<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Cryptographic Weakness</title>
  <link>https://cvedaily.com/pages/tags/crypto.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/crypto.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Cryptographic Weakness</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:41 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-47074 – Improper Certificate Validation vulnerability in ex-aws ex_aws_sns (ExAws.SNS, E...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-47074</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-47074</guid>
    <pubDate>Thu, 28 May 2026 10:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-47074</strong></p>
  <p>Improper Certificate Validation vulnerability in ex-aws ex_aws_sns (ExAws.SNS, ExAws.SNS.PublicKeyCache modules) allows Signature Spoofing by Improper Validation.  This vulnerability is associated with program files lib/ex_aws/sns.ex, lib/ex_aws/sns/public_key_cache.ex and program routines 'Elixir.ExAws.SNS':verify_message/1, 'Elixir.ExAws.SNS.PublicKeyCache':get/1.  'Elixir.ExAws.SNS':verify_mes…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-47074">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42790 – Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42790</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42790</guid>
    <pubDate>Wed, 27 May 2026 17:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42790</strong></p>
  <p>Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_cert and public_key modules) allows a DNS nameConstraints bypass via subject CommonName fallback in TLS hostname verification.  Two flaws combine to allow a subordinate CA whose DNS nameConstraints are restricted (e.g. permitted;DNS:allowed.example.com) to issue a leaf certificate that an OTP TLS client accepts as a va…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42790">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-42791 – Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42791</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42791</guid>
    <pubDate>Wed, 27 May 2026 14:16:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-42791</strong></p>
  <p>Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_ocsp module) allows forged OCSP responses signed with an expired responder certificate to be accepted as valid.  OCSP response verification in pubkey_ocsp:verify_response/5 and pubkey_ocsp:is_authorized_responder/3 in lib/public_key/src/pubkey_ocsp.erl does not check the validity period (notBefore/notAfter) of the OCSP…</p>
  <p><strong>CVSS:</strong> 3.7 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42791">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-49000 – An insecure password scheme refers to vulnerabilities arising from improper sele...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-49000</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-49000</guid>
    <pubDate>Wed, 27 May 2026 05:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-49000</strong></p>
  <p>An insecure password scheme refers to vulnerabilities arising from improper selection of encryption algorithms, inadequate key management, or flawed code implementation, which may lead to data leakage or tampering, such as hard-coded keys or the use of weak encryption algorithms.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-310</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-49000">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8992 – An improper certificate validation vulnerability in Ivanti Secure Access Client ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8992</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8992</guid>
    <pubDate>Fri, 22 May 2026 15:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8992</strong></p>
  <p>An improper certificate validation vulnerability in Ivanti Secure Access Client before 22.8R6 allows a remote unauthenticated attacker to execute arbitrary code.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8992">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-32745 – Dell PowerFlex Manager, version(s) &lt;=4.6.2, contain(s) an Improper Certificate V...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-32745</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-32745</guid>
    <pubDate>Fri, 22 May 2026 14:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-32745</strong></p>
  <p>Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Information tampering.</p>
  <p><strong>CVSS:</strong> 4.2 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-32745">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-41119 – Dell Live Optics Windows and Personal Edition collectors contain an improper cer...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41119</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41119</guid>
    <pubDate>Mon, 18 May 2026 11:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-41119</strong></p>
  <p>Dell Live Optics Windows and Personal Edition collectors contain an improper certificate validation vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability leading to loss of confidentiality and integrity.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41119">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-0249 – Multiple improper certificate validation vulnerabilities in the Palo Alto Networ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0249</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0249</guid>
    <pubDate>Wed, 13 May 2026 19:16:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-0249</strong></p>
  <p>Multiple improper certificate validation vulnerabilities in the Palo Alto Networks GlobalProtect™ app enables an attacker to intercept encrypted communications and potentially compromise the endpoint. This can enable a local non-administrative operating system user or an attacker on the same subnet to redirect traffic to an unauthorized server and facilitate the installation of malicious software…</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0249">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-0248 – An improper certificate validation vulnerability in the Prisma Access Agent® for...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0248</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0248</guid>
    <pubDate>Wed, 13 May 2026 19:16:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-0248</strong></p>
  <p>An improper certificate validation vulnerability in the Prisma Access Agent® for Android and Chrome OS enables an attacker to perform a man-in-the-middle (MitM) attack to intercept VPN traffic. By presenting a certificate for any domain issued by a trusted Certificate Authority, the attacker can capture sensitive device information.    The Prisma Access Agent on macOS, Windows, Linux and iOS are…</p>
  <p><strong>CVSS:</strong> 6.2 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0248">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-0244 – An improper certificate validation vulnerability in the Palo Alto Networks Prism...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0244</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0244</guid>
    <pubDate>Wed, 13 May 2026 19:16:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-0244</strong></p>
  <p>An improper certificate validation vulnerability in the Palo Alto Networks Prisma SD-WAN ION enables man-in-the-middle (MitM) attacker to impersonate the controller.</p>
  <p><strong>CVSS:</strong> 5.2 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0244">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41872 – "Kura Sushi Official App" provided by EPG, Inc. is vulnerable to improper certif...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41872</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41872</guid>
    <pubDate>Tue, 12 May 2026 06:16:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41872</strong></p>
  <p>"Kura Sushi Official App" provided by EPG, Inc. is vulnerable to improper certificate validation. A man-in-the-middle attack may allow eavesdropping on, or altering, the communication on push notifications between the affected application and the relevant server.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41872">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7807 – SmarterTools SmarterMail builds prior to 9560 contain a local file inclusion vul...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7807</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7807</guid>
    <pubDate>Fri, 08 May 2026 20:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7807</strong></p>
  <p>SmarterTools SmarterMail builds prior to 9560 contain a local file inclusion vulnerability in the /api/v1/report/summary/{type} API endpoint that allows authenticated users to read arbitrary .json files on the system. Attackers can exploit this vulnerability combined with weak encryption algorithms and hardcoded keys to decrypt and access stored passwords and 2FA secrets for all users.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7807">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7821 – Improper certificate validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7821</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7821</guid>
