CWE-295— Improper Certificate Validation
The product does not validate, or incorrectly validates, a certificate.— MITRE CWE catalog
1,642 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-295page 28 of 33
- CVE-2023-34143MEDIUMCVSS 5.6EG 5.62023-07-18
Improper Validation of Certificate with Host Mismatch vulnerability in Hitachi Device Manager on Windows, Linux (Device Manager Server, Device Manager Agent, Host Data Collector components) allows Man in the Middle Attack.This issue affect…
- CVE-2020-2187MEDIUMCVSS 5.6EG 5.62020-05-06
Jenkins Amazon EC2 Plugin 1.50.1 and earlier unconditionally accepts self-signed certificates and does not perform hostname validation, enabling man-in-the-middle attacks.
- CVE-2018-8479MEDIUMCVSS 5.6EG 5.62018-09-13
A spoofing vulnerability exists for the Azure IoT Device Provisioning for the C SDK library using the HTTP protocol on Windows platform, aka "Azure IoT SDK Spoofing Vulnerability." This affects C SDK.
- CVE-2018-8119MEDIUMCVSS 5.6EG 5.62018-05-09
A spoofing vulnerability exists when the Azure IoT Device Provisioning AMQP Transport library improperly validates certificates over the AMQP protocol, aka "Azure IoT SDK Spoofing Vulnerability." This affects C# SDK, C SDK, Java SDK.
- CVE-2018-1000151MEDIUMCVSS 5.6EG 5.62018-04-05
A man in the middle vulnerability exists in Jenkins vSphere Plugin 2.16 and older in VSphere.java that disables SSL/TLS certificate validation by default.
- CVE-2016-7171MEDIUMCVSS 5.6EG 5.62016-12-05
NetApp Plug-in for Symantec NetBackup prior to version 2.0.1 makes use of a non-unique server certificate, making it vulnerable to impersonation.
- CVE-2026-79975MEDIUMCVSS 5.5EG 5.52026-09-07
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. A low privileged attacker with local access could potentially exploit…
- CVE-2026-20500MEDIUMCVSS 5.5EG 5.52026-09-07
In Modem, there is a possible system crash due to improper input validation. This could lead to local denial of service with User execution privileges needed. User interaction is needed for exploitation. Patch ID: MOLY01810811; Issue ID: M…
- CVE-2026-18678MEDIUMCVSS 5.5EG 5.52026-08-12
When an operator adds an HTTPS control plane profile to kumactl without providing a CA certificate, kumactl disables TLS verification and sends API tokens over the unverified connection. An attacker on the network path between the opera…
- CVE-2026-48437MEDIUMCVSS 5.5EG 5.52026-08-11
CAI Content Credentials is affected by an Improper Certificate Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write a…
- CVE-2026-50166MEDIUMCVSS 5.5EG 5.52026-07-16
Kuma is a modern Envoy-based service mesh that can run on every cloud across both Kubernetes and VMs. Prior to 2.7.26, 2.9.16, 2.11.14, 2.12.11, and 2.13.7, a kumactl profile manually configured for an HTTPS control plane without --ca-cert…
- CVE-2026-39984MEDIUMCVSS 5.5EG 5.52026-04-15
Sigstore Timestamp Authority is a service for issuing RFC 3161 timestamps. Versions 2.0.5 and below contain an authorization bypass vulnerability in the VerifyTimestampResponse function. VerifyTimestampResponse correctly verifies the certi…
- CVE-2026-24508MEDIUMCVSS 5.5EG 5.52026-03-11
Dell Alienware Command Center (AWCC), versions prior to 6.12.24.0, contain an Improper Certificate Validation vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information e…
- CVE-2026-27221MEDIUMCVSS 5.5EG 5.52026-03-10
Acrobat Reader versions 24.001.30307, 24.001.30308, 25.001.21265 and earlier are affected by an Improper Certificate Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to …
- CVE-2026-22250MEDIUMCVSS 5.5EG 5.52026-01-12
wlc is a Weblate command-line client using Weblate's REST API. Prior to 1.17.0, the SSL verification would be skipped for some crafted URLs. This vulnerability is fixed in 1.17.0.
- CVE-2021-25635MEDIUMCVSS 5.5EG 5.52025-03-21
An Improper Certificate Validation vulnerability in LibreOffice allowed an attacker to self sign an ODF document, with a signature untrusted by the target, then modify it to change the signature algorithm to an invalid (or unknown to Li…
- CVE-2024-53846MEDIUMCVSS 5.5EG 5.52024-12-05
OTP is a set of Erlang libraries, which consists of the Erlang runtime system, a number of ready-to-use components mainly written in Erlang, and a set of design principles for Erlang programs. A regression was introduced into the ssl appli…
- CVE-2024-47241MEDIUMCVSS 5.5EG 5.52024-10-18
Dell Secure Connect Gateway (SCG) 5.0 Appliance - SRS, version(s) 5.24, contains an Improper Certificate Validation vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to unauth…
- CVE-2023-2422MEDIUMCVSS 5.5EG 5.52023-10-04
A flaw was found in Keycloak. A Keycloak server configured to support mTLS authentication for OAuth/OpenID clients does not properly verify the client certificate chain. A client that possesses a proper certificate can authorize itself as …
- CVE-2023-1055MEDIUMCVSS 5.5EG 5.52023-02-27
A flaw was found in RHDS 11 and RHDS 12. While browsing entries LDAP tries to decode the userPassword attribute instead of the userCertificate attribute which could lead into sensitive information leaked. An attacker with a local account w…
- CVE-2021-3798MEDIUMCVSS 5.5EG 5.52022-08-23
A flaw was found in openCryptoki. The openCryptoki Soft token does not check if an EC key is valid when an EC key is created via C_CreateObject, nor when C_DeriveKey is used with ECDH public data. This may allow a malicious user to extract…
- CVE-2022-26766MEDIUMCVSS 5.5EG 5.52022-05-26
A certificate parsing issue was addressed with improved checks. This issue is fixed in tvOS 15.5, iOS 15.5 and iPadOS 15.5, Security Update 2022-004 Catalina, watchOS 8.6, macOS Big Sur 11.6.6, macOS Monterey 12.4. A malicious app may be a…
- CVE-2022-22946MEDIUMCVSS 5.5EG 5.52022-03-04
In spring cloud gateway versions prior to 3.1.1+ , applications that are configured to enable HTTP2 and no key store or trusted certificates are set will be configured to use an insecure TrustManager. This makes the gateway able to connect…
- CVE-2021-26320MEDIUMCVSS 5.5EG 5.52021-11-16
Insufficient validation of the AMD SEV Signing Key (ASK) in the SEND_START command in the SEV Firmware may allow a local authenticated attacker to perform a denial of service of the PSP
- CVE-2021-20435MEDIUMCVSS 5.5EG 5.52021-09-23
IBM Security Verify Bridge 1.0.5.0 does not properly validate a certificate which could allow a local attacker to obtain sensitive information that could aid in further attacks against the system. IBM X-Force ID: 196355.
- CVE-2012-1096MEDIUMCVSS 5.5EG 5.52020-03-10
NetworkManager 0.9 and earlier allows local users to use other users' certificates or private keys when making a connection via the file path when adding a new connection.
- CVE-2019-14334MEDIUMCVSS 5.5EG 5.52019-08-01
An issue was discovered on D-Link 6600-AP, DWL-3600AP, and DWL-8610AP Ax 4.2.0.14 21/03/2019 devices. There is post-authenticated Certificate and RSA Private Key extraction through an insecure sslcert-get.cgi HTTP command.
- CVE-2018-8356MEDIUMCVSS 5.5EG 5.52018-07-11
A security feature bypass vulnerability exists when Microsoft .NET Framework components do not correctly validate certificates, aka ".NET Framework Security Feature Bypass Vulnerability." This affects .NET Framework 4.7.2, Microsoft .NET F…
- CVE-2017-8445MEDIUMCVSS 5.5EG 5.52017-08-18
An error was found in the X-Pack Security TLS trust manager for versions 5.0.0 to 5.5.1. If reloading the trust material fails the trust manager will be replaced with an instance that trusts all certificates. This could allow any node usin…
- CVE-2026-87571MEDIUMCVSS 5.4EG 5.42026-09-09
Improper certificate validation in Loader in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass web origin policy via crafted network traffic. (Chromium security severity: Low)
- CVE-2026-35207MEDIUMCVSS 5.4EG 5.42026-04-09
dde-control-center is the control panel of DDE, the Deepin Desktop Environment. plugin-deepinid is a plugin in dde-control-center, which provides the deepinid cloud service. Prior to 6.1.80, plugin-deepinid is configured to skip TLS certif…
- CVE-2025-20215MEDIUMCVSS 5.4EG 5.42025-08-06
A vulnerability in the meeting-join functionality of Cisco Webex Meetings could have allowed an unauthenticated, network-proximate attacker to complete a meeting-join process in place of an intended targeted user, provided the requisite co…
- CVE-2025-3218MEDIUMCVSS 5.4EG 5.42025-05-07
IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 is vulnerable to authentication and authorization attacks due to incorrect validation processing in IBM i Netserver. A malicious actor could use the weaknesses, in conjunction with brute force authenticat…
- CVE-2024-9160MEDIUMCVSS 5.4EG 5.42024-09-27
In versions of the PEADM Forge Module prior to 3.24.0 a security misconfiguration was discovered.
- CVE-2022-22305MEDIUMCVSS 5.4EG 5.42023-09-01
An improper certificate validation vulnerability [CWE-295] in FortiManager 7.0.1 and below, 6.4.6 and below; FortiAnalyzer 7.0.2 and below, 6.4.7 and below; FortiOS 6.2.x and 6.0.x; FortiSandbox 4.0.x, 3.2.x and 3.1.x may allow a network …
- CVE-2023-29000MEDIUMCVSS 5.4EG 5.42023-04-04
The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server. Starting with version 3.0.0 and prior to version 3.7.0, by trusting that the server will return a certificate that belongs to the keypair of the user, a mal…
- CVE-2022-1197MEDIUMCVSS 5.4EG 5.42022-12-22
When importing a revoked key that specified key compromise as the revocation reason, Thunderbird did not update the existing copy of the key that was not yet revoked, and the existing key was kept as non-revoked. Revocation statements that…
- CVE-2020-35509MEDIUMCVSS 5.4EG 5.42022-08-23
A flaw was found in keycloak affecting versions 11.0.3 and 12.0.0. An expired certificate would be accepted by the direct-grant authenticator because of missing time stamp validations. The highest threat from this vulnerability is to data …
- CVE-2022-22306MEDIUMCVSS 5.4EG 5.42022-05-24
An improper certificate validation vulnerability [CWE-295] in FortiOS 6.0.0 through 6.0.14, 6.2.0 through 6.2.10, 6.4.0 through 6.4.8, 7.0.0 may allow a network adjacent and unauthenticated attacker to man-in-the-middle the communication b…
- CVE-2021-32755MEDIUMCVSS 5.4EG 5.42021-07-13
Wire is a collaboration platform. wire-ios-transport handles authentication of requests, network failures, and retries for the iOS implementation of Wire. In the 3.82 version of the iOS application, a new web socket implementation was intr…
- CVE-2020-25680MEDIUMCVSS 5.4EG 5.42021-01-07
A flaw was found in JBCS httpd in version 2.4.37 SP3, where it uses a back-end worker SSL certificate with the keystore file's ID is 'unknown'. The validation of the certificate whether CN and hostname are matching stopped working and allo…
- CVE-2020-5909MEDIUMCVSS 5.4EG 5.42020-07-02
In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, when users run the command displayed in NGINX Controller user interface (UI) to fetch the agent installer, the server TLS certificate is not verified.
- CVE-2018-11751MEDIUMCVSS 5.4EG 5.42019-12-16
Previous versions of Puppet Agent didn't verify the peer in the SSL connection prior to downloading the CRL. This issue is resolved in Puppet Agent 6.4.0.
- CVE-2017-7513MEDIUMCVSS 5.4EG 5.42018-08-22
It was found that Satellite 5 configured with SSL/TLS for the PostgreSQL backend failed to correctly validate X.509 server certificate host name fields. A man-in-the-middle attacker could use this flaw to spoof a PostgreSQL server using a …
- CVE-2018-10894MEDIUMCVSS 5.4EG 5.42018-08-01
It was found that SAML authentication in Keycloak 3.4.3.Final incorrectly authenticated expired certificates. A malicious user could use this to access unauthorized data or possibly conduct further attacks.
- CVE-2017-6143MEDIUMCVSS 5.4EG 5.42018-04-13
X509 certificate verification was not correctly implemented in the IP Intelligence Subscription and IP Intelligence feed-list features, and thus the remote server's identity is not properly validated in F5 BIG-IP 12.0.0-12.1.2, 11.6.0-11.6…
- CVE-2026-102671MEDIUMCVSS 5.3EG 5.32026-10-01
The Joyland AI app accepts invalid SSL certificates in the invisible advertisement WebView by default.
- CVE-2026-102668MEDIUMCVSS 5.3EG 5.32026-10-01
The Joyland AI app accepts any TLS certificates from any server without validation.
- CVE-2026-89133MEDIUMCVSS 5.3EG 5.32026-09-27
wolfSSL versions 5.9.2 and earlier contain a flaw in the X.509 certificate validation logic where it fails to properly enforce NameConstraints extensions when there is an unconstrained CA tier between a name-constrained intermediate CA and…
- CVE-2026-90452MEDIUMCVSS 5.3EG 5.32026-09-11
Requests from the reverse proxy to the identity-provider service for token discovery, introspection, and credential exchange do not verify the identity provider's server certificate. An attacker positioned on the network path between the p…
Map vulnerabilities like CWE-295 to your infrastructure
EchelonGraph correlates every CVE — across CWE-295 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →