CWE-295: CWE-295

258
Total CVEs
38
Critical
144
High
7.4
Avg CVSS

Yearly Trend

2026
39
2025
90
2024
48
2023
31
2022
19

Top Affected Vendors

1 Ibm 10
2 Fortinet 7
3 Debian 7
4 Google 6
5 Qnap 6
6 Libreoffice 6
7 Hashicorp 5
8 Dell 5
9 Asustor 5
10 Linuxfoundation 4

All CWE-295 CVEs (258)

CVE-2024-0042
7.8

This vulnerability allows local attackers to bypass DRM content protection on Android devices by exploiting confusion between OEM and DRM certificates...

May 7, 2024
CVE-2023-6043
7.8

This CVE describes a local privilege escalation vulnerability in Lenovo Vantage software where attackers can bypass integrity checks to execute arbitr...

Jan 19, 2024
CVE-2020-12614
7.8

This vulnerability in BeyondTrust Privilege Management for Windows allows attackers to bypass certificate validation when publisher criteria is select...

Dec 12, 2023
CVE-2023-21358
7.8

This vulnerability allows a malicious Android app to impersonate the system UWB resources component due to improper cryptographic implementation. This...

Oct 30, 2023
CVE-2023-20963
7.8

This vulnerability in Android's WorkSource component involves a parcel mismatch that allows local privilege escalation without requiring user interact...

Mar 24, 2023
CVE-2022-40620
7.7

This vulnerability allows attackers to intercept unencrypted update requests and deliver malicious packages to affected NETGEAR routers and Orbi WiFi ...

Jan 28, 2026
CVE-2025-14022
7.7

LINE client for iOS versions before 15.4 has a critical SSL/TLS certificate validation bypass vulnerability in an integrated financial SDK. This allow...

Dec 15, 2025
CVE-2025-54607
7.7

This CVE describes an authentication management vulnerability in Huawei's ArkWeb module that could allow attackers to bypass authentication mechanisms...

Aug 6, 2025
CVE-2026-3336
7.5

A certificate validation bypass vulnerability in AWS-LC's PKCS7_verify() function allows unauthenticated attackers to bypass certificate chain verific...

Mar 2, 2026
CVE-2025-65753
7.5

A TLS certificate validation vulnerability in Guardian Gryphon v01.06.0006.22 allows attackers to bypass authentication and execute arbitrary commands...

Feb 17, 2026
CVE-2025-70029
7.5

This vulnerability in Sunbird-Ed portal version 1.13.4 disables TLS/SSL certificate validation, allowing attackers to intercept and potentially modify...

Feb 11, 2026
CVE-2026-25961
7.5

This vulnerability allows network attackers to intercept SumatraPDF's update requests and deliver malicious installers due to disabled TLS hostname ve...

Feb 9, 2026
CVE-2026-25644
7.5

DataHub's LDAP ingestion source is vulnerable to TLS downgrade attacks, allowing man-in-the-middle attackers to intercept and potentially modify LDAP ...

Feb 6, 2026
CVE-2025-61729
7.5

This vulnerability in Go's HostnameError.Error() function allows a malicious certificate to cause excessive resource consumption through unbounded str...

Dec 2, 2025
CVE-2025-12765
7.5

pgAdmin versions up to 9.9 have a vulnerability in LDAP authentication that allows attackers to bypass TLS certificate verification. This enables man-...

Nov 13, 2025
CVE-2025-10495
7.5

This vulnerability in Lenovo client applications allows attackers on the same logical network to execute arbitrary code under certain conditions. It a...

Nov 12, 2025
CVE-2025-40744
7.5

This vulnerability in Solid Edge SE2025 allows unauthenticated remote attackers to perform man-in-the-middle attacks by exploiting improper client cer...

Nov 11, 2025
CVE-2025-12943
7.5

This vulnerability allows attackers who can intercept and modify traffic destined for affected NETGEAR routers to execute arbitrary commands on the de...

Nov 11, 2025
CVE-2024-47619
7.5

This vulnerability in syslog-ng's TLS certificate validation allows improper wildcard matching patterns like 'foo.*.bar' and 'foo.a*c.bar' that should...

May 7, 2025
CVE-2025-0500
7.5

This CVE describes a man-in-the-middle vulnerability in Amazon's remote desktop clients (WorkSpaces, AppStream 2.0, DCV) that could allow attackers to...

Jan 15, 2025
CVE-2025-0501
7.5

This CVE describes a man-in-the-middle vulnerability in Amazon WorkSpaces native clients using the PCoIP protocol. Attackers could potentially interce...

Jan 15, 2025
CVE-2024-45234
7.5

A vulnerability in FORT RPKI validator before version 1.6.3 allows a malicious RPKI repository to serve specially crafted ROA or Manifest data encoded...

Aug 24, 2024
CVE-2024-41264
7.5

This vulnerability in Casdoor v1.636.0 allows attackers to bypass SSH host key verification, potentially enabling man-in-the-middle attacks and creden...

Aug 1, 2024
CVE-2024-31872
7.5

IBM Security Verify Access Appliance versions 10.0.0 through 10.0.7 have a missing certificate validation vulnerability when deploying Open Source scr...

Apr 10, 2024
CVE-2024-27323
7.5

This vulnerability allows network-adjacent attackers to execute arbitrary code on PDF-XChange Editor installations without user interaction. The updat...

