CVEs classified under CWE-299, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (14)
CVE-2026-9636: A security issue exists within CompactLogix® 5380, ControlLogix® 5580, and EN4 communication modules related to CIP Security certificate…
CVE-2025-11955: Incorrect validation of OCSP certificates vulnerability in TheGreenBow VPN, versions 7.5 and 7.6. During the IKEv2 authentication step, the…
CVE-2026-61699 — CVSS 8.1 (high): nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.7.1, revocation is the only in-band mechanism that…
CVE-2025-3085 — CVSS 8.1 (high): A MongoDB server under specific conditions running on Linux with TLS and CRL revocation status checking enabled, fails to check the…
CVE-2026-56821 — CVSS 7.4 (high): Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the…
CVE-2026-4428 — CVSS 7.4 (high): A logic error in CRL distribution point validation in AWS-LC before 1.71.0 causes partitioned CRLs to be incorrectly rejected as out of…
CVE-2026-73581 — CVSS 6.5 (medium): Improper Check for Certificate Revocation vulnerability in Apache Tomcat. Both the OpenSSL and OpenSSL-FFM TLS implementations ignore CRLs…
CVE-2020-16228 — CVSS 6.4 (medium): In Patient Information Center iX (PICiX) Versions C.02 and C.03, PerformanceBridge Focal Point Version A.01, IntelliVue patient monitors…
CVE-2026-93493 — CVSS 5.9 (medium): A flaw was found in Netty's `netty-handler-ssl-ocsp` component. A remote attacker can exploit this vulnerability by providing an Online…
CVE-2026-6899 — CVSS 5.6 (medium): Check for certificate revocation only considers the first matching CRL and ignores other valid CRLs of the same CA in the CycloneCrypto…
CVE-2026-94417 — CVSS 5.3 (medium): When an application enables both OCSP and CRL revocation checking on one WOLFSSL_CTX or certificate manager, wolfSSL skips the CRL check…
CVE-2025-36057 — CVSS 5.2 (medium): IBM Cognos Analytics Mobile (iOS) 1.1.0 through 1.1.22 is vulnerable to authentication bypass by using the Local Authentication Framework…
CVE-2026-93602 — CVSS 4.4 (medium): rustls-webpki versions before 0.103.10 and 0.104.0-alpha.5 contain faulty CRL authority-matching logic that compares only the first…
CVE-2024-56138 — CVSS 4.0 (medium): notion-go is a collection of libraries for supporting sign and verify OCI artifacts. Based on Notary Project specifications. This issue was…