    <pubDate>Thu, 07 May 2026 16:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7821</strong></p>
  <p>Improper certificate validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to enroll a device belonging to a restricted set of unenrolled devices, leading to information disclosure about EPMM appliance and impacting on the integrity of the newly enrolled device identity.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7821">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5787 – An Improper Certificate Validation in Ivanti EPMM before versions 12.6.1.1, 12.7...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5787</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5787</guid>
    <pubDate>Thu, 07 May 2026 16:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5787</strong></p>
  <p>An Improper Certificate Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to impersonate registered Sentry hosts and obtain valid CA-signed client certificates.</p>
  <p><strong>CVSS:</strong> 8.9 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5787">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-40557 – Improper Certificate Validation via Global SSL Context Downgrade in Apache Storm...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40557</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40557</guid>
    <pubDate>Mon, 27 Apr 2026 14:16:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-40557</strong></p>
  <p>Improper Certificate Validation via Global SSL Context Downgrade in Apache Storm Prometheus Reporter   Versions Affected: from 2.6.3 to 2.8.6   Description:   In production deployments where an administrator enables storm.daemon.metrics.reporter.plugin.prometheus.skip_tls_validation (by default it is disabled) intending to affect only the Prometheus reporter, the undocumented global side effect c…</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40557">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-23776 – Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Featu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23776</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23776</guid>
    <pubDate>Fri, 17 Apr 2026 10:16:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-23776</strong></p>
  <p>Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60, contain(s) an Improper Certificate Validation vulnerability in certificate-based login. A low privileged attacker with remote access could potentially exploit this vulnerabili…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23776">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-20184 – A vulnerability in the integration of single sign-on (SSO) with Control Hub in C...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20184</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20184</guid>
    <pubDate>Wed, 15 Apr 2026 17:17:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-20184</strong></p>
  <p>A vulnerability in the integration of single sign-on (SSO) with Control Hub in Cisco Webex Services could have allowed an unauthenticated, remote attacker to impersonate any user within the service.  This vulnerability existed because of improper certificate validation. Prior to this vulnerability being addressed, an attacker could have exploited this vulnerability by connecting to a service en…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20184">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32144 – Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32144</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32144</guid>
    <pubDate>Tue, 07 Apr 2026 13:16:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32144</strong></p>
  <p>Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_ocsp module) allows OCSP designated-responder authorization bypass via missing signature verification.  The OCSP response validation in public_key:pkix_ocsp_validate/5 does not verify that a CA-designated responder certificate was cryptographically signed by the issuing CA. Instead, it only checks that the responder ce…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32144">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-35560 – Improper certificate validation in the identity provider connection components i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35560</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35560</guid>
    <pubDate>Fri, 03 Apr 2026 21:17:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-35560</strong></p>
  <p>Improper certificate validation in the identity provider connection components in Amazon Athena ODBC driver before 2.1.0.0 might allow a man-in-the-middle threat actor to intercept authentication credentials due to insufficient default transport security when connecting to identity providers. This only applies to connections with external identity providers and does not apply to connections with…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35560">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-32794 – Improper Certificate Validation vulnerability in Apache Airflow Provider for Dat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32794</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32794</guid>
    <pubDate>Mon, 30 Mar 2026 22:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-32794</strong></p>
  <p>Improper Certificate Validation vulnerability in Apache Airflow Provider for Databricks. Provider code did not validate certificates for connections to Databricks back-end which could result in a man-of-a-middle attack that traffic is intercepted and manipulated or credentials exfiltrated w/o notice.  This issue affects Apache Airflow Provider for Databricks: from 1.10.0 before 1.12.0.  Users are…</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32794">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-4587 – A vulnerability was found in HybridAuth up to 3.12.2. This issue affects some un...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4587</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4587</guid>
    <pubDate>Mon, 23 Mar 2026 13:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-4587</strong></p>
  <p>A vulnerability was found in HybridAuth up to 3.12.2. This issue affects some unknown processing of the file src/HttpClient/Curl.php of the component SSL Handler. The manipulation of the argument curlOptions results in improper certificate validation. The attack can be launched remotely. This attack is characterized by high complexity. The exploitability is assessed as difficult. The project was…</p>
  <p><strong>CVSS:</strong> 3.7 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4587">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-4434 – Improper certificate validation in the PAM propagation WinRM connections
 allows...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4434</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4434</guid>
    <pubDate>Fri, 20 Mar 2026 13:16:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-4434</strong></p>
  <p>Improper certificate validation in the PAM propagation WinRM connections  allows a network attacker to perform a man-in-the-middle attack via  disabled TLS certificate verification.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4434">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-4396 – Improper certificate validation in Devolutions Hub Reporting Service 
2025.3.1.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4396</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4396</guid>
    <pubDate>Wed, 18 Mar 2026 20:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-4396</strong></p>
  <p>Improper certificate validation in Devolutions Hub Reporting Service  2025.3.1.1 and earlier allows a network attacker to perform a  man-in-the-middle attack via disabled TLS certificate verification.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4396">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-2368 – An improper certificate validation vulnerability was reported in the Lenovo File...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2368</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2368</guid>
    <pubDate>Wed, 11 Mar 2026 21:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-2368</strong></p>
  <p>An improper certificate validation vulnerability was reported in the Lenovo Filez application that could allow a user capable of intercepting network traffic to execute arbitrary code.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2368">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-1068 – An improper certificate validation vulnerability was reported in the Lenovo File...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1068</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1068</guid>
