CWE-295

Improper Certificate Validation

Parent: CWE-287 - Improper Authentication

The product does not validate, or incorrectly validates, a certificate.

1,454 vulnerabilities with CWE-295
CVE-2024-21543 HIGH
djoser < 2.3.0 - Authentication Bypass via Database Query Fallback
CVSS 7.1
CVE-2024-12174 LOW
Tenable Security Center - Privilege Escalation
CVSS 2.7
CVE-2024-54147 MEDIUM
Altair < 8.0.5 - Improper Certificate Validation
CVSS 6.8
CVE-2024-48865 HIGH
QNAP QTS and QuTS hero - Improper Certificate Validation
CVSS 7.5
CVE-2024-6219 LOW
LXD < 5.21.1 - Improper Certificate Validation in PKI Mode
CVSS 3.8
CVE-2024-6156 LOW
LXD < 5.21.2 - Improper Certificate Validation in PKI Mode
CVSS 3.8
CVE-2024-53846 MEDIUM
Erlang/OTP 25.3.2.8-25.3.2.16, 26.2-26.2.5.6, 27.0-27.1.3 - Improper Certificate Validation
CVSS 5.5
CVE-2024-45205 HIGH
Unifi iOS App <10.18.0 - Info Disclosure
CVSS 7.1
CVE-2024-5921 HIGH
Palo Alto Networks GlobalProtect - Improper Certificate Validation
CVSS 8.8
CVE-2024-52510 MEDIUM
Nextcloud Desktop 3.0.0-3.14.1 - Improper Certificate Validation via Empty Initial Signature
CVSS 4.2
CVE-2024-5918 MEDIUM
Palo Alto Networks PAN-OS - Improper Certificate Validation in GlobalProtect Portal/Gateway
CVSS 4.3
CVE-2024-49369 CRITICAL
Icinga 2.4.0-2.11.11 - Improper Certificate Validation
CVSS 9.8
CVE-2024-51774 HIGH
qBittorrent <5.0.1 - Info Disclosure
CVSS 8.1
CVE-2024-30149 MEDIUM
HCL AppScan Source <= 10.6.0 - Info Disclosure
CVSS 4.8
CVE-2024-43177 MEDIUM
IBM Concert 1.0.0 and 1.0.1 - Improper Certificate Validation
CVSS 5.9
CVE-2024-47241 MEDIUM
Dell Secure Connect Gateway (SCG) <5.24 - Improper Certificate Vali...
CVSS 5.5
CVE-2024-22030 HIGH
Rancher 2.7.0-2.9.2 URL Certificate Validation - Man-in-the-Middle
CVSS 8.0
CVE-2024-31955 MEDIUM
Samsung eMMC KLMAG2GE4A and KLM8G1WEMB - Improper Certificate Validation via Electromagnetic Fault Injection
CVSS 4.9
CVE-2024-48915 HIGH
agent_dart < 1.0.0-dev.29 - Improper Certificate Validation in _checkDelegation Function
CVE-2024-43550 HIGH
Windows Secure Channel - Spoofing via Improper Certificate Validation
CVSS 7.4
CVE-2024-7206 HIGH
eWeLink Zigbee Bridge Pro <= 2.0.0 - SSL Pinning Bypass Secret Extraction
CVE-2024-20385 MEDIUM
Cisco Nexus Dashboard Orchestrator - Info Disclosure
CVSS 5.9
CVE-2024-9160 MEDIUM
PEADM Forge Module <3.24.0 - Info Disclosure
CVE-2024-38861 HIGH
MikroTik 2.0.0-2.5.5 and 0.4a_mk-2.0a - Improper Certificate Validation
CVSS 7.4
CVE-2024-30134 MEDIUM
HCL Traveler for Microsoft Outlook < 3.0.9 - Improper Certificate Validation
CVSS 6.7
Details
Vulnerabilities 1,454