CWE-295: CWE-295
Yearly Trend
Top Affected Vendors
All CWE-295 CVEs (255)
A certificate validation vulnerability in Mozilla products allows improper certificate length checking when adding certificates to a certificate store...
Feb 4, 2025This vulnerability allows attackers to intercept and tamper with data transmitted to Nuki smart lock devices due to lack of certificate validation in ...
May 14, 2024This vulnerability in NETGEAR routers allows network-adjacent attackers to exploit improper certificate validation in the HTTPS update functionality. ...
May 3, 2024CVE-2022-27644 is a certificate validation vulnerability in NETGEAR R6700v3 routers that allows network-adjacent attackers to intercept HTTPS download...
Mar 29, 2023This vulnerability allows non-server agents in HashiCorp Nomad clusters to access server-only Raft RPC functionality, enabling privilege escalation. A...
Sep 7, 2021This vulnerability in D-Link DAP-1880AC firmware allows remote authenticated attackers to bypass certificate chain of trust validation, potentially ga...
Apr 26, 2021This vulnerability allows attackers to spoof the SALTO server in Gallagher Command Centre systems due to improper certificate validation. Attackers co...
Mar 10, 2025This vulnerability in OTRS and OTRS Community Edition allows attackers to intercept email communications by using invalid or expired SSL/TLS certifica...
Oct 16, 2023Dell Unity storage systems prior to version 5.3 contain a man-in-the-middle vulnerability in the vmadapter component. Attackers can spoof vCenter cert...
Nov 22, 2023This CVE describes a firmware downgrade vulnerability in GL-Inet GL-AXT1800 routers where attackers can perform man-in-the-middle attacks to deliver m...
Nov 24, 2025This vulnerability in Podman's machine init command allows man-in-the-middle attacks by failing to verify TLS certificates when downloading VM images ...
Jun 24, 2025Argo CD versions 0.4.0 through 2.4.4 (excluding patched versions) have improper certificate validation for OpenID Connect providers, allowing attacker...
Jul 12, 2022Errands versions before 46.2.10 fail to validate TLS certificates when connecting to CalDAV servers, allowing man-in-the-middle attackers to intercept...
Jan 12, 2026This vulnerability in IBM Cognos Controller and IBM Controller allows unauthorized users to obtain valid authentication tokens due to improper certifi...
Jan 7, 2025This vulnerability in IBM Security Verify Access allows a privileged user to install a configuration file that could enable remote access, potentially...
Feb 7, 2024This vulnerability allows an unauthenticated attacker on the same network to perform a man-in-the-middle attack between FortiClientEMS and FortiClient...
Dec 16, 2021OpenEMR versions before 7.0.4 have disabled SSL/TLS certificate verification by default in their HTTP client, making all HTTPS connections vulnerable ...
Feb 25, 2026This vulnerability allows an unauthorized attacker to execute arbitrary code over a network by exploiting improper certificate validation in Azure Loc...
Feb 10, 2026A vulnerability in fog-kubevirt allows remote attackers to perform Man-in-the-Middle attacks by intercepting communications between Satellite and Open...
Feb 2, 2026This vulnerability in foreman_kubevirt disables SSL certificate verification by default when connecting to OpenShift without an explicitly set CA cert...
Feb 2, 2026This vulnerability in Siemens industrial software products allows man-in-the-middle attacks due to missing TLS certificate validation in the SALT SDK....
Dec 9, 2025SICAM TOOLBOX II fails to validate extended key usage attributes in TLS certificates, allowing attackers to perform man-in-the-middle attacks. This af...
Jul 8, 2025BYD QIN PLUS DM-i vehicles running Dilink OS versions 3.0_13.1.7.2204050.1 through 3.0_13.1.7.2312290.1_0 send unencrypted broadcasts to manufacturer ...
Apr 23, 2025HCL BigFix Web Reports has improper SSL certificate validation, allowing man-in-the-middle attacks. Attackers could intercept and manipulate HTTPS com...
Apr 15, 2025CVE-2025-1193 is a certificate validation vulnerability in Devolutions Remote Desktop Manager that allows man-in-the-middle attacks. Attackers can int...
Feb 10, 20252N Access Commander versions 2.1 and earlier fail to verify TLS certificates from 2N edge devices by default, allowing man-in-the-middle attackers to ...
