CWE-295

Improper Certificate Validation

Parent: CWE-287 - Improper Authentication

The product does not validate, or incorrectly validates, a certificate.

1,397 vulnerabilities with CWE-295
CVE-2024-45159 CRITICAL
Mbed TLS 3.2.0-3.6.0 - Improper Certificate Validation in TLS 1.3 Client Authentication
CVSS 9.8
CVE-2024-8285 MEDIUM
Kroxylicious Kafka TLS - Hostname Verification Bypass
CVSS 5.9
CVE-2024-39771 MEDIUM
Safie QBiC CLOUD CC-2L < 1.1.30 & Safie One < 1.8.2 - MITM via Improper Certificate Validation
CVSS 6.8
CVE-2024-41996 HIGH
Diffie-Hellman Key Agreement Protocol - Resource Consumption
CVSS 7.5
CVE-2024-45234 HIGH
nicmx fort-validator < 1.6.3 - Denial of Service via Non-Canonical BER SignedAttrs
CVSS 7.5
CVE-2024-37311 HIGH
Collabora Online - SSL Incomplete Verification
CVSS 8.2
CVE-2024-8007 HIGH
Red Hat OpenStack Platform - Improper Certificate Validation in Container Image Deployment
CVSS 8.1
CVE-2024-32928 MEDIUM
Google Nest Mini Firmware - Improper Certificate Validation in libcurl
CVSS 5.9
CVE-2024-7570 HIGH
Ivanti Neurons for ITSM 2023.4 and earlier - Improper Certificate Validation
CVSS 8.3
CVE-2024-5445 LOW
Ecosystem Agent <4.1.5.2597 & <5.1.4.2473 - SSL/TLS Validation
CVSS 3.8
CVE-2024-42395 CRITICAL
AP Certificate Management Service - Unauthenticated RCE
CVSS 9.8
CVE-2024-7383 HIGH
Red Hat Enterprise Linux 8 - Improper Certificate Validation in libnbd
CVSS 7.4
CVE-2024-6472 HIGH
LibreOffice <24.2.5 - Info Disclosure
CVSS 7.8
CVE-2024-32865 MEDIUM
exacqVision Server < 24.06 - Improper TLS Certificate Validation
CVSS 6.4
CVE-2024-41264 HIGH
casdoor 1.636.0 - Improper Certificate Validation via Insecure SSH Host Key Handling
CVSS 7.5
CVE-2024-41258 MEDIUM
filestash < 0.4 - Man-in-the-Middle Attack via Insecure SSH Host Key Verification
CVSS 5.3
CVE-2024-41256 MEDIUM
filestash < 0.4 - Improper Certificate Validation in ShareProofVerifier
CVSS 5.9
CVE-2024-40464 HIGH
beego <2.2.0 - Privilege Escalation
CVSS 8.8
CVE-2024-4786 LOW
Lenovo Tab K10 - Improper Certificate Validation
CVSS 2.8
CVE-2024-28872 HIGH
ISC Stork 0.15.0-1.15.0 - Improper Certificate Validation
CVSS 8.9
CVE-2024-37865 MEDIUM
S3Browser < 11.7.5 - Improper Certificate Validation
CVSS 5.9
CVE-2024-39698 HIGH
electron-builder < 6.3.0 - Signature Validation Bypass via Environment Variable Expansion
CVSS 7.5
CVE-2024-28067 MEDIUM
Samsung Exynos Modem 5300 Firmware - Man-in-the-Middle Security Mode Downgrade
CVSS 5.3
CVE-2024-33509 MEDIUM
FortiWeb 6.3.0-7.2.1 - Unauthenticated Improper Certificate Validation
CVSS 4.8
CVE-2024-39312 MEDIUM
Botan < 2.19.5 - Improper Certificate Validation in X.509 Name Constraint Extension
CVSS 5.3
Details
Vulnerabilities 1,397