CWE-295— Improper Certificate Validation
The product does not validate, or incorrectly validates, a certificate.— MITRE CWE catalog
1,642 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-295page 1 of 33
- CVE-2022-20703CRITICALCVSS 10.0EG 10.0⚠ KEV2022-02-10
Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication a…
- CVE-2026-85102CRITICALCVSS 9.8EG 9.8⚠ KEV2026-09-09
Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.
- CVE-2022-26923CRITICALCVSS 8.8EG 9.0⚠ KEV2022-05-10
Active Directory Domain Services Elevation of Privilege Vulnerability
- CVE-2020-0601CRITICALCVSS 8.1EG 9.0⚠ KEV2020-01-14
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates.An attacker could exploit the vulnerability by using a spoofed code-signing certificate to sign a malicious…
- CVE-2023-20963CRITICALCVSS 7.8EG 9.0⚠ KEV2023-03-24
In WorkSource, there is a possible parcel mismatch. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Andro…
- CVE-2023-41991CRITICALCVSS 5.5EG 9.0⚠ KEV2023-09-21
A certificate validation issue was addressed. This issue is fixed in macOS Ventura 13.6, iOS 16.7 and iPadOS 16.7. A malicious app may be able to bypass signature validation. Apple is aware of a report that this issue may have been activel…
- CVE-2026-96207CRITICALCVSS 10.0EG 10.02026-10-08
Improper certificate validation in Microsoft Partner Center allows an unauthorized attacker to elevate privileges over a network.
- CVE-2026-58162CRITICALCVSS 10.0EG 10.02026-07-29
The Apache Traffic Server certifier plugin generates certificates based on attacker-controlled client SNI. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Us…
- CVE-2026-4370CRITICALCVSS 10.0EG 10.02026-04-01
A vulnerability was identified in Juju from version 3.2.0 until 3.6.19 and from version 4.0 until 4.0.4, where the internal Dqlite database cluster fails to perform proper TLS client and server authentication. Specifically, the Juju contro…
- CVE-2026-30836CRITICALCVSS 10.0EG 10.02026-03-19
Step CA is an online certificate authority for secure, automated certificate management for DevOps. Versions 0.30.0-rc6 and below do not safeguard against unauthenticated certificate issuance through the SCEP UpdateReq. This issue has been…
- CVE-2025-68121CRITICALCVSS 10.0EG 10.02026-02-05
During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between the initial handshake and the resumed handshake, the resumed handshake may succeed when it should have failed. This may h…
- CVE-2026-78234CRITICALCVSS 9.9EG 9.92026-09-08
A flaw was found in hawtio-operator. The operator reads the OpenShift Service CA private signing key from the openshift-service-ca namespace and uses it to mint client certificates with a Subject Common Name (CN) supplied by the author of …
- CVE-2026-66795CRITICALCVSS 9.9EG 9.92026-08-17
A flaw was found in the managedcluster-import-controller. The Certificate Signing Request (CSR) auto-approval logic improperly validates incoming CSRs, specifically by not inspecting the signer name or decoding the PEM-encoded x509 CSR. Th…
- CVE-2021-1471CRITICALCVSS 9.9EG 9.92021-03-24
Multiple vulnerabilities in Cisco Jabber for Windows, Cisco Jabber for MacOS, and Cisco Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system with elevated privileges, access s…
- CVE-2026-86131CRITICALCVSS 9.8EG 9.82026-09-29
A code injection vulnerability in WatchGuard Fireware OS's BOVPN Over TLS client configuration handling allows an attacker who controls the remote VPN server to execute arbitrary commands as root on the connecting Firebox.
- CVE-2026-65118CRITICALCVSS 9.8EG 9.82026-09-22
NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause improper certificate validation. A successful exploit of this vulnerability might lead to information disclosure, data tampering, and denial …
- CVE-2026-65084CRITICALCVSS 9.8EG 9.82026-08-25
NVIDIA NemoClaw for Linux contains a vulnerability in its deployment process, where an attacker could cause improper certificate validation. A successful exploit of this vulnerability might lead to information disclosure, data tampering, c…
- CVE-2026-17024CRITICALCVSS 9.8EG 9.82026-08-20
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to improper certificate validation.