Feb 6, 2025qBittorrent versions before 5.0.1 fail to properly validate HTTPS certificates, allowing connections to proceed even when certificate validation error...
Nov 2, 2024This vulnerability in Red Hat OpenStack Platform director allows attackers to deploy compromised container images by disabling TLS certificate verific...
Aug 21, 2024MiniTool Power Data Recovery 11.6 has an insecure installation process vulnerable to man-in-the-middle attacks, allowing attackers to intercept and re...
Sep 19, 2023MiniTool Shadow Maker version 4.1 has an insecure installation process vulnerable to man-in-the-middle attacks, allowing attackers to intercept and mo...
Sep 19, 2023MiniTool Partition Wizard 12.8 has an insecure installation mechanism that allows attackers to perform man-in-the-middle attacks during software updat...
Sep 19, 2023This vulnerability in Samsung Email allows attackers to perform man-in-the-middle attacks by exploiting improper certificate validation. Attackers can...
Sep 6, 2023The Mattermost iOS app fails to properly validate TLS server certificates during WebSocket connection initialization, allowing network attackers to pe...
Jul 17, 2023The DroneScout ds230 Remote ID receiver has an improper authentication vulnerability during firmware updates where it doesn't validate TLS certificate...
Jul 11, 2023This vulnerability allows authenticated Cloud Foundry users to overwrite syslog drain credentials of other users if they know the client certificate u...
May 19, 2023CVE-2023-31484 is a TLS certificate verification bypass vulnerability in CPAN.pm that allows man-in-the-middle attackers to intercept and modify softw...
Apr 29, 2023HTTP::Tiny versions before 0.083 have an insecure default TLS configuration that does not verify SSL/TLS certificates by default, requiring users to e...
Apr 29, 2023This vulnerability allows man-in-the-middle attackers to intercept and potentially manipulate connections between PCoIP Zero Clients and Amazon Worksp...
Jul 28, 2022Splunk Enterprise and Universal Forwarder versions before 9.0 do not validate TLS certificates by default when the CLI connects to remote Splunk insta...
Jun 15, 2022Splunk Enterprise and Splunk Cloud Platform versions before 9.0 and 8.2.2203 respectively did not validate TLS certificates during Splunk-to-Splunk co...
Jun 15, 2022This vulnerability allows man-in-the-middle attackers to intercept and potentially decrypt sensitive communications between Gallagher Command Centre s...
Nov 18, 2021This vulnerability allows man-in-the-middle attackers to intercept and manipulate communications between Acronis products and their servers due to mis...
Aug 5, 2021Motorola MH702x devices before version 2.0.0.301 fail to properly validate SSL/TLS server certificates when communicating with the support server. Thi...
Apr 13, 2021This vulnerability in SPIRE allows authenticated agents to request X.509 certificates for SPIFFE IDs they're not authorized to distribute. Attackers w...
Mar 5, 2021This vulnerability in MongoDB Rust Driver disables TLS certificate validation when tlsInsecure=False appears in connection strings, allowing man-in-th...
Oct 13, 2025Boundary and Boundary Enterprise are vulnerable to session hijacking through TLS certificate tampering. Attackers with specific privileges can craft T...
Feb 5, 2024This vulnerability allows a local attacker to escalate privileges through improper validation in the firmware update mechanism of LADM and LDCC compon...
Dec 16, 2024This vulnerability in LibreOffice's certificate validation UI could allow users to inadvertently run malicious signed macros when certificate verifica...
Aug 5, 2024This vulnerability allows local attackers to bypass DRM content protection on Android devices by exploiting confusion between OEM and DRM certificates...
May 7, 2024This CVE describes a local privilege escalation vulnerability in Lenovo Vantage software where attackers can bypass integrity checks to execute arbitr...
Jan 19, 2024About CWE-295 (CWE-295)
Our database tracks 255 CVEs classified as CWE-295, with 38 rated critical and 141 rated high severity. The average CVSS score for CWE-295 vulnerabilities is 7.4.
External reference: View CWE-295 on MITRE CWE →
Monitor CWE-295 Vulnerabilities
Get alerted when new CWE-295 CVEs affect your infrastructure.
Start Monitoring Free