CWE-295

Improper Certificate Validation

Parent: CWE-287 - Improper Authentication

The product does not validate, or incorrectly validates, a certificate.

1,454 vulnerabilities with CWE-295
CVE-2025-6026 LOW
Lenovo Universal Device Client < 25.7.0.21 - Improper Certificate Validation
CVSS 3.1
CVE-2025-10699 MEDIUM
Lenovo LeCloud Client < 2.501.25.0 - Information Disclosure via Improper Certificate Validation
CVSS 5.3
CVE-2025-11695 HIGH
MongoDB Rust Driver < 3.2.5 - Improper Certificate Validation
CVSS 8.0
CVE-2025-11633 LOW
Furbo 360 Dog Camera <036 & Furbo Mini <074 - Improper Certificate Validation
CVSS 3.7
CVE-2025-61778 CRITICAL
Akka.Remote 1.2.0-1.5.51 - Authentication Bypass via Missing Mutual TLS Enforcement
CVE-2025-34235 HIGH
Vasion Print Virtual Appliance < 25.1.102 & Application < 25.1.1413 - Remote Code Execution via Weak SSL/TLS Validation
CVSS 7.8
CVE-2025-10548 MEDIUM
CleverControl employee monitoring software 11.5.1041.6 - Remote Code Execution via TLS Certificate Validation Bypass
CVSS 6.5
CVE-2025-34199 HIGH
Vasion Print Virtual Appliance <20.0.2786 & Host <22.0.1049 TLS/SSL Certificate Validation Flaw
CVSS 8.1
CVE-2025-59353 HIGH
Dragonfly < 2.1.0 - Improper Certificate Validation via mTLS Authentication Bypass
CVSS 7.5
CVE-2025-59347 MEDIUM
Dragonfly < 2.1.0 - Improper Certificate Validation in HTTP Clients
CVSS 6.5
CVE-2025-35434 MEDIUM
CISA Thorium < 1.1.2 - Unauthenticated TLS Certificate Validation Bypass in Elasticsearch Connection
CVSS 4.2
CVE-2025-9708 MEDIUM
Kubernetes C# client - Man-in-the-Middle
CVSS 6.8
CVE-2025-55109 CRITICAL
Control-M/Agent <9.0.20 - Auth Bypass
CVSS 9.0
CVE-2025-50944 HIGH
AVTECH EagleEyes 2.0.0 - Info Disclosure
CVSS 8.8
CVE-2025-58781 MEDIUM
WTW-EAGLE App for iOS < 4.4.1 and Android < 4.4.0.10 - Improper Certificate Validation
CVSS 4.8
CVE-2025-9785 HIGH
PaperCut Print Deploy - Info Disclosure
CVE-2025-33099 MEDIUM
IBM Concert Software <1.1.0 - Man In The Middle
CVSS 5.9
CVE-2025-30278 HIGH
Qsync Central <4.5.0.7 - Info Disclosure
CVSS 8.8
CVE-2025-30277 HIGH
Qsync Central <4.5.0.7 - Info Disclosure
CVSS 8.8
CVE-2025-58127 MEDIUM
Checkmk Exchange Dell Powerscale Plugin - Improper Certificate Validation
CVSS 4.8
CVE-2025-58126 MEDIUM
Checkmk Exchange VMware vSAN Plugin - Improper Certificate Validation
CVSS 4.8
CVE-2025-58125 MEDIUM
pawelko freebox_v6_agent - Improper Certificate Validation
CVSS 4.8
CVE-2025-58124 MEDIUM
check_mk_python_api - Improper Certificate Validation
CVSS 4.8
CVE-2025-58123 MEDIUM
Checkmk Exchange BGP Monitoring - Improper Certificate Validation
CVSS 4.8
CVE-2025-7390 CRITICAL
OPC UA C++ SDK 6.40-6.79 and >=6.80.1 - Improper Certificate Validation
CVSS 9.1
Details
Vulnerabilities 1,454