CWE-295

Improper Certificate Validation

Parent: CWE-287 - Improper Authentication

The product does not validate, or incorrectly validates, a certificate.

1,280 vulnerabilities with CWE-295
CVE-2026-3822 MEDIUM
Taipower APP - Improper Certificate Validation
CVSS 6.5
CVE-2026-24281
Apache ZooKeeper <3.8.6/3.9.5 - Auth Bypass
CVE-2026-30840 HIGH
Wallos <4.6.2 - SSRF
CVSS 8.8
CVE-2026-30794
RustDesk Client <1.4.5 - Auth Bypass
CVE-2025-40896 MEDIUM
Arc Agent - MITM Attack
CVSS 6.5
CVE-2026-2748 MEDIUM
SEPPmail Secure Email Gateway <15.0.1 - Auth Bypass
CVSS 5.3
CVE-2026-3336 HIGH
AWS-LC <1.69.0 - Auth Bypass
CVSS 7.5
CVE-2025-67601 HIGH
Rancher Manager - Auth Bypass
CVSS 8.3
CVE-2026-3100 MEDIUM
ADM 4.1.0-4.3.3.ROF1 & 5.0 - MitM
CVSS 6.5
CVE-2025-67752 HIGH
OpenEMR <7.0.4 - MITM
CVSS 8.1
CVE-2025-70058 HIGH
YMFE yapi 1.12.0 - Improper Certificate Validation
CVSS 7.4
CVE-2025-70045 HIGH
jxcore jxm master - Improper Certificate Validation
CVSS 7.4
CVE-2025-70044 MEDIUM
uTools-quickcommand 5.0.3 - Improper Cert Validation
CVSS 6.5
CVE-2025-70043 CRITICAL
Ayms node-To master - Improper Certificate Validation
CVSS 9.1
CVE-2026-27134 HIGH
Strimzi 0.49.0-0.50.0 - Auth Bypass
CVSS 8.1
CVE-2026-27133 MEDIUM
Strimzi 0.47.0-0.50.1 - Auth Bypass
CVSS 5.9
CVE-2026-24122 LOW
Cosign <=3.0.4 - Auth Bypass
CVSS 3.7
CVE-2025-65753 HIGH
Guardian Gryphon v01.06.0006.22 - Command Injection
CVSS 7.5
CVE-2026-0872
Thales SafeNet Agent <4.1.2 - Signature Spoofing
CVE-2025-9293
Certificate Validation Logic - Info Disclosure
CVE-2025-15573 CRITICAL
SolaX Cloud - Man-in-the-Middle
CVSS 9.4
CVE-2026-0228
PAN-OS - Certificate Validation
CVE-2025-70029 HIGH
SunbirdEd-portal <1.13.4 - Info Disclosure
CVSS 7.5
CVE-2026-21228 HIGH
Azure Local - RCE
CVSS 8.1
CVE-2026-25961 HIGH
SumatraPDF <3.5.2 - RCE
CVSS 7.5
Details
Vulnerabilities 1,280