Apr 1, 2024
CVE-2023-4499
7.5

CVE-2023-4499 is an information disclosure vulnerability in HP ThinUpdate utility (also known as HP Recovery Image and Software Download Tool) that co...

Oct 13, 2023
CVE-2023-21265
7.5

This vulnerability involves multiple root CA certificates that should be disabled in Android systems. If exploited, it could allow remote attackers to...

Aug 14, 2023
CVE-2023-30222
7.5

This vulnerability in 4D SAS 4D Server allows attackers to eavesdrop on network traffic and retrieve password hashes for all users. It affects 4D Serv...

Jun 16, 2023
CVE-2022-45458
7.5

This vulnerability allows attackers to bypass certificate validation in Acronis products, potentially leading to man-in-the-middle attacks, sensitive ...

May 18, 2023
CVE-2023-22642
7.5

This CVE describes an improper certificate validation vulnerability in FortiAnalyzer and FortiManager devices that allows remote unauthenticated attac...

Apr 11, 2023
CVE-2023-0464
7.5

This OpenSSL vulnerability allows attackers to cause denial-of-service by exploiting certificate policy constraint processing. When enabled, malicious...

Mar 22, 2023
CVE-2022-26305
7.5

LibreOffice improperly validates macro signatures by only checking certificate serial numbers and issuer strings, not the actual cryptographic signatu...

Jul 25, 2022
CVE-2021-29755
7.5

IBM QRadar SIEM versions 7.3, 7.4, and 7.5 fail to properly validate SSL/TLS certificates for some inter-host communications. This allows attackers to...

Jul 20, 2022
CVE-2020-16093
7.5

LemonLDAP::NG versions through 2.0.8 do not validate X.509 certificates when connecting to LDAP backends by default, allowing man-in-the-middle attack...

Jul 18, 2022
CVE-2022-22549
7.5

CVE-2022-22549 is an improper certificate validation vulnerability in Dell PowerScale OneFS storage systems. Unauthenticated remote attackers can expl...

Apr 12, 2022
CVE-2022-28142
7.5

The Jenkins Proxmox Plugin versions 0.6.0 and earlier disable SSL/TLS certificate validation globally for the entire Jenkins controller JVM when confi...

Mar 29, 2022
CVE-2021-3698
7.5

CVE-2021-3698 is an authentication bypass vulnerability in Cockpit's SSSD certificate verification. It allows client certificates to authenticate succ...

Mar 10, 2022
CVE-2022-25640
7.5

This vulnerability in wolfSSL allows TLS 1.3 clients to bypass mutual authentication requirements by omitting the certificate_verify message during ha...

Feb 24, 2022
CVE-2021-25634
7.5

LibreOffice has an improper certificate validation vulnerability that allows attackers to modify digitally signed ODF documents and insert bogus signi...

Oct 12, 2021
CVE-2021-25633
7.5

This vulnerability allows attackers to create digitally signed LibreOffice documents that appear valid but contain manipulated content unrelated to th...

Oct 11, 2021
CVE-2021-38864
7.5

IBM Security Verify Bridge 1.0.5.0 has improper certificate validation that could allow attackers to intercept sensitive information. This affects org...

Sep 23, 2021
CVE-2020-36478
7.5

This vulnerability in Mbed TLS allows attackers to bypass certificate validation by exploiting a parsing flaw where NULL algorithm parameters are inco...

Aug 23, 2021
CVE-2021-35193
7.5

Patterson Eaglesoft dental practice management software versions 18-21 has a certificate authentication flaw where the same certificate is accepted ac...

Jul 30, 2021
CVE-2021-32574
7.5

This vulnerability in HashiCorp Consul's Envoy proxy allows TLS connections to bypass service identity validation. Attackers could potentially interce...

Jul 17, 2021
CVE-2021-36377
7.5

This vulnerability in Fossil SCM software allows attackers to perform man-in-the-middle attacks by bypassing TLS certificate hostname validation. When...

Jul 12, 2021
CVE-2016-20011
7.5

CVE-2016-20011 is a TLS certificate verification bypass vulnerability in libgrss that allows attackers to perform man-in-the-middle attacks on RSS/Ato...

May 25, 2021
CVE-2021-27400
7.5

HashiCorp Vault's Cassandra integrations failed to validate TLS certificates when connecting to Cassandra clusters, allowing man-in-the-middle attacks...

Apr 22, 2021
CVE-2020-9321
7.5

Traefik 2.x before 2.1.4 and TraefikEE 2.0.0 fail to properly purge certificate contents before logging, potentially exposing sensitive TLS certificat...

Mar 16, 2020
CVE-2025-70045
7.4

This vulnerability allows man-in-the-middle attacks by disabling TLS/SSL certificate validation in jxcore jxm master. When 'jx_obj.IsSecure' is true, ...

Feb 23, 2026
CVE-2025-11043
7.4

An improper certificate validation vulnerability in OPC-UA and ANSL over TLS clients in Automation Studio allows attackers to intercept and manipulate...

Jan 19, 2026

About CWE-295 (CWE-295)

Our database tracks 258 CVEs classified as CWE-295, with 38 rated critical and 144 rated high severity. The average CVSS score for CWE-295 vulnerabilities is 7.4.

External reference: View CWE-295 on MITRE CWE →

Monitor CWE-295 Vulnerabilities

Get alerted when new CWE-295 CVEs affect your infrastructure.

Start Monitoring Free