CWE-295

Improper Certificate Validation

Parent: CWE-287 - Improper Authentication

The product does not validate, or incorrectly validates, a certificate.

1,400 vulnerabilities with CWE-295
CVE-2022-32153 HIGH
Splunk Enterprise <9.0-8.2.2203 - Privilege Escalation
CVSS 8.1
CVE-2022-32152 HIGH
Splunk Enterprise < 9.0 & Splunk Cloud Platform < 8.2.2203 - Improper Certificate Validation
CVSS 8.1
CVE-2022-32151 HIGH
Splunk < 9.0 and Splunk Cloud Platform < 8.2.2203 - Improper Certificate Validation
CVSS 7.4
CVE-2022-29482 LOW
Mobaoku-Auction&Flea Market < 5.5.16 - Improper Certificate Validation
CVSS 3.7
CVE-2022-32563 CRITICAL
Couchbase Sync Gateway 3.0.0-3.0.1 - Unauthenticated Privilege Escalation via X.509 Certificate Authentication Bypass
CVSS 9.8
CVE-2022-26493 CRITICAL
miniOrange Premium-Enterprise Drupal SAML SP - Auth Bypass
CVSS 9.8
CVE-2022-27782 HIGH
curl < 7.83.1 - Improper Certificate Validation
CVSS 7.5
CVE-2022-26491 MEDIUM
Pidgin < 2.14.9 - Improper Certificate Validation via DNS Spoofing
CVSS 5.9
CVE-2022-26766 MEDIUM
tvOS <15.5-iOS <15.5- iPadOS <15.5 - Signature Validation Bypass
CVSS 5.5
CVE-2022-29082 LOW
Dell EMC NetWorker <19.6 - SSL/TLS Impersonation
CVSS 3.7
CVE-2022-22306 MEDIUM
FortiOS 6.0.0-6.0.14, 6.2.0-6.2.10, 6.4.0-6.4.8, 7.0.0 - MITM via Improper Certificate Validation
CVSS 5.4
CVE-2022-29222 MEDIUM
Pion DTLS < 2.1.5 - Improper Certificate Validation
CVSS 5.9
CVE-2022-22787 MEDIUM
Zoom Meetings < 5.10.0 - Improper Certificate Validation
CVSS 5.9
CVE-2022-26923 HIGH KEV
Active Directory Certificate Services (ADCS) privilege escalation (Certifried)
CVSS 8.8
CVE-2022-24901 HIGH
parse-server < 4.10.10 - Improper Certificate Validation in Apple Game Center Authentication
CVSS 7.5
CVE-2022-1343 MEDIUM
OpenSSL 3.0.0-3.0.2 - Improper Certificate Validation in OCSP_basic_verify
CVSS 5.3
CVE-2022-27536 HIGH
GO < 1.18.1 - Improper Certificate Validation
CVSS 7.5
CVE-2022-22549 HIGH
Dell PowerScale OneFS - Improper Certificate Validation
CVSS 7.5
CVE-2022-20081 MEDIUM
Android - Man-in-the-Middle Attack via Improper Certificate Validation in A-GPS
CVSS 5.9
CVE-2022-20071 MEDIUM
Android - Privilege Escalation via Missing Certificate Validation
CVSS 6.7
CVE-2022-28352 MEDIUM
WeeChat 3.2-3.4 - Improper Certificate Validation via GnuTLS Option Change
CVSS 4.3
CVE-2022-28142 HIGH
Jenkins Proxmox Plugin < 0.6.0 - SSL/TLS Certificate Validation Disabled
CVSS 7.5
CVE-2022-0123 MEDIUM
GitLab <14.4.5, 14.5.0-14.5.3, 14.6.0-14.6.1 - Info Disclosure
CVSS 5.9
CVE-2022-0759 HIGH
kubeclient < 4.9.3 - Improper Certificate Validation in Kubeconfig Parser
CVSS 8.1
CVE-2022-27820 MEDIUM
OWASP Zed Attack Proxy < w2022-03-21 - Improper Certificate Validation
CVSS 4.0
Details
Vulnerabilities 1,400