CVE Browser
Search and filter CVEs by severity, ecosystem, EPSS score, and more.
Page 1 (more results available)
(D)TLS 1.2 client accepts early ChangeCipherSpec before ClientKeyExchange
Trusted peer certificate match ignores public key, allowing forged CA clones
Failed X509_verify_cert leaves unverified CA in shared CertManager
Subject CN name-constraint check bypassed when non-DNS SAN present
NameConstraints not enforced across unconstrained intermediate CA
Heap use-after-free on read during bidirectional (D)TLS shutdown
OCSP stapling v2 multi accepts non-CA chain certificates as issuers
Client session cache reference poisoning allows resumption with wrong server
Signature failure masked by date error under WOLFSSL_SMALL_CERT_VERIFY
Client accepts unsolicited RawPublicKey server certificate type
CRL check skipped when OCSP enabled and certificate has no OCSP URL
wolfEngine reuses the AES-CCM nonce on TLS 1.2 / DTLS 1.2 records
wolfEngine reuses the AES-GCM nonce on every TLS 1.2 / DTLS 1.2 record
wolfProvider reuses the AES-GCM nonce on every TLS 1.2 / DTLS 1.2 record
PKCS7_verify signer confusion allows forged signatures to be accepted
iPAddress name constraints not enforced when WOLFSSL_IP_ALT_NAME is undefined
HMAC-BLAKE2 final discards message when key length exceeds block size
OCSP CertID serial-number length-confusion in wolfSSL_OCSP_resp_find_status
Missing SNI/ALPN binding on stateful (session-ID) TLS session resumption
TLS 1.3 post-handshake authentication: server accepts Finished without client Certificate/CertificateVerify
Encrypt-then-MAC could fall back to MAC-then-Encrypt when HAVE_ENCRYPT_THEN_MAC is configured
Out-of-bounds write in SetSuitesHashSigAlgo on oversized signature algorithms list
PKCS#12 MAC verification uses attacker-controlled comparison length
ML-KEM ARM64 NEON ciphertext comparison only compares half of the input
HMAC zero-length tag forgery in EVP_DigestVerifyFinal
Showing 1 to 25 CVEs · page 1 (more available)