CWE-295

Improper Certificate Validation

Parent: CWE-287 - Improper Authentication

The product does not validate, or incorrectly validates, a certificate.

1,395 vulnerabilities with CWE-295
CVE-2025-59353 HIGH
Dragonfly < 2.1.0 - Improper Certificate Validation via mTLS Authentication Bypass
CVSS 7.5
CVE-2025-59347 MEDIUM
Dragonfly < 2.1.0 - Improper Certificate Validation in HTTP Clients
CVSS 6.5
CVE-2025-35434 MEDIUM
CISA Thorium < 1.1.2 - Unauthenticated TLS Certificate Validation Bypass in Elasticsearch Connection
CVSS 4.2
CVE-2025-9708 MEDIUM
Kubernetes C# client - Man-in-the-Middle
CVSS 6.8
CVE-2025-55109 CRITICAL
Control-M/Agent <9.0.20 - Auth Bypass
CVSS 9.0
CVE-2025-50944 HIGH
AVTECH EagleEyes 2.0.0 - Info Disclosure
CVSS 8.8
CVE-2025-58781 MEDIUM
WTW-EAGLE App for iOS < 4.4.1 and Android < 4.4.0.10 - Improper Certificate Validation
CVSS 4.8
CVE-2025-9785 HIGH
PaperCut Print Deploy - Info Disclosure
CVE-2025-33099 MEDIUM
IBM Concert Software <1.1.0 - Man In The Middle
CVSS 5.9
CVE-2025-30278 HIGH
Qsync Central <4.5.0.7 - Info Disclosure
CVSS 8.8
CVE-2025-30277 HIGH
Qsync Central <4.5.0.7 - Info Disclosure
CVSS 8.8
CVE-2025-58127 MEDIUM
Checkmk Exchange Dell Powerscale Plugin - Improper Certificate Validation
CVSS 4.8
CVE-2025-58126 MEDIUM
Checkmk Exchange VMware vSAN Plugin - Improper Certificate Validation
CVSS 4.8
CVE-2025-58125 MEDIUM
pawelko freebox_v6_agent - Improper Certificate Validation
CVSS 4.8
CVE-2025-58124 MEDIUM
check_mk_python_api - Improper Certificate Validation
CVSS 4.8
CVE-2025-58123 MEDIUM
Checkmk Exchange BGP Monitoring - Improper Certificate Validation
CVSS 4.8
CVE-2025-7390 CRITICAL
OPC UA C++ SDK 6.40-6.79 and >=6.80.1 - Improper Certificate Validation
CVSS 9.1
CVE-2025-33142 MEDIUM
IBM WebSphere App Server <9.0 - Info Disclosure
CVSS 5.3
CVE-2025-0309 MEDIUM
Netskope Client - Privilege Escalation
CVE-2025-2183 MEDIUM
Palo Alto GlobalProtect - Auth Bypass
CVE-2025-54809 HIGH
F5 Access for Android 3.1.0-3.1.1 - Improper Certificate Validation
CVSS 7.4
CVE-2025-8393 HIGH
Dreamehome iOS app < 2.3.4 and Android app < 2.1.8.8 - Improper Certificate Validation
CVSS 7.3
CVE-2025-20215 MEDIUM
Cisco Webex Meetings - Privilege Escalation
CVSS 5.4
CVE-2025-48393 MEDIUM
Eaton G4 PDU < 3.5.0 - Man-in-the-Middle via Insecure Firmware Upgrade Certificate Validation
CVSS 5.7
CVE-2025-2028 MEDIUM
Check Point Log Server - Improper Certificate Validation
CVSS 6.5
Details
Vulnerabilities 1,395