    <pubDate>Wed, 11 Mar 2026 21:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-1068</strong></p>
  <p>An improper certificate validation vulnerability was reported in the Lenovo Filez application that could allow a user capable of intercepting network traffic to obtain sensitive user data from the application.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1068">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-24508 – Dell Alienware Command Center (AWCC), versions prior to 6.12.24.0, contain an Im...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24508</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24508</guid>
    <pubDate>Wed, 11 Mar 2026 20:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-24508</strong></p>
  <p>Dell Alienware Command Center (AWCC), versions prior to 6.12.24.0, contain an Improper Certificate Validation vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure.</p>
  <p><strong>CVSS:</strong> 2.5 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24508">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-14024 – An improper certificate validation vulnerability has been reported to affect Vid...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-14024</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-14024</guid>
    <pubDate>Wed, 11 Mar 2026 08:16:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-14024</strong></p>
  <p>An improper certificate validation vulnerability has been reported to affect Video Station. If an attacker gains local network access who have also gained an administrator account, they can then exploit the vulnerability to compromise the security of the system.  We have already fixed the vulnerability in the following version: Video Station 5.8.2 and later</p>
  <p><strong>CVSS:</strong> 6.7 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-14024">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-27221 – Acrobat Reader versions 24.001.30307, 24.001.30308, 25.001.21265 and earlier are...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27221</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27221</guid>
    <pubDate>Tue, 10 Mar 2026 22:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-27221</strong></p>
  <p>Acrobat Reader versions 24.001.30307, 24.001.30308, 25.001.21265 and earlier are affected by an Improper Certificate Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to spoof the identity of a signer. Exploitation of this issue requires user interaction.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27221">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-68482 – A improper certificate validation vulnerability in Fortinet FortiAnalyzer 7.6.0 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-68482</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-68482</guid>
    <pubDate>Tue, 10 Mar 2026 18:17:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-68482</strong></p>
  <p>A improper certificate validation vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.8, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer 6.4 all versions, FortiManager 7.6.0 through 7.6.4, FortiManager 7.4.0 through 7.4.8, FortiManager 7.2 all versions, FortiManager 7.0 all versions, FortiManager 6.4 all versions may allow a r…</p>
  <p><strong>CVSS:</strong> 6.9 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68482">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-3822 – Taipower APP for Andorid developed by Taipower has an Improper Certificate Valid...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3822</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3822</guid>
    <pubDate>Mon, 09 Mar 2026 04:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-3822</strong></p>
  <p>Taipower APP for Andorid developed by Taipower has an Improper Certificate Validation vulnerability. When establishing an HTTPS connection with the server, the application fails to verify the server-side TLS/SSL certificate. This flaw allows an unauthenticated remote attackers to exploit the vulnerability to perform a Man-in-the-Middle (MITM) attack to read and tamper with network packets.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3822">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-30794 – Improper Certificate Validation vulnerability in rustdesk-client RustDesk Client...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30794</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30794</guid>
    <pubDate>Thu, 05 Mar 2026 16:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-30794</strong></p>
  <p>Improper Certificate Validation vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (HTTP API client, TLS transport modules) allows Adversary in the Middle (AiTM). This vulnerability is associated with program files src/hbbs_http/http_client.Rs and program routines TLS retry with danger_accept_invalid_certs(true).  This issue affects RustDesk Cl…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30794">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-3336 – Improper certificate validation in PKCS7_verify() in AWS-LC allows an unauthenti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3336</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3336</guid>
    <pubDate>Mon, 02 Mar 2026 22:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-3336</strong></p>
  <p>Improper certificate validation in PKCS7_verify() in AWS-LC allows an unauthenticated user to bypass certificate chain verification when processing PKCS7 objects with multiple signers, except the final signer.  Customers of AWS services do not need to take action. Applications using AWS-LC should upgrade to AWS-LC version 1.69.0.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3336">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-70058 – An issue pertaining to CWE-295: Improper Certificate Validation was discovered i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-70058</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-70058</guid>
    <pubDate>Mon, 23 Feb 2026 16:29:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-70058</strong></p>
  <p>An issue pertaining to CWE-295: Improper Certificate Validation was discovered in YMFE yapi v1.12.0. The application disables TLS/SSL certificate validation by setting 'rejectUnauthorized': false in the HTTPS agent configuration for Axios requests</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-70058">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-70045 – An issue pertaining to CWE-295: Improper Certificate Validation was discovered i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-70045</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-70045</guid>
    <pubDate>Mon, 23 Feb 2026 16:29:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-70045</strong></p>
  <p>An issue pertaining to CWE-295: Improper Certificate Validation was discovered in jxcore jxm master. The application disables TLS/SSL certificate validation by setting 'rejectUnauthorized': false in HTTPS request options when 'jx_obj.IsSecure' is true</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-70045">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-70044 – An issue pertaining to CWE-295: Improper Certificate Validation was discovered i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-70044</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-70044</guid>
    <pubDate>Mon, 23 Feb 2026 16:29:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-70044</strong></p>
  <p>An issue pertaining to CWE-295: Improper Certificate Validation was discovered in fofolee uTools-quickcommand 5.0.3.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-70044">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-70043 – An issue pertaining to CWE-295: Improper Certificate Validation was discovered i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-70043</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-70043</guid>
    <pubDate>Mon, 23 Feb 2026 16:29:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-70043</strong></p>
  <p>An issue pertaining to CWE-295: Improper Certificate Validation was discovered in Ayms node-To master. The application disables TLS/SSL certificate validation by setting 'rejectUnauthorized': false in TLS socket options</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-70043">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-0872 – Improper Certificate Validation vulnerability in Thales SafeNet Agent for Window...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0872</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0872</guid>
    <pubDate>Fri, 13 Feb 2026 09:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-0872</strong></p>
  <p>Improper Certificate Validation vulnerability in Thales SafeNet Agent for Windows Logon on Windows allows Signature Spoofing by Improper Validation.This issue affects SafeNet Agent for Windows Logon: 4.0.0, 4.1.1, 4.1.2.</p>
  <p><strong>CVSS:</strong> 2.5 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0872">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-0228 – An improper certificate validation vulnerability in PAN-OS allows users to conne...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0228</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0228</guid>
    <pubDate>Wed, 11 Feb 2026 18:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-0228</strong></p>
  <p>An improper certificate validation vulnerability in PAN-OS allows users to connect Terminal Server Agents on Windows to PAN-OS using expired certificates even if the PAN-OS configuration would not normally permit them to do so.</p>
  <p><strong>CVSS:</strong> 1.3 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0228">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-21228 – Improper certificate validation in Azure Local allows an unauthorized attacker t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21228</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-21228</guid>
    <pubDate>Tue, 10 Feb 2026 18:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-21228</strong></p>
  <p>Improper certificate validation in Azure Local allows an unauthorized attacker to execute code over a network.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21228">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-15323 – Tanium addressed an improper certificate validation vulnerability in Tanium Appl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-15323</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-15323</guid>
    <pubDate>Thu, 05 Feb 2026 19:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-15323</strong></p>
  <p>Tanium addressed an improper certificate validation vulnerability in Tanium Appliance.</p>
  <p><strong>CVSS:</strong> 3.7 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-15323">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-15557 – An Improper Certificate Validation vulnerability in TP-Link Tapo H100 v1 and Tap...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-15557</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-15557</guid>
    <pubDate>Thu, 05 Feb 2026 18:16:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-15557</strong></p>
  <p>An Improper Certificate Validation vulnerability in TP-Link Tapo H100 v1 and Tapo P100 v1 allows an on-path attacker on the same network segment to intercept and modify encrypted device-cloud communications.  This may compromise the confidentiality and integrity of device-to-cloud communication, enabling manipulation of device data or operations.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-15557">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-67229 – An improper certificate validation vulnerability exists in ToDesktop Builder v0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-67229</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-67229</guid>
    <pubDate>Fri, 23 Jan 2026 17:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-67229</strong></p>
  <p>An improper certificate validation vulnerability exists in ToDesktop Builder v0.32.1 This vulnerability allows an unauthenticated, on-path attacker to spoof backend responses by exploiting insufficient certificate validation.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-67229">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-11043 – An Improper Certificate Validation vulnerability in the OPC-UA client and ANSL o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-11043</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-11043</guid>
    <pubDate>Mon, 19 Jan 2026 16:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-11043</strong></p>
  <p>An Improper Certificate Validation vulnerability in the OPC-UA client and ANSL over TLS client used in Automation Studio versions before 6.5 could allow an unauthenticated attacker on the network to position themselves to intercept and interfere with data exchanges.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-11043">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-22079 – This vulnerability exists in Tenda wireless routers (300Mbps Wireless Router F3 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22079</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22079</guid>
    <pubDate>Fri, 09 Jan 2026 11:15:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-22079</strong></p>
  <p>This vulnerability exists in Tenda wireless routers (300Mbps Wireless Router F3 and N300 Easy Setup Router) due to the plaintext transmission of login credentials during the initial login or post-factory reset setup through the web-based administrative interface. An attacker on the same network could exploit this vulnerability by intercepting network traffic and capturing the credentials transmit…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-319</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22079">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-54981 – Weak Encryption Algorithm in StreamPark, The use of an AES cipher in ECB mode an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54981</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54981</guid>
    <pubDate>Fri, 12 Dec 2025 15:15:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-54981</strong></p>
  <p>Weak Encryption Algorithm in StreamPark, The use of an AES cipher in ECB mode and a weak random number generator for encrypting sensitive data, including JWT tokens, may have risked exposing sensitive authentication data  This issue affects Apache StreamPark: from 2.0.0 before 2.1.7.  Users are recommended to upgrade to version 2.1.7, which fixes the issue.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-327</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54981">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-60022 – Improper certificate validation vulnerability exists in 'デジラアプリ' App for iOS pri...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-60022</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-60022</guid>
    <pubDate>Mon, 17 Nov 2025 06:15:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-60022</strong></p>
  <p>Improper certificate validation vulnerability exists in 'デジラアプリ' App for iOS prior to ver.80.10.00. If this vulnerability is exploited, a man-in-the-middle attack may allow an attacker to eavesdrop on and/or tamper with an encrypted communication.</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-60022">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-30669 – Improper certificate validation in certain Zoom Clients may allow an unauthentic...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-30669</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-30669</guid>
    <pubDate>Thu, 13 Nov 2025 15:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-30669</strong></p>
  <p>Improper certificate validation in certain Zoom Clients may allow an unauthenticated user to conduct a disclosure of information via adjacent access.</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-30669">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-12943 – Improper certificate
validation in firmware update logic in NETGEAR RAX30 (Night...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-12943</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-12943</guid>
    <pubDate>Tue, 11 Nov 2025 17:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-12943</strong></p>
  <p>Improper certificate validation in firmware update logic in NETGEAR RAX30 (Nighthawk AX5 5-Stream AX2400 WiFi 6 Router) and RAXE300 (Nighthawk AXE7800 Tri-Band WiFi 6E Router) allows attackers with the ability to intercept and tamper traffic destined to the device to execute arbitrary commands on the device.  Devices with automatic updates enabled may already have this patch applied. If not, plea…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-12943">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-11619 – Improper certificate validation when connecting to gateways in Devolutions Serve...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-11619</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-11619</guid>
    <pubDate>Wed, 15 Oct 2025 20:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-11619</strong></p>
  <p>Improper certificate validation when connecting to gateways in Devolutions Server 2025.3.2 and earlier allows attackers in MitM position to intercept traffic.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-11619">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-6026 – An improper certificate validation vulnerability was reported in the Lenovo Univ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-6026</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-6026</guid>
    <pubDate>Wed, 15 Oct 2025 15:16:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-6026</strong></p>
  <p>An improper certificate validation vulnerability was reported in the Lenovo Universal Device Client (UDC) that could allow a user capable of intercepting network traffic to obtain application metadata, including device information, geolocation, and telemetry data.</p>
  <p><strong>CVSS:</strong> 3.1 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-6026">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-11633 – A vulnerability was identified in Tomofun Furbo 360 and Furbo Mini. Affected by ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-11633</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-11633</guid>
    <pubDate>Sun, 12 Oct 2025 12:15:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-11633</strong></p>
  <p>A vulnerability was identified in Tomofun Furbo 360 and Furbo Mini. Affected by this issue is the function upload_file_to_s3 of the file collect_logs.sh of the component HTTP Traffic Handler. The manipulation leads to improper certificate validation. The attack may be initiated remotely. The attack is considered to have high complexity. The exploitation is known to be difficult. The firmware vers…</p>
  <p><strong>CVSS:</strong> 3.7 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-11633">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-57176 – On Ceragon Networks / Siklu Communication EtherHaul and MultiHaul Series microwa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-57176</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-57176</guid>
    <pubDate>Mon, 15 Sep 2025 17:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-57176</strong></p>
  <p>On Ceragon Networks / Siklu Communication EtherHaul and MultiHaul Series microwave antennas before 2026-03-10, the rfpiped service on TCP port 555 allows unauthenticated file uploads to any writable location on the device. File upload packets use weak encryption (metadata only) with file contents transmitted in cleartext. No authentication or path validation is performed.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-57176">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-33099 – IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to perfor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-33099</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-33099</guid>
    <pubDate>Mon, 01 Sep 2025 15:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-33099</strong></p>
  <p>IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to perform unauthorized actions using man in the middle techniques due to improper certificate validation.</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-33099">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-30278 – An improper certificate validation vulnerability has been reported to affect Qsy...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-30278</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-30278</guid>
    <pubDate>Fri, 29 Aug 2025 18:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-30278</strong></p>
  <p>An improper certificate validation vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to compromise the security of the system.  We have already fixed the vulnerability in the following version: Qsync Central 4.5.0.7 ( 2025/04/23 ) and later</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-30278">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-30277 – An improper certificate validation vulnerability has been reported to affect Qsy...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-30277</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-30277</guid>
    <pubDate>Fri, 29 Aug 2025 18:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-30277</strong></p>
  <p>An improper certificate validation vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to compromise the security of the system.  We have already fixed the vulnerability in the following version: Qsync Central 4.5.0.7 ( 2025/04/23 ) and later</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-30277">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-58127 – Improper Certificate Validation in Checkmk Exchange plugin Dell Powerscale allow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-58127</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-58127</guid>
    <pubDate>Thu, 28 Aug 2025 13:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-58127</strong></p>
  <p>Improper Certificate Validation in Checkmk Exchange plugin Dell Powerscale allows attackers in MitM position to intercept traffic.</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58127">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-58126 – Improper Certificate Validation in Checkmk Exchange plugin VMware vSAN allows at...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-58126</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-58126</guid>
    <pubDate>Thu, 28 Aug 2025 13:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-58126</strong></p>
  <p>Improper Certificate Validation in Checkmk Exchange plugin VMware vSAN allows attackers in MitM position to intercept traffic.</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58126">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-58125 – Improper Certificate Validation in Checkmk Exchange plugin Freebox v6 agent allo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-58125</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-58125</guid>
    <pubDate>Thu, 28 Aug 2025 13:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-58125</strong></p>
  <p>Improper Certificate Validation in Checkmk Exchange plugin Freebox v6 agent allows attackers in MitM position to intercept traffic.</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58125">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-58124 – Improper Certificate Validation in Checkmk Exchange plugin check-mk-api allows a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-58124</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-58124</guid>
    <pubDate>Thu, 28 Aug 2025 13:16:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-58124</strong></p>
  <p>Improper Certificate Validation in Checkmk Exchange plugin check-mk-api allows attackers in MitM position to intercept traffic.</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58124">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-58123 – Improper Certificate Validation in Checkmk Exchange plugin BGP Monitoring allows...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-58123</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-58123</guid>
    <pubDate>Thu, 28 Aug 2025 13:16:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-58123</strong></p>
  <p>Improper Certificate Validation in Checkmk Exchange plugin BGP Monitoring allows attackers in MitM position to intercept traffic.</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58123">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-8393 – A TLS vulnerability exists in the phone application used to manage a 
connected ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-8393</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-8393</guid>
    <pubDate>Fri, 08 Aug 2025 17:15:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-8393</strong></p>
  <p>A TLS vulnerability exists in the phone application used to manage a  connected device. The phone application accepts self-signed certificates  when establishing TLS communication which may result in  man-in-the-middle attacks on untrusted networks. Captured communications  may include user credentials and sensitive session tokens.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-8393">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-45765 – ruby-jwt v3.0.0.beta1 was discovered to contain weak encryption. NOTE: the Suppl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-45765</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-45765</guid>
    <pubDate>Thu, 07 Aug 2025 21:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-45765</strong></p>
  <p>ruby-jwt v3.0.0.beta1 was discovered to contain weak encryption. NOTE: the Supplier's perspective is "keysize is not something that is enforced by this library. Currently more recent versions of OpenSSL are enforcing some key sizes and those restrictions apply to the users of this gem also."</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-326</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-45765">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-45766 – poco v1.14.1-release was discovered to contain weak encryption. NOTE: this issue...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-45766</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-45766</guid>
    <pubDate>Wed, 06 Aug 2025 20:15:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-45766</strong></p>
  <p>poco v1.14.1-release was discovered to contain weak encryption. NOTE: this issue has been disputed on the basis that key lengths are expected to be set by an application, not by this library. This dispute is subject to review under CNA rules 4.1.4, 4.1.14, and other rules; the dispute tagging is not meant to recommend an outcome for this CVE Record.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-327</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-45766">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-45764 – jsrsasign v11.1.0 was discovered to contain weak encryption. NOTE: this issue ha...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-45764</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-45764</guid>
    <pubDate>Wed, 06 Aug 2025 20:15:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-45764</strong></p>
  <p>jsrsasign v11.1.0 was discovered to contain weak encryption. NOTE: this issue has been disputed by a third party who believes that CVE IDs can be assigned for key lengths in specific applications that use a library, and should not be assigned to the default key lengths in a library. This dispute is subject to review under CNA rules 4.1.4, 4.1.14, and other rules; the dispute tagging is not meant…</p>
  <p><strong>CVSS:</strong> 3.2 · <strong>CWE:</strong> CWE-326</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-45764">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-8476 – Alpine iLX-507 TIDAL Improper Certificate Validation Vulnerability. This vulnera...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-8476</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-8476</guid>
    <pubDate>Fri, 01 Aug 2025 18:15:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-8476</strong></p>
  <p>Alpine iLX-507 TIDAL Improper Certificate Validation Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Alpine iLX-507 devices. Authentication is not required to exploit this vulnerability.  The specific flaw exists within the TIDAL music streaming application. The issue results from improper certificate validation. An attack…</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-8476">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-45767 – jose v6.0.10 was discovered to contain weak encryption. NOTE: this is disputed b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-45767</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-45767</guid>
    <pubDate>Fri, 01 Aug 2025 15:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-45767</strong></p>
  <p>jose v6.0.10 was discovered to contain weak encryption. NOTE: this is disputed by a third party because the claim of "do not meet recommended security standards" does not reflect guidance in a final publication.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-327</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-45767">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-45768 – pyjwt v2.10.1 was discovered to contain weak encryption. NOTE: this is disputed ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-45768</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-45768</guid>
    <pubDate>Thu, 31 Jul 2025 21:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-45768</strong></p>
  <p>pyjwt v2.10.1 was discovered to contain weak encryption. NOTE: this is disputed by the Supplier because the key length is chosen by the application that uses the library (admittedly, library users may benefit from a minimum value and a mechanism for opting in to strict enforcement).</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-311</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-45768">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-45770 – jwt v5.4.3 was discovered to contain weak encryption. NOTE: this issue has been ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-45770</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-45770</guid>
    <pubDate>Thu, 31 Jul 2025 20:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-45770</strong></p>
  <p>jwt v5.4.3 was discovered to contain weak encryption. NOTE: this issue has been disputed on the basis that key lengths are expected to be set by an application, not by this library. This dispute is subject to review under CNA rules 4.1.4, 4.1.14, and other rules; the dispute tagging is not meant to recommend an outcome for this CVE Record.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-326</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-45770">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-45769 – php-jwt v6.11.0 was discovered to contain weak encryption. NOTE: this issue has ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-45769</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-45769</guid>
    <pubDate>Thu, 31 Jul 2025 20:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-45769</strong></p>
  <p>php-jwt v6.11.0 was discovered to contain weak encryption. NOTE: this issue has been disputed on the basis that key lengths are expected to be set by an application, not by this library. This dispute is subject to review under CNA rules 4.1.4, 4.1.14, and other rules; the dispute tagging is not meant to recommend an outcome for this CVE Record.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-326</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-45769">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-36005 – IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 thr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-36005</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-36005</guid>
    <pubDate>Thu, 24 Jul 2025 15:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-36005</strong></p>
  <p>IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4.1, 3.5.0, 3.5.1, 3.6.0, and MQ Operator SC2 3.2.0 through 3.2.13 Internet Pass-Thru could allow a malicious user to obtain sensitive information from another TLS session connection by the proxy to the same hostname and port due to improper certificate validation.</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-36005">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-46788 – Improper certificate validation in Zoom Workplace for Linux before version 6.4.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-46788</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-46788</guid>
    <pubDate>Thu, 10 Jul 2025 16:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-46788</strong></p>
  <p>Improper certificate validation in Zoom Workplace for Linux before version 6.4.13 may allow an unauthorized user to conduct an information disclosure via network access.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-46788">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-35983 – Improper Certificate Validation (CWE-295) in the Controller 7000 OneLink impleme...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-35983</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-35983</guid>
    <pubDate>Thu, 10 Jul 2025 03:15:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-35983</strong></p>
  <p>Improper Certificate Validation (CWE-295) in the Controller 7000 OneLink implementation could allow an unprivileged attacker to perform a limited denial of service or perform privileged overrides during the initial configuration of the Controller, there is no risk for Controllers once they are connected.   This issue affects Controller 7000:   9.30 prior to vCR9.30.250624a (distributed in 9.30.18…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-35983">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-48802 – Improper certificate validation in Windows SMB allows an authorized attacker to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-48802</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-48802</guid>
    <pubDate>Tue, 08 Jul 2025 17:15:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-48802</strong></p>
  <p>Improper certificate validation in Windows SMB allows an authorized attacker to perform spoofing over a network.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48802">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-7095 – A vulnerability classified as critical has been found in Comodo Internet Securit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-7095</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-7095</guid>
    <pubDate>Sun, 06 Jul 2025 22:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-7095</strong></p>
  <p>A vulnerability classified as critical has been found in Comodo Internet Security Premium 12.3.4.8162. This affects an unknown part of the component Update Handler. The manipulation leads to improper certificate validation. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The vendor was contacted early about th…</p>
  <p><strong>CVSS:</strong> 3.7 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-7095">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-34066 – An improper certificate validation vulnerability exists in AVTECH IP cameras, DV...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-34066</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-34066</guid>
    <pubDate>Tue, 01 Jul 2025 15:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-34066</strong></p>
  <p>An improper certificate validation vulnerability exists in AVTECH IP cameras, DVRs, and NVRs due to the use of wget with --no-check-certificate in scripts like SyncCloudAccount.sh and SyncPermit.sh. This exposes HTTPS communications to man-in-the-middle (MITM) attacks.</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-34066">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-24471 – An Improper Certificate Validation vulnerability [CWE-295] in FortiOS version 7...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-24471</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-24471</guid>
    <pubDate>Tue, 10 Jun 2025 17:21:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-24471</strong></p>
  <p>An Improper Certificate Validation vulnerability [CWE-295] in FortiOS version 7.6.1 and below, version 7.4.7 and below may allow an EAP verified remote user to connect from FortiClient via revoked certificate.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24471">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-33031 – An improper certificate validation vulnerability has been reported to affect Fil...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-33031</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-33031</guid>
    <pubDate>Fri, 06 Jun 2025 16:15:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-33031</strong></p>
  <p>An improper certificate validation vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to compromise the security of the system.  We have already fixed the vulnerability in the following version: File Station 5 5.5.6.4847 and later</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-33031">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-30279 – An improper certificate validation vulnerability has been reported to affect Fil...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-30279</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-30279</guid>
    <pubDate>Fri, 06 Jun 2025 16:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-30279</strong></p>
  <p>An improper certificate validation vulnerability has been reported to affect File Station 5. If a remote  attacker gains a user account, they can then exploit the vulnerability to compromise the security of the system.  We have already fixed the vulnerability in the following version: File Station 5 5.5.6.4847 and later</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-30279">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-29885 – An improper certificate validation vulnerability has been reported to affect Fil...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-29885</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-29885</guid>
    <pubDate>Fri, 06 Jun 2025 16:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-29885</strong></p>
  <p>An improper certificate validation vulnerability has been reported to affect File Station 5. If exploited, the vulnerability could allow remote attackers who have gained user access to compromise the security of the system.  We have already fixed the vulnerability in the following versions: File Station 5 5.5.6.4791 and later   and later</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-29885">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-29884 – An improper certificate validation vulnerability has been reported to affect Fil...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-29884</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-29884</guid>
    <pubDate>Fri, 06 Jun 2025 16:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-29884</strong></p>
  <p>An improper certificate validation vulnerability has been reported to affect File Station 5. If exploited, the vulnerability could allow remote attackers who have gained user access to compromise the security of the system.  We have already fixed the vulnerability in the following versions: File Station 5 5.5.6.4791 and later   and later</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-29884">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-29883 – An improper certificate validation vulnerability has been reported to affect Fil...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-29883</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-29883</guid>
    <pubDate>Fri, 06 Jun 2025 16:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-29883</strong></p>
  <p>An improper certificate validation vulnerability has been reported to affect File Station 5. If exploited, the vulnerability could allow remote attackers who have gained user access to compromise the security of the system.  We have already fixed the vulnerability in the following versions: File Station 5 5.5.6.4791 and later   and later</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-29883">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-22486 – An improper certificate validation vulnerability has been reported to affect Fil...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-22486</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-22486</guid>
    <pubDate>Fri, 06 Jun 2025 16:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-22486</strong></p>
  <p>An improper certificate validation vulnerability has been reported to affect File Station 5. If exploited, the vulnerability could allow remote attackers who have gained user access to compromise the security of the system.  We have already fixed the vulnerability in the following versions: File Station 5 5.5.6.4791 and later   and later</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22486">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-13956 – SSL Verification Bypass vulnerabilities exist in ASPECT if administrator credent...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-13956</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-13956</guid>
    <pubDate>Thu, 22 May 2025 19:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-13956</strong></p>
  <p>SSL Verification Bypass vulnerabilities exist in ASPECT if administrator credentials become compromisedThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.</p>
  <p><strong>CVSS:</strong> 6.7 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13956">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-27524 – Weak encryption vulnerability in Hitachi JP1/IT Desktop Management 2 - Smart Dev...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-27524</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-27524</guid>
    <pubDate>Thu, 15 May 2025 07:15:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-27524</strong></p>
  <p>Weak encryption vulnerability in Hitachi JP1/IT Desktop Management 2 - Smart Device Manager on Windows.This issue affects JP1/IT Desktop Management 2 - Smart Device Manager: from 12-00 before 12-00-08, from 11-10 through 11-10-08, from 11-00 through 11-00-05, from 10-50 through 10-50-06.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-326</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-27524">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-37730 – Improper certificate validation in Logstash's TCP output could lead to a man-in-...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-37730</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-37730</guid>
    <pubDate>Tue, 06 May 2025 18:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-37730</strong></p>
  <p>Improper certificate validation in Logstash's TCP output could lead to a man-in-the-middle (MitM) attack in “client” mode, as hostname verification in TCP output was not being performed when the ssl_verification_mode => full was set.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-37730">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-20670 – In Modem, there is a possible permission bypass due to improper certificate vali...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20670</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20670</guid>
    <pubDate>Mon, 05 May 2025 03:15:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-20670</strong></p>
  <p>In Modem, there is a possible permission bypass due to improper certificate validation. This could lead to remote information disclosure, if a UE has connected to a rogue base station controlled by the attacker, with User execution privileges needed. User interaction is needed for exploitation. Patch ID: MOLY01334347; Issue ID: MSV-2772.</p>
  <p><strong>CVSS:</strong> 5.7 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20670">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-26478 – Dell ECS version 3.8.1.4 and prior contain an Improper Certificate Validation vu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-26478</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-26478</guid>
    <pubDate>Thu, 17 Apr 2025 12:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-26478</strong></p>
  <p>Dell ECS version 3.8.1.4 and prior contain an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Information disclosure.</p>
  <p><strong>CVSS:</strong> 3.1 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-26478">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-22459 – Improper certificate validation in Ivanti Endpoint Manager before version 2024 S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-22459</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-22459</guid>