- CVE-2026-66402CRITICALCVSS 9.8EG 9.82026-08-01
FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains multiple TLS certificate identity validation weaknesses in tls_verify_certificate(), tls_match_hostname(), and x509_utils_get_dns_names(). Because FreeRDP performs custom Common …
- CVE-2026-59836CRITICALCVSS 9.8EG 9.82026-07-14
A improper certificate validation vulnerability in Fortinet FortiClientEMS 7.4.3 through 7.4.5, FortiClientEMS 7.4.0 through 7.4.1, FortiClientEMS 7.2 all versions may allow attacker to information disclosure via <insert attack vector here>
- CVE-2026-9258CRITICALCVSS 9.8EG 9.82026-06-16
Improper validation of SSH host keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier
- CVE-2026-9259CRITICALCVSS 9.8EG 9.82026-06-16
Improper validation of server certificates in Canon EOS Network Setting Tool Version 1.5.0 or earlier
- CVE-2026-32253CRITICALCVSS 9.8EG 9.82026-05-22
Sunshine is a self-hosted game stream host for Moonlight. In versions prior to 2026.516.143833, the client-certificate authentication can be bypassed because of how OpenSSL verification results are handled. In src/crypto.cpp, the custom ve…
- CVE-2026-40974CRITICALCVSS 9.8EG 9.82026-04-28
Spring Boot's Cassandra auto-configuration does not perform hostname verification when establishing an SSL connection to Cassandra. Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14), 3.4.0–3.4.15 (fix 3.4.16),…
- CVE-2026-20184CRITICALCVSS 9.8EG 9.82026-04-15
A vulnerability in the integration of single sign-on (SSO) with Control Hub in Cisco Webex Services could have allowed an unauthenticated, remote attacker to impersonate any user within the service. This vulnerability existed because of…
- CVE-2026-2590CRITICALCVSS 9.8EG 9.82026-03-03
Improper enforcement of the Disable password saving in vaults setting in the connection entry component in Devolutions Remote Desktop Manager 2025.3.30 and earlier allows an authenticated user to persist credentials in vault entries, po…
- CVE-2025-67229CRITICALCVSS 9.8EG 9.82026-01-23
An improper certificate validation vulnerability exists in ToDesktop Builder v0.32.1 This vulnerability allows an unauthenticated, on-path attacker to spoof backend responses by exploiting insufficient certificate validation.
- CVE-2025-46070CRITICALCVSS 9.8EG 9.82026-01-12
An issue in Automai BotManager v.25.2.0 allows a remote attacker to execute arbitrary code via the BotManager.exe component
- CVE-2025-29331CRITICALCVSS 9.8EG 9.82025-06-26
An issue in MHSanaei 3x-ui before v.2.5.3 and before allows a remote attacker to execute arbitrary code via the management script x-ui passes the no check certificate option to wget when downloading updates
- CVE-2025-6433CRITICALCVSS 9.8EG 9.82025-06-24
If a user visited a webpage with an invalid TLS certificate, and granted an exception, the webpage was able to provide a WebAuthn challenge that the user would be prompted to complete. This is in violation of the WebAuthN spec which requi…
- CVE-2025-32878CRITICALCVSS 9.8EG 9.82025-06-20
An issue was discovered on COROS PACE 3 devices through 3.0808.0. It implements a function to connect the watch to a WLAN. This function is mainly for downloading firmware files. Before downloading firmware files, the watch requests some i…
- CVE-2024-56521CRITICALCVSS 9.8EG 9.82024-12-27
An issue was discovered in TCPDF before 6.8.0. If libcurl is used, CURLOPT_SSL_VERIFYHOST and CURLOPT_SSL_VERIFYPEER are set unsafely.
