CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1 (more results available)

CVE-2026-93304 MEDIUM

(D)TLS 1.2 client accepts early ChangeCipherSpec before ClientKeyExchange

CVSS 6.3 EPSS 0.19% Sep 27, 2026
CVE-2026-93302 HIGH

Trusted peer certificate match ignores public key, allowing forged CA clones

CVSS 8.3 EPSS 0.29% Sep 27, 2026
CVE-2026-89135 MEDIUM

Failed X509_verify_cert leaves unverified CA in shared CertManager

CVSS 6.3 EPSS 0.21% Sep 27, 2026
CVE-2026-89134 MEDIUM

Subject CN name-constraint check bypassed when non-DNS SAN present

CVSS 6.3 EPSS 0.14% Sep 27, 2026
CVE-2026-89133 MEDIUM

NameConstraints not enforced across unconstrained intermediate CA

CVSS 6.3 EPSS 0.15% Sep 27, 2026
CVE-2026-15442 LOW

Heap use-after-free on read during bidirectional (D)TLS shutdown

CVSS 2.3 EPSS 0.28% Sep 27, 2026
CVE-2026-89102 HIGH

OCSP stapling v2 multi accepts non-CA chain certificates as issuers

CVSS 8.3 EPSS 0.18% Sep 27, 2026
CVE-2026-94419 LOW

Client session cache reference poisoning allows resumption with wrong server

CVSS 2.3 EPSS 0.10% Sep 27, 2026
CVE-2026-94418 LOW

Signature failure masked by date error under WOLFSSL_SMALL_CERT_VERIFY

CVSS 2.3 EPSS 0.05% Sep 27, 2026
CVE-2026-89136 HIGH

Client accepts unsolicited RawPublicKey server certificate type

CVSS 8.3 EPSS 0.55% Sep 27, 2026
CVE-2026-94417 LOW

CRL check skipped when OCSP enabled and certificate has no OCSP URL

CVSS 2.3 EPSS 0.15% Sep 27, 2026
CVE-2026-81341 MEDIUM

wolfEngine reuses the AES-CCM nonce on TLS 1.2 / DTLS 1.2 records

CVSS 6.5 EPSS 0.32% Aug 28, 2026
CVE-2026-81020 HIGH

wolfEngine reuses the AES-GCM nonce on every TLS 1.2 / DTLS 1.2 record

CVSS 7.4 EPSS 0.38% Aug 28, 2026
CVE-2026-81019 HIGH

wolfProvider reuses the AES-GCM nonce on every TLS 1.2 / DTLS 1.2 record

CVSS 7.4 EPSS 0.38% Aug 28, 2026
CVE-2026-7511 MEDIUM

PKCS7_verify signer confusion allows forged signatures to be accepted

CVSS 5.9 EPSS 0.26% Jun 25, 2026
CVE-2026-7532 MEDIUM

iPAddress name constraints not enforced when WOLFSSL_IP_ALT_NAME is undefined

CVSS 5.7 EPSS 0.29% Jun 25, 2026
CVE-2026-8720 MEDIUM

HMAC-BLAKE2 final discards message when key length exceeds block size

CVSS 5.9 EPSS 0.16% Jun 25, 2026
CVE-2026-10098 MEDIUM

OCSP CertID serial-number length-confusion in wolfSSL_OCSP_resp_find_status

CVSS 6.3 EPSS 0.19% Jun 25, 2026
CVE-2026-11703 MEDIUM

Missing SNI/ALPN binding on stateful (session-ID) TLS session resumption

CVSS 6.0 EPSS 0.36% Jun 25, 2026
CVE-2026-55962 MEDIUM

TLS 1.3 post-handshake authentication: server accepts Finished without client Certificate/CertificateVerify

CVSS 6.0 EPSS 0.24% Jun 25, 2026
CVE-2026-6092 LOW

Encrypt-then-MAC could fall back to MAC-then-Encrypt when HAVE_ENCRYPT_THEN_MAC is configured

CVSS 2.1 EPSS 0.38% Jun 25, 2026
CVE-2026-6325 LOW

Out-of-bounds write in SetSuitesHashSigAlgo on oversized signature algorithms list

CVSS 2.0 EPSS 0.29% Jun 25, 2026
CVE-2026-6329 MEDIUM

PKCS#12 MAC verification uses attacker-controlled comparison length

CVSS 6.0 EPSS 0.21% Jun 25, 2026
CVE-2026-6330 MEDIUM

ML-KEM ARM64 NEON ciphertext comparison only compares half of the input

CVSS 6.3 EPSS 0.17% Jun 25, 2026
CVE-2026-6331 LOW

HMAC zero-length tag forgery in EVP_DigestVerifyFinal

CVSS 2.1 EPSS 0.19% Jun 25, 2026

Showing 1 to 25 CVEs · page 1 (more available)