CWE-295

Improper Certificate Validation

Parent: CWE-287 - Improper Authentication

The product does not validate, or incorrectly validates, a certificate.

1,454 vulnerabilities with CWE-295
CVE-2025-52919 MEDIUM
Yealink RPS <2025-05-26 - Info Disclosure
CVSS 4.3
CVE-2025-32878 CRITICAL
COROS PACE 3 Firmware < 3.0808.0 - Improper Certificate Validation in HTTPS Communication
CVSS 9.8
CVE-2025-36041 MEDIUM
IBM MQ Operator 2.0.0-2.0.29, 3.1.0-3.1.3, 3.2.0-3.2.12 - Improper Certificate Validation in Native HA CRR
CVSS 4.7
CVE-2025-24471 MEDIUM
Fortinet Fortisase < 7.4.8 - Improper Certificate Validation
CVSS 6.5
CVE-2025-33031 HIGH
File Station 5 <5.5.6.4847 - Info Disclosure
CVSS 8.8
CVE-2025-30279 HIGH
File Station 5 <5.5.6.4847 - Improper Certificate Validation
CVSS 8.8
CVE-2025-29885 HIGH
File Station 5 <5.5.6.4791 - Improper Certificate Validation
CVSS 8.8
CVE-2025-29884 HIGH
File Station 5 <5.5.6.4791 - Info Disclosure
CVSS 8.8
CVE-2025-29883 HIGH
File Station 5 <5.5.6.4791 - Improper Certificate Validation
CVSS 8.8
CVE-2025-22486 HIGH
QNAP File Station 5.5.6.4691-5.5.6.4791 - Improper Certificate Validation
CVSS 8.8
CVE-2025-5025 MEDIUM
curl 8.5.0-8.13.9 - Improper Certificate Validation in QUIC HTTP/3 with wolfSSL
CVSS 4.8
CVE-2025-4947 MEDIUM
curl 8.8.0-8.13.0 - Improper Certificate Validation for QUIC Connections via IP Address URL
CVSS 6.5
CVE-2025-5279 HIGH
Amazon Redshift Python Connector 2.0.872-2.1.7 - Improper Certificate Validation
CVE-2025-4575 MEDIUM
OpenSSL 3.5 - Improper Certificate Validation via -addreject Option
CVSS 6.5
CVE-2025-32407 MEDIUM
Samsung Internet for Galaxy Watch 5.0.9 - Improper Certificate Validation
CVSS 5.9
CVE-2025-3463 CRITICAL
ASUS DriverHub - Improper Certificate Validation via Crafted HTTP Requests
CVE-2025-20157 MEDIUM
Cisco Catalyst SD-WAN Manager - Info Disclosure
CVSS 5.9
CVE-2025-46551 LOW
JRuby-OpenSSL 0.12.1-0.15.3 and JRuby 9.3.4.0-9.4.12.0 and 10.0.0.0 - Improper Certificate Validation
CVSS 3.7
CVE-2025-3218 MEDIUM
IBM i 7.2-7.6 - Improper Certificate Validation in Netserver
CVSS 5.4
CVE-2025-37730 MEDIUM
Logstash 8.0.0-8.17.5, 8.18.0, 9.0.0 - Improper Certificate Validation in TCP Output
CVSS 6.5
CVE-2025-20670 MEDIUM
MediaTek NR16 NR17 NR17R - Remote Information Disclosure via Improper Certificate Validation
CVSS 5.7
CVE-2025-27820 HIGH
Apache HttpClient 5.4-5.4.2 - Improper Certificate Validation in PSL Domain Check Logic
CVSS 7.5
CVE-2025-28169 HIGH
BYD QIN PLUS DM-i Dilink OS - Info Disclosure
CVSS 8.1
CVE-2025-26478 LOW
Dell ECS < 3.8.1.4 & ObjectScale < 4.0.0.0 - Unauthenticated Info Disclosure via Cert Validation
CVSS 3.1
CVE-2025-22459 MEDIUM
Ivanti Endpoint Manager <2024 SU1, <2022 SU7 - Info Disclosure
CVSS 4.8
Details
Vulnerabilities 1,454