMS a…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-41028">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-23167 – Improper certificate validation vulnerability in SMTP Client allows man-in-the-m...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-23167</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-23167</guid>
    <pubDate>Thu, 18 Nov 2021 18:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-23167</strong></p>
  <p>Improper certificate validation vulnerability in SMTP Client allows man-in-the-middle attack to retrieve sensitive information from the Command Centre Server. This issue affects: Gallagher Command Centre 8.50 versions prior to 8.50.2048 (MR3); 8.40 versions prior to 8.40.2063 (MR4); 8.30 versions prior to 8.30.1454 (MR4) ; version 8.20 and prior versions.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-23167">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-25634 – LibreOffice supports digital signatures of ODF documents and macros within docum...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-25634</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-25634</guid>
    <pubDate>Tue, 12 Oct 2021 14:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-25634</strong></p>
  <p>LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occurred since the last signing and that the signature is valid. An Improper Certificate Validation vulnerability in LibreOffice allowed an attacker to modify a digitally signed ODF document to insert an additional signing time timestamp which LibreOffice…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-25634">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-25633 – LibreOffice supports digital signatures of ODF documents and macros within docum...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-25633</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-25633</guid>
    <pubDate>Mon, 11 Oct 2021 17:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-25633</strong></p>
  <p>LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occurred since the last signing and that the signature is valid. An Improper Certificate Validation vulnerability in LibreOffice allowed an attacker to create a digitally signed ODF document, by manipulating the documentsignatures.xml or macrosignatures.x…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-25633">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-38864 – IBM Security Verify Bridge 1.0.5.0 could allow a user to obtain sensitive inform...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-38864</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-38864</guid>
    <pubDate>Thu, 23 Sep 2021 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-38864</strong></p>
  <p>IBM Security Verify Bridge 1.0.5.0 could allow a user to obtain sensitive information due to improper certificate validation. IBM X-Force ID: 208155.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-38864">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
