CWE-295

Improper Certificate Validation

Parent: CWE-287 - Improper Authentication

The product does not validate, or incorrectly validates, a certificate.

1,335 vulnerabilities with CWE-295
CVE-2025-64685 HIGH
Jetbrains Youtrack < 2025.3.104432 - Improper Certificate Validation
CVSS 8.1
CVE-2025-64432 MEDIUM
Kubevirt < 1.5.3 - Authentication Bypass
CVSS 4.7
CVE-2025-56231 CRITICAL
Tonec Internet Download Manager - Improper Certificate Validation
CVSS 9.1
CVE-2025-54470 HIGH
Neuvector < 5.3.5 - Improper Certificate Validation
CVSS 8.6
CVE-2025-58188 HIGH
GO < 1.24.8 - Improper Certificate Validation
CVSS 7.5
CVE-2025-62375 MEDIUM
In-toto Go-witness < 0.9.1 - Improper Certificate Validation
CVE-2025-11619 HIGH
Devolutions Server < 2025.2.15.0 - Improper Certificate Validation
CVSS 8.8
CVE-2025-62371 HIGH
Amazon Opensearch Data Prepper - Improper Certificate Validation
CVSS 7.4
CVE-2025-6026 LOW
Lenovo UDC - Info Disclosure
CVSS 3.1
CVE-2025-10699 MEDIUM
Lenovo LeCloud - Info Disclosure
CVSS 5.3
CVE-2025-11695 HIGH
Mongodb Rust Driver < 3.2.5 - Improper Certificate Validation
CVSS 8.0
CVE-2025-11633 LOW
Furbo Mini Firmware < 074 - Authentication Bypass
CVSS 3.7
CVE-2025-61778 CRITICAL
Nuget Akka.remote < 1.5.52 - Missing Authentication
CVE-2025-34235 HIGH
Vasion Virtual Appliance Application - Improper Certificate Validation
CVSS 7.8
CVE-2025-10548 MEDIUM
CleverControl v11.5.1041.6 - RCE
CVSS 6.5
CVE-2025-34199 HIGH
Vasion Virtual Appliance Application - Improper Certificate Validation
CVSS 8.1
CVE-2025-59353 HIGH
Linuxfoundation Dragonfly < 2.1.0 - Missing Authorization
CVSS 7.5
CVE-2025-59347 MEDIUM
Linuxfoundation Dragonfly < 2.1.0 - Improper Certificate Validation
CVSS 6.5
CVE-2025-35434 MEDIUM
Cisa Thorium < 1.1.2 - Improper Certificate Validation
CVSS 4.2
CVE-2025-9708 MEDIUM
Kubernetes C# client - Man-in-the-Middle
CVSS 6.8
CVE-2025-55109 CRITICAL
Control-M/Agent <9.0.20 - Auth Bypass
CVSS 9.0
CVE-2025-50944 HIGH
AVTECH EagleEyes 2.0.0 - Info Disclosure
CVSS 8.8
CVE-2025-58781 MEDIUM
WTW-EAGLE App - Info Disclosure
CVSS 4.8
CVE-2025-9785 HIGH
PaperCut Print Deploy - Info Disclosure
CVE-2025-33099 MEDIUM
IBM Concert Software <1.1.0 - Man In The Middle
CVSS 5.9
Details
Vulnerabilities 1,335