CWE-295

Improper Certificate Validation

Parent: CWE-287 - Improper Authentication

The product does not validate, or incorrectly validates, a certificate.

1,454 vulnerabilities with CWE-295
CVE-2024-4786 LOW
Lenovo Tab K10 - Improper Certificate Validation
CVSS 2.8
CVE-2024-28872 HIGH
ISC Stork 0.15.0-1.15.0 - Improper Certificate Validation
CVSS 8.9
CVE-2024-37865 MEDIUM
S3Browser < 11.7.5 - Improper Certificate Validation
CVSS 5.9
CVE-2024-39698 HIGH
electron-builder < 6.3.0 - Signature Validation Bypass via Environment Variable Expansion
CVSS 7.5
CVE-2024-28067 MEDIUM
Samsung Exynos Modem 5300 Firmware - Man-in-the-Middle Security Mode Downgrade
CVSS 5.3
CVE-2024-33509 MEDIUM
FortiWeb 6.3.0-7.2.1 - Unauthenticated Improper Certificate Validation
CVSS 4.8
CVE-2024-39312 MEDIUM
Botan < 2.19.5 - Improper Certificate Validation in X.509 Name Constraint Extension
CVSS 5.3
CVE-2024-20080 CRITICAL
Gnss Service - Privilege Escalation
CVSS 9.8
CVE-2024-25053 MEDIUM
IBM Cognos Analytics <12.0.2 - Improper Certificate Validation
CVSS 5.9
CVE-2024-5261 CRITICAL
LibreOffice < 24.2.4 - Improper Certificate Validation in LibreOfficeKit Mode
CVSS 9.8
CVE-2024-28021 HIGH
FOXMAN-UN/UNEM - Improper Certificate Validation in Message Queueing Mechanism
CVSS 7.4
CVE-2024-35140 HIGH
IBM Security Verify Access Docker 10.0.0-10.0.6 - Privilege Escalation via Improper Certificate Validation
CVSS 7.7
CVE-2024-29072 HIGH
Foxit PDF Editor < 11.2.9.53938 & PDF Reader < 2024.2.1.25153 Privilege Escalation
CVSS 8.2
CVE-2024-31340 MEDIUM
TP-Link Tether <4.5.13 & Tapo <3.3.6 - Info Disclosure
CVSS 4.8
CVE-2024-35299 MEDIUM
JetBrains YouTrack < 2024.1.29548 - Improper Certificate Validation in SMTPS Protocol
CVSS 5.9
CVE-2024-30020 HIGH
Microsoft Windows Cryptographic Services - Remote Code Execution
CVSS 8.1
CVE-2024-33612 MEDIUM
BIG-IP Next Central Manager 20.0.1-20.1.x - Improper Certificate Validation
CVSS 6.8
CVE-2024-0042 HIGH
Google Android - Improper Certificate Validation
CVSS 7.8
CVE-2024-4063 LOW
EZVIZ CS-C6-21WFR-8 5.2.7 Build 170628 - Improper Certificate Valid...
CVSS 3.7
CVE-2024-4062 LOW
Hualai Xiaofang iSC5 3.2.2_112 - Improper Certificate Validation
CVSS 3.7
CVE-2024-29733 LOW
Apache Airflow FTP Provider <3.7.0 - Certificate Validation
CVSS 2.7
CVE-2024-3738 HIGH
nginxwebui < 4.2.4 - Improper Certificate Validation in handlePath Function
CVSS 7.3
CVE-2024-31872 HIGH
IBM Security Verify Access Appliance <10.0.8 - SSRF
CVSS 7.5
CVE-2024-31871 HIGH
IBM Security Verify Access Appliance <10.0.8 - SSRF
CVSS 7.5
CVE-2024-29050 HIGH
Windows 10 1507-22H2 and Windows 11 21H2-22H2 - Remote Code Execution via Cryptographic Services
CVSS 8.4
Details
Vulnerabilities 1,454