CWE-295: CWE-295

255
Total CVEs
38
Critical
141
High
7.4
Avg CVSS

Yearly Trend

2026
38
2025
90
2024
48
2023
31
2022
19

Top Affected Vendors

1 Ibm 10
2 Fortinet 7
3 Debian 7
4 Google 6
5 Libreoffice 6
6 Qnap 6
7 Hashicorp 5
8 Dell 5
9 Asustor 5
10 Linuxfoundation 4

All CWE-295 CVEs (255)

CVE-2025-68121
10.0

This vulnerability in Go's crypto/tls package allows TLS session resumption to succeed when it should fail due to certificate authority configuration ...

Feb 5, 2026
CVE-2025-67229
9.8

An improper certificate validation vulnerability in ToDesktop Builder v0.32.1 allows an unauthenticated, on-path attacker to spoof backend responses b...

Jan 23, 2026
CVE-2025-46070
9.8

A critical remote code execution vulnerability in Automai BotManager v25.2.0 allows attackers to execute arbitrary code on affected systems via the Bo...

Jan 12, 2026
CVE-2025-29331
9.8

A critical vulnerability in MHSanaei 3x-ui management panel allows remote attackers to execute arbitrary code by exploiting insecure certificate valid...

Jun 26, 2025
CVE-2025-6433
9.8

This vulnerability allows malicious websites with invalid TLS certificates to bypass WebAuthn security requirements and prompt users for authenticatio...

Jun 24, 2025
CVE-2024-56521
9.8

This vulnerability in TCPDF before version 6.8.0 disables SSL certificate verification when libcurl is used, allowing man-in-the-middle attacks. Any a...

Dec 27, 2024
CVE-2024-49369
9.8

CVE-2024-49369 is a critical TLS certificate validation flaw in Icinga 2 that allows attackers to impersonate trusted cluster nodes and API users usin...

Nov 12, 2024
CVE-2019-20461
9.8

This vulnerability allows unauthenticated attackers to access Alecto IVM-100 camera feeds over the internet by exploiting a custom UDP protocol that l...

Nov 7, 2024
CVE-2024-20080
9.8

This vulnerability in MediaTek's GNSS service allows remote attackers to escalate privileges without user interaction due to improper certificate vali...

Jul 1, 2024
CVE-2024-5261
9.8

LibreOfficeKit mode in LibreOffice versions before 24.2.4 disables TLS certificate verification when fetching remote resources via curl, allowing man-...

Jun 25, 2024
CVE-2024-25140
9.8

A default installation of RustDesk 1.2.3 on Windows automatically installs a test code signing certificate into the Trusted Root Certification Authori...

Feb 6, 2024
CVE-2023-51837
9.8

MeshCentral 1.1.16 fails to properly validate SSL certificates when establishing connections, allowing man-in-the-middle attackers to intercept and ma...

Jan 30, 2024
CVE-2023-42425
9.8

This critical vulnerability in Turing Video Turing Edge+ EVC5FD allows remote attackers to execute arbitrary code and access sensitive information thr...

Oct 31, 2023
CVE-2023-40256
9.8

CVE-2023-40256 allows untrusted clients to interact with RabbitMQ service in Veritas NetBackup Snapshot Manager due to improper certificate validation...

Aug 11, 2023
CVE-2022-47758
9.8

Nanoleaf smart lighting firmware versions 7.1.1 and below lack TLS certificate verification, allowing attackers to intercept communications via DNS hi...

Apr 27, 2023
CVE-2021-46880
9.8

This vulnerability in LibreSSL and OpenBSD's certificate verification allows authentication bypass by discarding errors for unverified certificate cha...

Apr 15, 2023
CVE-2022-45597
9.8

ComponentSpace.Saml2 4.4.0 fails to validate SSL certificates at the application layer during SAML authentication, allowing man-in-the-middle attacks....

Mar 24, 2023
CVE-2022-32563
9.8

CVE-2022-32563 is an authentication bypass vulnerability in Couchbase Sync Gateway that allows unauthenticated users to escalate privileges when X.509...

Jun 10, 2022
CVE-2022-26493
9.8

This vulnerability allows attackers to bypass authentication and authorization in miniOrange Drupal SAML SP modules by removing SAML assertion signatu...

Jun 3, 2022
CVE-2022-22885
9.8

CVE-2022-22885 is a critical vulnerability in Hutool v5.7.18 where the HttpRequest component disables TLS/SSL certificate validation, allowing man-in-...

Feb 16, 2022
CVE-2021-40855
9.8

A critical vulnerability in the EU Digital COVID Certificate system allowed non-production public key certificates to be used in production, potential...

Jan 21, 2022
CVE-2021-33907
9.8

This vulnerability allows attackers to execute arbitrary code with elevated privileges by exploiting improper certificate validation during Zoom Clien...

Sep 27, 2021
CVE-2020-28907
9.8

CVE-2020-28907 is a critical SSL certificate validation vulnerability in Nagios Fusion that allows attackers to escalate privileges to root or execute...

May 24, 2021
CVE-2021-31597
9.4

The xmlhttprequest-ssl package for Node.js versions before 1.6.1 disables SSL certificate validation by default, allowing man-in-the-middle attacks. T...

Apr 23, 2021
CVE-2023-38686
9.3

Sydent, an identity server for Matrix, fails to verify SMTP server certificates when sending emails via TLS, making email communications vulnerable to...

Aug 4, 2023
CVE-2025-70043
9.1

This vulnerability in Ayms node-To master branch disables TLS/SSL certificate validation, allowing man-in-the-middle attackers to intercept and manipu...

Feb 23, 2026
CVE-2026-25160
9.1

Alist file list program versions before 3.57.0 disable TLS certificate verification by default for all outgoing storage communications, making all dat...

Feb 4, 2026
CVE-2025-65830
9.1

This vulnerability allows attackers to intercept and manipulate TLS traffic between a mobile application and its server due to missing certificate val...

Dec 10, 2025
CVE-2025-56231
9.1

Tonec Internet Download Manager versions 6.42.41.1 and earlier fail to properly validate SSL certificates during update checks. This allows attackers ...

Nov 5, 2025
CVE-2025-7390
9.1

CVE-2025-7390 allows a malicious client to bypass client certificate authentication in Softing OPC HTTPS servers configured for secure communication o...

Aug 21, 2025
CVE-2024-25141
9.1

This vulnerability in Apache Airflow's MongoDB hook allows SSL/TLS certificate validation to be disabled by default when SSL is enabled, enabling man-...

Feb 20, 2024
CVE-2023-49312
9.1

This vulnerability allows attackers to bypass Precision Bridge's license enforcement by using the same license key on multiple systems. Attackers can ...

Nov 26, 2023
CVE-2021-29504
9.1

This vulnerability in WP-CLI allows attackers who can intercept network traffic to disable TLS certificate verification, enabling man-in-the-middle at...

Jun 7, 2021
CVE-2020-29663
9.1

This vulnerability in Icinga 2 allows revoked certificates to be automatically renewed despite being on a Certificate Revocation List (CRL), bypassing...

Dec 15, 2020
CVE-2020-9868
9.1

This vulnerability allows an attacker to impersonate trusted websites by exploiting a certificate validation flaw in administrator-added certificates....

Oct 22, 2020
CVE-2025-55109
9.0

An authentication bypass vulnerability in Control-M/Agent allows remote attackers to authenticate using expired demo or third-party certificates inste...

Sep 16, 2025
CVE-2025-23114
9.0

A TLS certificate validation vulnerability in Veeam Updater allows man-in-the-middle attackers to intercept update communications and execute arbitrar...

Feb 5, 2025
CVE-2021-43882
9.0

CVE-2021-43882 is a remote code execution vulnerability in Microsoft Defender for IoT that allows attackers to execute arbitrary code on affected syst...

Dec 15, 2021
CVE-2024-28872
8.9

A TLS certificate validation flaw in Stork management tool allows attackers to obtain valid certificates from the Stork server and use them to connect...

Jul 11, 2024
CVE-2025-15557
8.8

An improper certificate validation vulnerability in TP-Link Tapo H100 v1 and Tapo P100 v1 allows attackers on the same network segment to intercept an...

Feb 5, 2026
CVE-2025-66001
8.8

This vulnerability in NeuVector's OpenID Connect implementation allows man-in-the-middle attacks by not enforcing TLS certificate verification by defa...

Jan 8, 2026
CVE-2025-11619
8.8

CVE-2025-11619 is an improper certificate validation vulnerability in Devolutions Server that allows man-in-the-middle attackers to intercept encrypte...

Oct 15, 2025
CVE-2025-50944
8.8

This vulnerability in AVTECH EagleEyes 2.0.0 allows attackers to perform man-in-the-middle attacks by bypassing TLS certificate validation. The custom...

Sep 15, 2025
CVE-2025-30277
8.8

An improper certificate validation vulnerability in Qsync Central allows attackers with user accounts to bypass certificate checks and potentially int...

Aug 29, 2025
CVE-2025-30279
8.8

This CVE describes an improper certificate validation vulnerability in QNAP File Station 5. If an attacker obtains valid user credentials, they can ex...

Jun 6, 2025
CVE-2025-29883
8.8

This CVE describes an improper certificate validation vulnerability in QNAP File Station 5 that allows remote attackers with user access to bypass cer...

Jun 6, 2025
CVE-2025-29885
8.8

This CVE describes an improper certificate validation vulnerability in QNAP File Station 5. If exploited, remote attackers with user access could comp...

Jun 6, 2025
CVE-2025-22486
8.8

This CVE describes an improper certificate validation vulnerability in QNAP File Station 5 that could allow remote attackers with user access to compr...

Jun 6, 2025
CVE-2024-50394
8.8

This CVE describes an improper certificate validation vulnerability in QNAP Helpdesk software. Attackers could exploit this to perform man-in-the-midd...

Mar 7, 2025
CVE-2024-11621
8.8

This vulnerability allows attackers to perform man-in-the-middle attacks by intercepting and modifying encrypted communications in Devolutions Remote ...

Feb 10, 2025

About CWE-295 (CWE-295)

Our database tracks 255 CVEs classified as CWE-295, with 38 rated critical and 141 rated high severity. The average CVSS score for CWE-295 vulnerabilities is 7.4.

External reference: View CWE-295 on MITRE CWE →

Monitor CWE-295 Vulnerabilities

Get alerted when new CWE-295 CVEs affect your infrastructure.

Start Monitoring Free