CWE-295

Improper Certificate Validation

Parent: CWE-287 - Improper Authentication

The product does not validate, or incorrectly validates, a certificate.

1,454 vulnerabilities with CWE-295
CVE-2025-65290 HIGH
Aqara Hub M2, M3, and Camera Hub G3 Firmware - Improper Certificate Validation
CVSS 7.4
CVE-2025-65830 CRITICAL
meatmeet - Improper Certificate Validation
CVSS 9.1
CVE-2025-40801 HIGH
Siemens COMOS V10.6 < V10.6.1 - Improper Certificate Validation
CVSS 8.1
CVE-2025-40800 HIGH
COMOS V10.6- Simcenter Femap - SSL/TLS Validation
CVSS 7.4
CVE-2025-66491 MEDIUM
Traefik 3.5.0-3.6.2 - Improper Certificate Validation via proxy-ssl-verify Annotation
CVSS 5.9
CVE-2025-61727 MEDIUM
GO < 1.24.11 - Improper Certificate Validation
CVSS 6.5
CVE-2025-61729 HIGH
GO < 1.24.11 - Improper Certificate Validation
CVSS 7.5
CVE-2025-12893 MEDIUM
MongoDB 7.0.0-7.0.25 - Improper Certificate Validation on Windows and Apple Platforms
CVSS 4.2
CVE-2025-44018 HIGH
GL-Inet GL-AXT1800 4.7.0 - Firmware Downgrade
CVSS 8.3
CVE-2025-65083 LOW
GoSign Desktop <2.4.1 - Info Disclosure
CVSS 3.2
CVE-2025-60022 MEDIUM
デジラアプリ iOS < 80.10.00 - Man-in-the-Middle Information Disclosure
CVSS 4.8
CVE-2025-30669 MEDIUM
Zoom Meeting Software Development Kit < 6.5.10 - Improper Certificate Validation
CVSS 4.8
CVE-2025-12765 HIGH
pgAdmin <= 9.9 - Improper Certificate Validation in LDAP Authentication
CVSS 7.5
CVE-2025-12047 MEDIUM
Lenovo Scanner pro - Info Disclosure
CVSS 5.3
CVE-2025-10495 HIGH
Lenovo App Store, PC Manager, Browser, and Legion Zone - Remote Code Execution via Improper Certificate Validation
CVSS 7.5
CVE-2025-40744 HIGH
Solid Edge SE2025 <V225.0 Update 11 - Man in the Middle
CVSS 7.5
CVE-2025-12943 HIGH
NETGEAR RAX30/RAXE300 - Command Injection
CVSS 7.5
CVE-2025-64685 HIGH
JetBrains YouTrack < 2025.3.104432 - Improper TLS Certificate Validation
CVSS 8.1
CVE-2025-64432 MEDIUM
KubeVirt < 1.5.3 and 1.6.0 - Improper Certificate Validation in mTLS Authentication
CVSS 4.7
CVE-2025-56231 CRITICAL
Tonec Internet Download Manager < 6.42.41.1 - Missing SSL Certificate Validation
CVSS 9.1
CVE-2025-54470 HIGH
NeuVector 5.3.0-5.3.4, 5.4.0-5.4.6 - Certificate Validation Bypass and DoS via Telemetry
CVSS 8.6
CVE-2025-58188 HIGH
GO < 1.24.8 - Improper Certificate Validation
CVSS 7.5
CVE-2025-62375 MEDIUM
go-witness < 0.9.1 - Improper Certificate Validation in AWS Attestor
CVE-2025-11619 HIGH
Devolutions Server < 2025.2.15.0 - Improper Certificate Validation
CVSS 8.8
CVE-2025-62371 HIGH
OpenSearch Data Prepper < 2.12.2 - Improper Certificate Validation in OpenSearch Sink and Source Plugins
CVSS 7.4
Details
Vulnerabilities 1,454