CWE-295— Improper Certificate Validation
The product does not validate, or incorrectly validates, a certificate.— MITRE CWE catalog
1,642 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-295page 7 of 33
- CVE-2026-45574HIGHCVSS 8.1EG 8.12026-05-15
epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. Prior to 1.2.2, an attacker on the network path between the ePA service and the Konnektor can present any TLS certificate (self-signed, expired, wrong …
- CVE-2026-0244HIGHCVSS 8.1EG 8.12026-05-13
An improper certificate validation vulnerability in the Palo Alto Networks Prisma SD-WAN ION enables man-in-the-middle (MitM) attacker to impersonate the controller.
- CVE-2026-22747HIGHCVSS 8.1EG 8.12026-04-22
Vulnerability in Spring Spring Security. SubjectX500PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which can lead to reading the wrong value for the username. In a carefully crafted certific…
- CVE-2026-5501HIGHCVSS 8.1EG 8.12026-04-10
wolfSSL_X509_verify_cert in the OpenSSL compatibility layer accepts a certificate chain in which the leaf's signature is not checked, if the attacker supplies an untrusted intermediate with Basic Constraints `CA:FALSE` that is legitimately…
- CVE-2025-15612HIGHCVSS 8.1EG 8.12026-03-27
Wazuh provisioning scripts and Dockerfiles contain an insecure transport vulnerability where curl is invoked with the -k/--insecure flag, disabling SSL/TLS certificate validation. Attackers with network access can perform man-in-the-middle…
- CVE-2026-4434HIGHCVSS 8.1EG 8.12026-03-20
Improper certificate validation in the PAM propagation WinRM connections allows a network attacker to perform a man-in-the-middle attack via disabled TLS certificate verification.
- CVE-2026-32627HIGHCVSS 8.1EG 8.12026-03-16
cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.37.2, when a cpp-httplib client is configured with a proxy and set_follow_location(true), any HTTPS redirect it follows will have TLS certificate …
- CVE-2025-67752HIGHCVSS 8.1EG 8.12026-02-25
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 7.0.4, OpenEMR's HTTP client wrapper (`oeHttp`/`oeHttpRequest`) disables SSL/TLS certificate verification by default …
- CVE-2026-27134HIGHCVSS 8.1EG 8.12026-02-21
Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. In versions 0.49.0 through 0.50.0, when using a custom Cluster or Clients CA with a multistage CA chain consisting of m…
- CVE-2025-9293HIGHCVSS 8.1EG 8.12026-02-13
A vulnerability in the certificate validation logic may allow applications to accept untrusted or improperly validated server identities during TLS communication. An attacker in a privileged network position may be able to intercept or mod…
- CVE-2026-21228HIGHCVSS 8.1EG 8.12026-02-10
Improper certificate validation in Azure Local allows an unauthorized attacker to execute code over a network.
- CVE-2026-1531HIGHCVSS 8.1EG 8.12026-02-02
A flaw was found in foreman_kubevirt. When configuring the connection to OpenShift, the system disables SSL verification if a Certificate Authority (CA) certificate is not explicitly set. This insecure default allows a remote attacker, cap…
- CVE-2026-1530HIGHCVSS 8.1EG 8.12026-02-02
A flaw was found in fog-kubevirt. This vulnerability allows a remote attacker to perform a Man-in-the-Middle (MITM) attack due to disabled certificate validation. This enables the attacker to intercept and potentially alter sensitive commu…
- CVE-2025-40801HIGHCVSS 8.1EG 8.12025-12-09
A vulnerability has been identified in COMOS V10.6 (All versions < V10.6.1), COMOS V10.6 (All versions < V10.6.1), JT Bi-Directional Translator for STEP (All versions), NX V2412 (All versions < V2412.8900 with Cloud Entitlement (bundled as…
- CVE-2025-34199HIGHCVSS 8.1EG 8.12025-09-19
Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22.0.1049 and Application versions prior to 20.0.2786 (VA and SaaS deployments) contain insecure defaults and code patterns that disable TLS/SSL certificate ver…
- CVE-2024-31854HIGHCVSS 8.1EG 8.12025-07-08
A vulnerability has been identified in SICAM TOOLBOX II (All versions < V07.11). During establishment of a https connection to the TLS server of a managed device, the affected application doesn't check device's certificate common name agai…
- CVE-2024-31853HIGHCVSS 8.1EG 8.12025-07-08
A vulnerability has been identified in SICAM TOOLBOX II (All versions < V07.11). During establishment of a https connection to the TLS server of a managed device, the affected application doesn't check the extended key usage attribute of t…
- CVE-2025-28169HIGHCVSS 8.1EG 8.12025-04-23
BYD QIN PLUS DM-i Dilink OS v3.0_13.1.7.2204050.1 to v3.0_13.1.7.2312290.1_0 was discovered to cend broadcasts to the manufacturer's cloud server unencrypted, allowing attackers to execute a man-in-the-middle attack.
- CVE-2024-42193HIGHCVSS 8.1EG 8.12025-04-15
HCL BigFix Web Reports' service communicates over HTTPS but exhibits a weakness in its handling of SSL certificate validation. This scenario presents a possibility of man-in-the-middle (MITM) attacks and data exposure as, if exploited, thi…
- CVE-2025-1193HIGHCVSS 8.1EG 8.12025-02-10
Improper host validation in the certificate validation component in Devolutions Remote Desktop Manager on 2024.3.19 and earlier on Windows allows an attacker to intercept and modify encrypted communications via a man-in-the-middle attack …
- CVE-2024-47258HIGHCVSS 8.1EG 8.12025-02-06
2N Access Commander version 2.1 and prior is vulnerable in default settings to Man In The Middle attack due to not verifying certificates of 2N edge devices. 2N has currently released an updated version 3.3 of 2N Access Commander, wi…
- CVE-2024-6001HIGHCVSS 8.1EG 8.12024-12-16
An improper certificate validation vulnerability was reported in LADM that could allow a network attacker with the ability to redirect an update request to a remote server and execute code with elevated privileges.
- CVE-2024-51774HIGHCVSS 8.1EG 8.12024-11-02
qBittorrent before 5.0.1 proceeds with use of https URLs even after certificate validation errors.
- CVE-2024-8007HIGHCVSS 8.1EG 8.12024-08-21
A flaw was found in the openstack-tripleo-common component of the Red Hat OpenStack Platform (RHOSP) director. This vulnerability allows an attacker to deploy potentially compromised container images via disabling TLS certificate verificat…
- CVE-2024-30020HIGHCVSS 8.1EG 8.12024-05-14
Windows Cryptographic Services Remote Code Execution Vulnerability
- CVE-2024-2048HIGHCVSS 8.1EG 8.12024-03-04
Vault and Vault Enterprise (“Vault”) TLS certificate auth method did not correctly validate client certificates when configured with a non-CA certificate as trusted certificate. In this configuration, an attacker may be able to craft a…
- CVE-2023-6680HIGHCVSS 8.1EG 8.12023-12-15
An improper certificate validation issue in Smartcard authentication in GitLab EE affecting all versions from 11.6 prior to 16.4.4, 16.5 prior to 16.5.4, and 16.6 prior to 16.6.2 allows an attacker to authenticate as another user given the…
- CVE-2023-38356HIGHCVSS 8.1EG 8.12023-09-19
MiniTool Power Data Recovery 11.6 contains an insecure installation process that allows attackers to achieve remote code execution through a man in the middle attack.
- CVE-2023-38355HIGHCVSS 8.1EG 8.12023-09-19
MiniTool Movie Maker 7.0 contains an insecure installation process that allows attackers to achieve remote code execution through a man in the middle attack.
- CVE-2023-38354HIGHCVSS 8.1EG 8.12023-09-19
MiniTool Shadow Maker version 4.1 contains an insecure installation process that allows attackers to achieve remote code execution through a man in the middle attack.
- CVE-2023-38352HIGHCVSS 8.1EG 8.12023-09-19
MiniTool Partition Wizard 12.8 contains an insecure update mechanism that allows attackers to achieve remote code execution through a man in the middle attack.
- CVE-2023-38351HIGHCVSS 8.1EG 8.12023-09-19
MiniTool Partition Wizard 12.8 contains an insecure installation mechanism that allows attackers to achieve remote code execution through a man in the middle attack.
- CVE-2023-30729HIGHCVSS 8.1EG 8.12023-09-06
Improper Certificate Validation in Samsung Email prior to version 6.1.82.0 allows remote attacker to intercept the network traffic including sensitive information.
- CVE-2023-3615HIGHCVSS 8.1EG 8.12023-07-17
Mattermost iOS app fails to properly validate the server certificate while initializing the TLS connection allowing a network attacker to intercept the WebSockets connection.
- CVE-2023-31190HIGHCVSS 8.1EG 8.12023-07-11
DroneScout ds230 Remote ID receiver from BlueMark Innovations is affected by an Improper Authentication vulnerability during the firmware update procedure. Specifically, the firmware update procedure ignores and does not check the validi…
- CVE-2023-35142HIGHCVSS 8.1EG 8.12023-06-14
Jenkins Checkmarx Plugin 2022.4.3 and earlier disables SSL/TLS validation for connections to the Checkmarx server by default.
- CVE-2023-20881HIGHCVSS 8.1EG 8.12023-05-19
Cloud foundry instances having CAPI version between 1.140 and 1.152.0 along with loggregator-agent v7+ may override other users syslog drain credentials if they're aware of the client certificate used for that syslog drain. This applies ev…
- CVE-2023-31486HIGHCVSS 8.1EG 8.12023-04-29
HTTP::Tiny before 0.083, a Perl core module since 5.13.9 and available standalone on CPAN, has an insecure default TLS configuration where users must opt in to verify certificates.
- CVE-2023-31484HIGHCVSS 8.1EG 8.12023-04-29
CPAN.pm before 2.35 does not verify TLS certificates when downloading distributions over HTTPS.
- CVE-2020-36659HIGHCVSS 8.1EG 8.12023-01-27
In Apache::Session::Browseable before 1.3.6, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backends, because the default configuration of the Net::LDAPS module for Perl is used. NOTE: this can, …
- CVE-2020-36658HIGHCVSS 8.1EG 8.12023-01-27
In Apache::Session::LDAP before 0.5, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backends, because the default configuration of the Net::LDAPS module for Perl is used. NOTE: this can, for exam…
- CVE-2022-34469HIGHCVSS 8.1EG 8.12022-12-22
When a TLS Certificate error occurs on a domain protected by the HSTS header, the browser should not allow the user to bypass the certificate error. On Firefox for Android, the user was presented with the option to bypass the error; this c…
- CVE-2022-46153HIGHCVSS 8.1EG 8.12022-12-08
Traefik is an open source HTTP reverse proxy and load balancer. In affected versions there is a potential vulnerability in Traefik managing TLS connections. A router configured with a not well-formatted TLSOption is exposed with an empty T…
- CVE-2022-33684HIGHCVSS 8.1EG 8.12022-11-04
The Apache Pulsar C++ Client does not verify peer TLS certificates when making HTTPS calls for the OAuth2.0 Client Credential Flow, even when tlsAllowInsecureConnection is disabled via configuration. This vulnerability allows an attacker t…
- CVE-2022-41244HIGHCVSS 8.1EG 8.12022-09-21
Jenkins View26 Test-Reporting Plugin 1.0.7 and earlier does not perform hostname validation when connecting to the configured View26 server that could be abused using a man-in-the-middle attack to intercept these connections.
- CVE-2022-41243HIGHCVSS 8.1EG 8.12022-09-21
Jenkins SmallTest Plugin 1.0.4 and earlier does not perform hostname validation when connecting to the configured View26 server that could be abused using a man-in-the-middle attack to intercept these connections.
- CVE-2022-36173HIGHCVSS 8.1EG 8.12022-09-12
FreshService macOS Agent < 4.4.0 and FreshServce Linux Agent < 3.4.0 are vulnerable to TLS Man-in-The-Middle via the FreshAgent client and scheduled update service.
- CVE-2021-43766HIGHCVSS 8.1EG 8.12022-08-25
Odyssey passes to server unencrypted bytes from man-in-the-middle When Odyssey is configured to use certificate Common Name for client authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first…
- CVE-2022-1805HIGHCVSS 8.1EG 8.12022-07-28
When connecting to Amazon Workspaces, the SHA256 presented by AWS connection provisioner is not fully verified by Zero Clients. The issue could be exploited by an adversary that places a MITM (Man in the Middle) between a zero client and A…
- CVE-2022-36881HIGHCVSS 8.1EG 8.12022-07-27
Jenkins Git client Plugin 3.11.0 and earlier does not perform SSH host key verification when connecting to Git repositories via SSH, enabling man-in-the-middle attacks.
Map vulnerabilities like CWE-295 to your infrastructure
EchelonGraph correlates every CVE — across CWE-295 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →