CWE-295

Improper Certificate Validation

Parent: CWE-287 - Improper Authentication

The product does not validate, or incorrectly validates, a certificate.

1,335 vulnerabilities with CWE-295
CVE-2025-15612 MEDIUM
Wazuh Provisioning Scripts / Build Infrastructure Improper Certificate Validation leading to MITM and RCE
CVSS 4.8
CVE-2025-68482 MEDIUM
Fortinet FortiAnalyzer/FortiManager - Info Disclosure
CVSS 6.9
CVE-2025-40896 MEDIUM
Arc Agent - MITM Attack
CVSS 6.5
CVE-2025-67601 HIGH
Rancher Manager - Auth Bypass
CVSS 8.3
CVE-2025-67752 HIGH
OpenEMR <7.0.4 - MITM
CVSS 8.1
CVE-2025-70058 HIGH
YMFE yapi 1.12.0 - Improper Certificate Validation
CVSS 7.4
CVE-2025-70045 HIGH
jxcore jxm master - Improper Certificate Validation
CVSS 7.4
CVE-2025-70044 MEDIUM
uTools-quickcommand 5.0.3 - Improper Cert Validation
CVSS 6.5
CVE-2025-70043 CRITICAL
Ayms node-To master - Improper Certificate Validation
CVSS 9.1
CVE-2025-66614 CRITICAL
Apache Tomcat 11.0.0-M1-11.0.14 - DoS
CVSS 9.1
CVE-2025-65753 HIGH
Guardian Gryphon v01.06.0006.22 - Command Injection
CVSS 7.5
CVE-2025-9293 HIGH
Certificate Validation Logic - Info Disclosure
CVSS 8.1
CVE-2025-15573 CRITICAL
SolaX Cloud - Man-in-the-Middle
CVSS 9.4
CVE-2025-70029 HIGH
SunbirdEd-portal <1.13.4 - Info Disclosure
CVSS 7.5
CVE-2025-15323 LOW
Tanium Tanos < 1.8.3.0199 - Improper Certificate Validation
CVSS 3.7
CVE-2025-68121 CRITICAL
GO < 1.24.13 - Improper Certificate Validation
CVSS 10.0
CVE-2025-15557 HIGH
Tp-link Tapo H100 Firmware < 1.6.1 - Improper Certificate Validation
CVSS 8.8
CVE-2025-53869 LOW
Brother MFP - SSL/TLS Info Disclosure
CVSS 3.7
CVE-2025-67229 CRITICAL
Todesktop Builder < 0.32.1 - Improper Certificate Validation
CVSS 9.8
CVE-2025-32057 MEDIUM
Bosch Infotainment ECU - SSL Impersonation
CVSS 6.5
CVE-2025-27377 MEDIUM
Altium Designer <24.9.0 - Info Disclosure
CVSS 5.3
CVE-2025-11043 HIGH
Automation Studio <6.5 - Info Disclosure
CVSS 7.4
CVE-2025-46070 CRITICAL
Automai Botmanager - Improper Certificate Validation
CVSS 9.8
CVE-2025-71063 HIGH
Mrvladus Errands < 46.2.10 - Improper Certificate Validation
CVSS 8.2
CVE-2025-66001 HIGH
NeuVector - Info Disclosure
CVSS 8.8
Details
Vulnerabilities 1,335