- CVE-2024-49369CRITICALCVSS 9.8EG 9.82024-11-12
Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. The TLS certificate validation in all Icinga 2 versions starting from 2.4.0 was flaw…
- CVE-2019-20461CRITICALCVSS 9.8EG 9.82024-11-07
An issue was discovered on Alecto IVM-100 2019-11-12 devices. The device uses a custom UDP protocol to start and control video and audio services. The protocol has been partially reverse engineered. Based upon the reverse engineering, no p…
- CVE-2024-45159CRITICALCVSS 9.8EG 9.82024-09-05
An issue was discovered in Mbed TLS 3.x before 3.6.1. With TLS 1.3, when a server enables optional authentication of the client, if the client-provided certificate does not have appropriate values in if keyUsage or extKeyUsage extensions, …
- CVE-2024-42395CRITICALCVSS 9.8EG 9.82024-08-06
There is a vulnerability in the AP Certificate Management Service which could allow a threat actor to execute an unauthenticated RCE attack. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying op…
- CVE-2024-20080CRITICALCVSS 9.8EG 9.82024-07-01
In gnss service, there is a possible escalation of privilege due to improper certificate validation. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for explo…
- CVE-2024-5261CRITICALCVSS 9.8EG 9.82024-06-25
Improper Certificate Validation vulnerability in LibreOffice "LibreOfficeKit" mode disables TLS certification verification LibreOfficeKit can be used for accessing LibreOffice functionality through C/C++. Typically this is used by third …
- CVE-2024-25140CRITICALCVSS 9.8EG 9.82024-02-06
A default installation of RustDesk 1.2.3 on Windows places a WDKTestCert certificate under Trusted Root Certification Authorities with Enhanced Key Usage of Code Signing (1.3.6.1.5.5.7.3.3), valid from 2023 until 2033. This is potentially …
- CVE-2023-51837CRITICALCVSS 9.8EG 9.82024-01-30
Ylianst MeshCentral 1.1.16 is vulnerable to Missing SSL Certificate Validation.
- CVE-2023-48427CRITICALCVSS 9.8EG 9.82023-12-12
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). Affected products do not properly validate the certificate of the configured UMC server. This could allow an attacker to intercept credentials that are se…
- CVE-2023-42425CRITICALCVSS 9.8EG 9.82023-10-31
An issue in Turing Video Turing Edge+ EVC5FD v.1.38.6 allows remote attacker to execute arbitrary code and obtain sensitive information via the cloud connection components.
- CVE-2023-5554CRITICALCVSS 9.8EG 9.82023-10-12
Lack of TLS certificate verification in log transmission of a financial module within LINE client for iOS prior to 13.16.0.
- CVE-2023-40256CRITICALCVSS 9.8EG 9.82023-08-11
A vulnerability was discovered in Veritas NetBackup Snapshot Manager before 10.2.0.1 that allowed untrusted clients to interact with the RabbitMQ service. This was caused by improper validation of the client certificate due to misconfigura…
- CVE-2023-27823CRITICALCVSS 9.8EG 9.82023-05-12
An authentication bypass in Optoma 1080PSTX C02 allows an attacker to access the administration console without valid credentials.
- CVE-2022-35898CRITICALCVSS 9.8EG 9.82023-05-01
OpenText BizManager before 16.6.0.1 does not perform proper validation during the change-password operation. This allows any authenticated user to change the password of any other user, including the Administrator account.
- CVE-2022-47758CRITICALCVSS 9.8EG 9.82023-04-27
Nanoleaf firmware v7.1.1 and below is missing TLS verification, allowing attackers to execute arbitrary code via a DNS hijacking attack.
- CVE-2023-26463CRITICALCVSS 9.8EG 9.82023-04-15
strongSwan 5.9.8 and 5.9.9 potentially allows remote code execution because it uses a variable named "public" for two different purposes within the same function. There is initially incorrect access control, later followed by an expired po…
- CVE-2021-46880CRITICALCVSS 9.8EG 9.82023-04-15
x509/x509_verify.c in LibreSSL before 3.4.2, and OpenBSD before 7.0 errata 006, allows authentication bypass because an error for an unverified certificate chain is sometimes discarded.
- CVE-2022-45597CRITICALCVSS 9.8EG 9.82023-03-24
ComponentSpace.Saml2 4.4.0 Missing SSL Certificate Validation. NOTE: the vendor does not consider this a vulnerability because the report is only about use of certificates at the application layer (not the transport layer) and "Certificate…
Map vulnerabilities like CWE-295 to your infrastructure
EchelonGraph correlates every CVE — across CWE-295 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →