The product does not validate, or incorrectly validates, a certificate.
1,453 vulnerabilities with CWE-295
CVE-2026-8497
HIGH
Devolutions Password Manager < 2026.2.2 - Improper Certificate Validation
CVSS 7.4
CVE-2026-18257
MEDIUM
Improper Certificate Validation in S2OPC
CVSS 5.6
CVE-2026-58162
CRITICAL
Apache Traffic Server: Certifier plugin trusts client SNI when generating certificates
CVSS 10.0
CVE-2026-65325
MEDIUM
Apache Traffic Server: HTTP/2 multiplexed origin sessions are reused without certificate re-verification
CVSS 4.8
CVE-2026-16107
MEDIUM
IBM TS4500 CLI Tool 0.1.31-1.12.0.0 - Improper TLS Certificate Validation
CVSS 5.9
CVE-2026-54342
HIGH
TLS Certificate Verification Disabled on CXF Transport Clients in epa4all
CVSS 8.1
CVE-2026-48021
CRITICAL
epa4all Security Incident: Implement keystore based on Telematik TSL, implement hostname check and certificate check for lib-vau
CVSS 9.1
CVE-2026-52688
HIGH
PowerDNS Recursor - DNSSEC Wildcard Validation Bypass
CVSS 7.5
CVE-2026-56820
HIGH
Netty: Missing CertificateID Validation in OCSP Response Allows Replay Attacks
CVSS 7.4
CVE-2026-60648
HIGH
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Code Execution via Web Content Management
CVSS 8.0
CVE-2026-56624
HIGH
Apache MINA SSHD: SSH certificate options lack validations
CVSS 7.3
CVE-2026-46428
CRITICAL
lettre has TLS hostname verification disabled when using Boring TLS backend
CVE-2026-13410
HIGH
Dancer::Plugin::Auth::Google versions through 0.07 for Perl have TLS verification disabled
CVSS 8.2
CVE-2026-38974
MEDIUM
Dulwich <= 1.1.0 - Unauthenticated Remote Code Execution via Missing SSH Host Key Verification in Paramiko Vendor Module
CVSS 5.3
CVE-2026-13385
CRITICAL
Asus Router - Improper Certificate Validation
CVE-2026-50302
MEDIUM
Microsoft Windows 10 Version 21H2 - Windows Cryptographic Services Security Feature Bypass Vulnerability
CVSS 4.2
CVE-2026-55001
HIGH
Microsoft Windows 10 Version 1607 - Active Directory Domain Services Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-47632
HIGH
Azure Monitor Agent Metrics Extension Elevation of Privilege Vulnerability
CVSS 8.8
CVE-2026-59836
HIGH
Fortinet FortiClientEMS - Improper Certificate Validation
CVSS 7.5
CVE-2026-15683
HIGH
Lorex 2K Indoor Wi-Fi Security Camera Device Management Server Improper Certificate Validation Vulnerability
CVSS 7.5
CVE-2026-22093
CRITICAL
EVbee Service Android App - Improper Certificate Validation
CVE-2026-54919
HIGH
cpp-httplib: TLS certificate chain verification bypassed for IP-literal hosts on Mbed TLS and wolfSSL backends
CVSS 7.4
CVE-2026-0277
MEDIUM
Prisma Access Agent: Improper Certificate Validation on iOS
CVSS 5.9
CVE-2026-59818
MEDIUM
etcd: gRPC client listener does not enforce `--client-crl-file` certificate revocation
CVSS 6.5
CVE-2026-55436
HIGH
Coder's AI Bridge Proxy skips TLS certificate verification in default configuration
CVSS 7.4
Details
Vulnerabilities
1,453