Browse and filter security vulnerabilities across ecosystems
Browse and filter security vulnerabilities across ecosystems
Claude Desktop: SSH Host Key Verification Bypass Allows Man-in-the-Middle Attack on Remote Sessions
Apache Thrift: TSSLTransportFactory.java hostname verification
Apache Thrift: Java TSSLTransportFactory hostname verification
Apache Log4j Core: verifyHostName attribute silently ignored in TLS configuration, allowing hostname verification bypass
Apache Ranger: Hostname verification bypass in NiFiRegistryClient and NifiClient
Xiaomi Galaxy FDS Android SDK <= 3.0.8 TLS Hostname Verification Disabled Enables MITM
Apache Uniffle: Insecure SSL Configuration in Uniffle HTTP Client
Apache Log4j Core: Missing TLS hostname verification in Socket appender
An Improper Validation of Certificate with Host Mismatch vulnerability [CWE-297] in FortiProxy version 7
Host Header Injection in Akinsoft's QR Menu
Host Header Injection in HotelRunner's B2B
A improper validation of certificate with host mismatch in Fortinet FortiClientWindows version 7
Org.keycloak.protocol.services: keycloak hostname verification
In JetBrains Toolbox App before 2
The mobile application (com
IBM OpenPages improper certificate validation
IBM Storage Defender improper certificate validation
Client connections using default TLS certificates from OpenEdge may bypass TLS host name validation
Kroxylicious: missing upstream kafka tls hostname verification
Allow attackers to intercept or falsify data exchanges between the client and the server
Showing 1 - 20 of 1,000+ results