CWE-295— Improper Certificate Validation
The product does not validate, or incorrectly validates, a certificate.— MITRE CWE catalog
1,642 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-295page 9 of 33
- CVE-2024-23928HIGHCVSS 6.5EG 8.12025-01-31
This vulnerability allows network-adjacent attackers to compromise the integrity of downloaded information on affected installations of Pioneer DMH-WT7600NEX devices. Authentication is not required to exploit this vulnerability. The speci…
- CVE-2024-41256HIGHCVSS 5.9EG 8.12024-07-31
Default configurations in the ShareProofVerifier function of filestash v0.4 causes the application to skip the TLS certificate verification process when sending out email verification codes, possibly allowing attackers to access sensitive …
- CVE-2026-86185HIGHCVSS 8.0EG 8.02026-09-05
Bilibili Desktop through 1.18.0 disables TLS certificate verification process-wide and executes unsigned remote JavaScript configuration without integrity checks. An attacker in an on-path network position can intercept configuration fetch…
- CVE-2026-70454HIGHCVSS 8.0EG 8.02026-08-13
rsync 3.2.0 through 3.2.3 (openssl mode) and rsync-ssl through 3.4.4 (stunnel mode) contain a TLS certificate validation vulnerability that allows on-path attackers to intercept encrypted sessions by presenting self-signed or otherwise inv…
- CVE-2026-60648HIGHCVSS 8.0EG 8.02026-07-21
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privil…
- CVE-2026-45745HIGHCVSS 8.0EG 8.02026-06-05
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Starting in version 1.7.0, Termix Desktop (Electron) disables TLS certificate validation, allowing a machine-in-the-middle attack…
- CVE-2025-8476HIGHCVSS 8.0EG 8.02025-08-01
Alpine iLX-507 TIDAL Improper Certificate Validation Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Alpine iLX-507 devices. Authentication is not required to explo…
- CVE-2024-22030HIGHCVSS 8.0EG 8.02024-10-16
A vulnerability has been identified within Rancher that can be exploited in narrow circumstances through a man-in-the-middle (MITM) attack. An attacker would need to have control of an expired domain or execute a DNS spoofing/hijacking …
- CVE-2024-1052HIGHCVSS 8.0EG 8.02024-02-05
Boundary and Boundary Enterprise (“Boundary”) is vulnerable to session hijacking through TLS certificate tampering. An attacker with privileges to enumerate active or pending sessions, obtain a private key pertaining to a session, and …
- CVE-2020-15134HIGHCVSS 8.0EG 8.02020-07-31
Faye before version 1.4.0, there is a lack of certification validation in TLS handshakes. Faye uses em-http-request and faye-websocket in the Ruby version of its client. Those libraries both use the `EM::Connection#start_tls` method in Eve…
- CVE-2020-15133HIGHCVSS 8.0EG 8.02020-07-31
In faye-websocket before version 0.11.0, there is a lack of certification validation in TLS handshakes. The `Faye::WebSocket::Client` class uses the `EM::Connection#start_tls` method in EventMachine to implement the TLS handshake whenever …
- CVE-2024-28021HIGHCVSS 7.4EG 8.02024-06-11
A vulnerability exists in the FOXMAN-UN/UNEM server that affects the message queueing mechanism’s certificate validation. If exploited an attacker could spoof a trusted entity causing a loss of confidentiality and integrity.
- CVE-2026-55001HIGHCVSS 7.8EG 7.82026-07-14
Improper certificate validation in Windows Active Directory allows an authorized attacker to elevate privileges locally.
- CVE-2026-46734HIGHCVSS 7.8EG 7.82026-06-25
Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3, contain an Improper Certificate Validation vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Protectio…
- CVE-2026-45175HIGHCVSS 7.8EG 7.82026-06-11
Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within internal agent validation processes. A local attacker could potentially bypass built-in security controls or cryptographic validations. Un…
- CVE-2026-41859HIGHCVSS 7.8EG 7.82026-06-04
A network man-in-the-middle between nats-sync and the BOSH director can steal the director credentials (Basic auth header or UAA client secret) and can tamper with the VM list that is written into the NATS authorization file. Stolen creden…
- CVE-2025-34235HIGHCVSS 7.8EG 7.82025-09-29
Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.1.102 and Application prior to version 25.1.1413 (Windows client deployments) contain a registry key that can be enabled by administrators, causing the client …
- CVE-2024-4762HIGHCVSS 7.8EG 7.82024-12-16
An improper validation vulnerability was reported in the firmware update mechanism of LADM and LDCC that could allow a local attacker to escalate privileges.
- CVE-2024-38642HIGHCVSS 7.8EG 7.82024-09-06
An improper certificate validation vulnerability has been reported to affect QuMagie. If exploited, the vulnerability could allow local network users to compromise the security of the system via unspecified vectors. We have already fixed …
- CVE-2024-6472HIGHCVSS 7.8EG 7.82024-08-05
Certificate Validation user interface in LibreOffice allows potential vulnerability. Signed macros are scripts that have been digitally signed by the developer using a cryptographic signature. When a document with a signed macro is o…
- CVE-2024-0042HIGHCVSS 7.8EG 7.82024-05-07
In TBD of TBD, there is a possible confusion of OEM and DRM certificates due to improperly used crypto. This could lead to local bypass of DRM content protection with no additional execution privileges needed. User interaction is not neede…
- CVE-2023-6043HIGHCVSS 7.8EG 7.82024-01-19
A privilege escalation vulnerability was reported in Lenovo Vantage that could allow a local attacker to bypass integrity checks and execute arbitrary code with elevated privileges.
- CVE-2020-12614HIGHCVSS 7.8EG 7.82023-12-12
An issue was discovered in BeyondTrust Privilege Management for Windows through 5.6. If the publisher criteria is selected, it defines the name of a publisher that must be present in the certificate (and also requires that the certificate …
- CVE-2023-21358HIGHCVSS 7.8EG 7.82023-10-30
In UWB Google, there is a possible way for a malicious app to masquerade as system app com.android.uwb.resources due to improperly used crypto. This could lead to local escalation of privilege with no additional execution privileges needed…
- CVE-2022-41747HIGHCVSS 7.8EG 7.82022-10-10
An improper certification validation vulnerability in Trend Micro Apex One agents could allow a local attacker to load a DLL file with system service privileges on affected installations. Please note: an attacker must first obtain the abil…
- CVE-2022-29908HIGHCVSS 7.8EG 7.82022-09-19
The folioupdate service in Fabasoft Cloud Enterprise Client 22.4.0043 allows Local Privilege Escalation.
- CVE-2022-21836HIGHCVSS 7.8EG 7.82022-01-11
Windows Certificate Spoofing Vulnerability
- CVE-2021-3162HIGHCVSS 7.8EG 7.82021-01-15
Docker Desktop Community before 2.5.0.0 on macOS mishandles certificate checking, leading to local privilege escalation.
- CVE-2020-8289HIGHCVSS 7.8EG 7.82020-12-27
Backblaze for Windows before 7.0.1.433 and Backblaze for macOS before 7.0.1.434 suffer from improper certificate validation in `bztransmit` helper due to hardcoded whitelist of strings in URLs where validation is disabled leading to possib…
- CVE-2018-10408HIGHCVSS 7.8EG 7.82018-06-13
An issue was discovered in VirusTotal. A maliciously crafted Universal/fat binary can evade third-party code signing checks. By not completing full inspection of the Universal/fat binary, the user of the third-party tool will believe that …
- CVE-2018-10406HIGHCVSS 7.8EG 7.82018-06-13
An issue was discovered in Yelp OSXCollector. A maliciously crafted Universal/fat binary can evade third-party code signing checks. By not completing full inspection of the Universal/fat binary, the user of the third-party tool will believ…
- CVE-2018-10405HIGHCVSS 7.8EG 7.82018-06-13
An issue was discovered in Google Santa and molcodesignchecker. A maliciously crafted Universal/fat binary can evade third-party code signing checks. By not completing full inspection of the Universal/fat binary, the user of the third-part…
- CVE-2018-10404HIGHCVSS 7.8EG 7.82018-06-13
An issue was discovered in Objective-See KnockKnock, LuLu, TaskExplorer, WhatsYourSign, and procInfo. A maliciously crafted Universal/fat binary can evade third-party code signing checks. By not completing full inspection of the Universal/…
- CVE-2018-10403HIGHCVSS 7.8EG 7.82018-06-13
An issue was discovered in F-Secure XFENCE and Little Flocker. A maliciously crafted Universal/fat binary can evade third-party code signing checks. By not completing full inspection of the Universal/fat binary, the user of the third-party…
- CVE-2026-86474HIGHCVSS 7.7EG 7.72026-09-16
The lack of TLS certificate validation when downloading firmware updates in VEO and VEO-XS Wi-Fi monitors, in versions prior to 01.48.001, allows an attacker to perform man-in-the-middle attacks on the update channel.
- CVE-2026-79637HIGHCVSS 7.7EG 7.72026-09-09
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially expl…
- CVE-2026-41012HIGHCVSS 7.7EG 7.72026-08-29
Traffic interception vulnerability in BOSH Director vCenter CPI allows attackers positioned between BOSH Director and vCenter to impersonate vCenter REST API and capture administrator credentials via HTTP Basic auth, leading to complete vi…
- CVE-2022-40620HIGHCVSS 7.7EG 7.72026-01-28
FunJSQ, a third-party module integrated on some NETGEAR routers and Orbi WiFi Systems, does not properly validate TLS certificates when downloading update packages through its auto-update mechanism. An attacker (suitably positioned on the …
- CVE-2025-9785HIGHCVSS 7.7EG 7.72025-09-03
PaperCut Print Deploy is an optional component that integrates with PaperCut NG/MF which simplifies printer deployment and management. When the component is deployed to an environment, the customer has an option to configure the system to …
- CVE-2025-54607HIGHCVSS 7.7EG 7.72025-08-06
Authentication management vulnerability in the ArkWeb module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2024-35140HIGHCVSS 7.7EG 7.72024-05-31
IBM Security Verify Access Docker 10.0.0 through 10.0.6 could allow a local user to escalate their privileges due to improper certificate validation. IBM X-Force ID: 292416.
- CVE-2021-23162HIGHCVSS 7.7EG 7.72021-11-18
Improper validation of the cloud certificate chain in Mobile Connect allows man-in-the-middle attack to impersonate the legitimate Command Centre Server. This issue affects: Gallagher Command Centre Mobile Connect for Android 15 versions p…
- CVE-2019-3814HIGHCVSS 7.7EG 7.72019-03-27
It was discovered that Dovecot before versions 2.2.36.1 and 2.3.4.1 incorrectly handled client certificates. A remote attacker in possession of a valid certificate with an empty username field could possibly use this issue to impersonate o…
- CVE-2025-14022HIGHCVSS 6.8EG 7.72025-12-15
LINE client for iOS prior to 15.4 allows man-in-the-middle attacks due to improper SSL/TLS certificate validation in an integrated financial SDK. The SDK interfered with the application's network processing, causing server certificate veri…
- CVE-2026-87425HIGHCVSS 7.6EG 7.62026-10-08
An unauthenticated remote attacker can modify the TLS client trust store in Brocade ASCG versions before 3.5.0. By supplying an unauthorized Certificate Authority (CA) certificate to an unauthenticated management interface, the attacker ca…
- CVE-2026-92543HIGHCVSS 7.6EG 7.62026-10-07
Docker Engine classifies a registry hostname as insecure using an any-match DNS check. loadInsecureRegistries() injects 127.0.0.0/8 and ::1/128 as insecure CIDRs by default. isCIDRMatch resolves all of the hostname's addresses and returns …
- CVE-2026-63697HIGHCVSS 7.6EG 7.62026-10-06
Dell System Update, versions prior to 2.3.0.0, contains an Improper Certificate Validation vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.
- CVE-2026-97687HIGHCVSS 7.6EG 7.62026-09-29
urllib3 is an HTTP client library for Python. From 1.26.0 until 2.8.0, the proxy_ssl_context, proxy_assert_hostname, proxy_assert_fingerprint, ssl_context, cert_reqs, verify_mode, use_forwarding_for_https=True, and CERT_NONE configuration …
- CVE-2026-79639HIGHCVSS 7.6EG 7.62026-09-07
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially expl…
- CVE-2026-78020HIGHCVSS 7.5EG 7.52026-10-09
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading…
Map vulnerabilities like CWE-295 to your infrastructure
EchelonGraph correlates every CVE — across CWE-295 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →