Skip to main content

CWE archive

CWE-296 CVEs

Programmatic archive

17 CVEs tagged with CWE-2962 Critical, 10 High, 5 Medium, 0 Low, 0 Unrated.

CVE-2026-24066

Published Jun 10, 2026

Slate Digital Connect 1.37.0 for macOS installs a privileged helper tool, com.slatedigital.connect.privileged.helper.tool, which exposes the XPC service com.slatedigital.connect.p…

CVSS 8.4 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-42789

Published May 27, 2026

Improper Following of a Certificate's Chain of Trust vulnerability in Erlang OTP public_key (pubkey_cert module) allows a non-CA certificate to be accepted as an intermediate issu…

CVSS 7.0 · High
evidence mentions
11
Buzz score
44.9
Vendor/product tagsBeta · best-effort

CVE-2026-44852

Published May 12, 2026

An authenticated remote code execution vulnerability exists in the AOS-8 and AOS-10 web-based management interface. A vulnerability in the certificate download functionality could…

CVSS 7.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-10539

Published Apr 28, 2026

Due to improper TLS certificate validation in the DeskTime Time Tracking App before version 1.3.674, attackers who can position themselves in the network path between the client a…

CVSS 4.8 · Medium
evidence mentions
5
Buzz score
34.4
Vendor/product tagsBeta · best-effort

CVE-2026-33779

Published Apr 9, 2026

An Improper Following of a Certificate's Chain of Trust vulnerability in J-Web of Juniper Networks Junos OS on SRX Series allows a PITM to intercept the communication of the devic…

CVSS 8.3 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-27133

Published Feb 20, 2026

Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. From 0.47.0 to before 0.50.1, when a chain consisting of mul…

CVSS 5.9 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2025-48057

Published May 27, 2025

Icinga 2 is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. Prior to versions 2.12…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-22459

Published Apr 8, 2025

Improper certificate validation in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows a remote unauthenticated attacker to intercept limited traffic…

CVSS 4.8 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-1146

Published Feb 12, 2025

CrowdStrike uses industry-standard TLS (transport layer security) to secure communications from the Falcon sensor to the CrowdStrike cloud. CrowdStrike has identified a validation…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2021-44532

Published Feb 24, 2022

Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 converts SANs (Subject Alternative Names) to a string format. It uses this string to check peer certificates against hostname…

CVSS 5.3 · Medium
Showing 1-17 of 17 CVEsPage 1 of 1