    <pubDate>Tue, 08 Apr 2025 15:15:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-22459</strong></p>
  <p>Improper certificate validation in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows a remote unauthenticated attacker to intercept limited traffic between clients and servers.</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-296</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22459">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-25635 – An Improper Certificate Validation vulnerability in LibreOffice allowed 
an atta...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-25635</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-25635</guid>
    <pubDate>Fri, 21 Mar 2025 15:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-25635</strong></p>
  <p>An Improper Certificate Validation vulnerability in LibreOffice allowed  an attacker to self sign an ODF document, with a signature untrusted by  the target, then modify it to change the signature algorithm to an  invalid (or unknown to LibreOffice) algorithm and LibreOffice would incorrectly present such a signature with an unknown algorithm as a  valid signature issued by a trusted person   Thi…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-25635">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-10445 – Improper certificate validation vulnerability in the update functionality in Syn...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-10445</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-10445</guid>
    <pubDate>Wed, 19 Mar 2025 02:15:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-10445</strong></p>
  <p>Improper certificate validation vulnerability in the update functionality in Synology BeeStation OS (BSM) before 1.1-65374 and Synology DiskStation Manager (DSM) before 6.2.4-25556-8, 7.1.1-42962-7, 7.2-64570-4, 7.2.1-69057-6 and 7.2.2-72806-1 allow remote attackers to write limited files via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-10445">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-10444 – Improper certificate validation vulnerability in the LDAP utilities in Synology ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-10444</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-10444</guid>
    <pubDate>Wed, 19 Mar 2025 02:15:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-10444</strong></p>
  <p>Improper certificate validation vulnerability in the LDAP utilities in Synology DiskStation Manager (DSM) before 7.1.1-42962-8, 7.2.1-69057-7 and 7.2.2-72806-3 allows man-in-the-middle attackers to hijack the authentication of administrators via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-10444">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-48785 – An improper certificate validation vulnerability [CWE-295] in FortiNAC-F version...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-48785</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-48785</guid>
    <pubDate>Fri, 14 Mar 2025 16:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-48785</strong></p>
  <p>An improper certificate validation vulnerability [CWE-295] in FortiNAC-F version 7.2.4 and below may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the HTTPS communication channel between the FortiOS device, an inventory, and FortiNAC-F.</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-48785">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-40590 – An improper certificate validation vulnerability [CWE-295] in FortiPortal versio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-40590</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-40590</guid>
    <pubDate>Fri, 14 Mar 2025 15:15:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-40590</strong></p>
  <p>An improper certificate validation vulnerability [CWE-295] in FortiPortal version 7.4.0, version 7.2.4 and below, version 7.0.8 and below, version 6.0.15 and below when connecting to a FortiManager device, a FortiAnalyzer device, or an SMTP server may allow an unauthenticated attacker in a Man-in-the-Middle position to intercept on and tamper with the encrypted communication channel established b…</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-40590">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-43107 – Improper Certificate Validation (CWE-295) in the Gallagher Milestone Integration...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-43107</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-43107</guid>
    <pubDate>Mon, 10 Mar 2025 03:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-43107</strong></p>
  <p>Improper Certificate Validation (CWE-295) in the Gallagher Milestone Integration Plugin (MIP) permits unauthenticated messages (e.g. alarm events) to be sent to the Plugin. This issue effects Gallagher MIPS Plugin v4.0 prior to v4.0.32, all versions of v3.0 and prior.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-43107">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-41724 – Improper Certificate Validation (CWE-295) in the Gallagher Command Centre SALTO ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-41724</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-41724</guid>
    <pubDate>Mon, 10 Mar 2025 03:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-41724</strong></p>
  <p>Improper Certificate Validation (CWE-295) in the Gallagher Command Centre SALTO integration allowed an attacker to spoof the SALTO server.      This issue affects all versions of Gallagher Command Centre prior to 9.20.1043.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-41724">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-50394 – An improper certificate validation vulnerability has been reported to affect Hel...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-50394</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-50394</guid>
    <pubDate>Fri, 07 Mar 2025 17:15:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-50394</strong></p>
  <p>An improper certificate validation vulnerability has been reported to affect Helpdesk. If exploited, the vulnerability could allow remote attackers to compromise the security of the system.  We have already fixed the vulnerability in the following version: Helpdesk 3.3.3 and later</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-50394">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-47092 – Insecure deserialization and improper certificate validation in Checkmk Exchange...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47092</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47092</guid>
    <pubDate>Mon, 03 Mar 2025 14:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-47092</strong></p>
  <p>Insecure deserialization and improper certificate validation in Checkmk Exchange plugin check-mk-api prior to 5.8.1</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47092">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-23118 – An Improper Certificate Validation vulnerability could allow an authenticated ma...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-23118</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-23118</guid>
    <pubDate>Sat, 01 Mar 2025 03:15:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-23118</strong></p>
  <p>An Improper Certificate Validation vulnerability could allow an authenticated malicious actor with access to UniFi Protect Cameras adjacent network to make unsupported changes to the camera system.</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-23118">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-54089 – A vulnerability has been identified in APOGEE PXC Series (BACnet) (All versions)...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-54089</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-54089</guid>
    <pubDate>Tue, 11 Feb 2025 11:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-54089</strong></p>
  <p>A vulnerability has been identified in APOGEE PXC Series (BACnet) (All versions), APOGEE PXC Series (P2 Ethernet) (All versions), TALON TC Series (BACnet) (All versions). Affected devices contain a weak encryption mechanism based on a hard-coded key. This could allow an attacker to guess or decrypt the password from the cyphertext.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-326</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-54089">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-23091 – An Improper Certificate Validation on UniFi OS devices, with Identity Enterprise...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-23091</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-23091</guid>
    <pubDate>Sat, 01 Feb 2025 07:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-23091</strong></p>
  <p>An Improper Certificate Validation on UniFi OS devices, with Identity Enterprise configured, could allow a malicious actor to execute a man-in-the-middle (MitM) attack during application update.</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-23091">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
