CWE-295

Improper Certificate Validation

Parent: CWE-287 - Improper Authentication

The product does not validate, or incorrectly validates, a certificate.

1,454 vulnerabilities with CWE-295
CVE-2024-38324 MEDIUM
IBM Storage Defender <2.0.8 - Info Disclosure
CVSS 5.9
CVE-2024-43201 HIGH
Planet Fitness Workouts - Info Disclosure
CVSS 8.8
CVE-2024-8287 HIGH
Anbox Management Service <1.23.0 - Info Disclosure
CVSS 7.5
CVE-2024-8096 MEDIUM
curl 7.41.0-8.10.0 - Improper Certificate Validation via OCSP Stapling
CVSS 6.5
CVE-2024-31489 MEDIUM
FortiClient 7.0.0-7.0.11, 7.2.0-7.2.4 - Unauthenticated MITM via ZTNA Tunnel Certificate Validation
CVSS 6.8
CVE-2024-40714 HIGH
TLS Certificate Validation - Info Disclosure
CVSS 8.3
CVE-2024-38642 HIGH
QuMagie < 2.3.1 - Improper Certificate Validation
CVSS 7.8
CVE-2024-45159 CRITICAL
Mbed TLS 3.2.0-3.6.0 - Improper Certificate Validation in TLS 1.3 Client Authentication
CVSS 9.8
CVE-2024-8285 MEDIUM
Kroxylicious Kafka TLS - Hostname Verification Bypass
CVSS 5.9
CVE-2024-39771 MEDIUM
Safie QBiC CLOUD CC-2L < 1.1.30 & Safie One < 1.8.2 - MITM via Improper Certificate Validation
CVSS 6.8
CVE-2024-41996 HIGH
Diffie-Hellman Key Agreement Protocol - Resource Consumption
CVSS 7.5
CVE-2024-45234 HIGH
nicmx fort-validator < 1.6.3 - Denial of Service via Non-Canonical BER SignedAttrs
CVSS 7.5
CVE-2024-37311 HIGH
Collabora Online - SSL Incomplete Verification
CVSS 8.2
CVE-2024-8007 HIGH
Red Hat OpenStack Platform - Improper Certificate Validation in Container Image Deployment
CVSS 8.1
CVE-2024-32928 MEDIUM
Google Nest Mini Firmware - Improper Certificate Validation in libcurl
CVSS 5.9
CVE-2024-7570 HIGH
Ivanti Neurons for ITSM 2023.4 and earlier - Improper Certificate Validation
CVSS 8.3
CVE-2024-5445 LOW
Ecosystem Agent <4.1.5.2597 & <5.1.4.2473 - SSL/TLS Validation
CVSS 3.8
CVE-2024-42395 CRITICAL
AP Certificate Management Service - Unauthenticated RCE
CVSS 9.8
CVE-2024-7383 HIGH
Red Hat Enterprise Linux 8 - Improper Certificate Validation in libnbd
CVSS 7.4
CVE-2024-6472 HIGH
LibreOffice <24.2.5 - Info Disclosure
CVSS 7.8
CVE-2024-32865 MEDIUM
exacqVision Server < 24.06 - Improper TLS Certificate Validation
CVSS 6.4
CVE-2024-41264 HIGH
casdoor 1.636.0 - Improper Certificate Validation via Insecure SSH Host Key Handling
CVSS 7.5
CVE-2024-41258 MEDIUM
filestash < 0.4 - Man-in-the-Middle Attack via Insecure SSH Host Key Verification
CVSS 5.3
CVE-2024-41256 MEDIUM
filestash < 0.4 - Improper Certificate Validation in ShareProofVerifier
CVSS 5.9
CVE-2024-40464 HIGH
beego <2.2.0 - Privilege Escalation
CVSS 8.8
Details
Vulnerabilities 1,454