CWE-295: CWE-295

260
Total CVEs
38
Critical
146
High
7.4
Avg CVSS

Yearly Trend

2026
39
2025
90
2024
48
2023
31
2022
19

Top Affected Vendors

1 Ibm 10
2 Fortinet 7
3 Google 7
4 Debian 7
5 Qnap 6
6 Libreoffice 6
7 Hashicorp 5
8 Dell 5
9 Asustor 5
10 Linuxfoundation 4

All CWE-295 CVEs (260)

CVE-2025-11043
7.4

An improper certificate validation vulnerability in OPC-UA and ANSL over TLS clients in Automation Studio allows attackers to intercept and manipulate...

Jan 19, 2026
CVE-2025-65290
7.4

Aqara Hub devices fail to validate server certificates during HTTPS firmware downloads, allowing man-in-the-middle attackers to intercept update traff...

Dec 10, 2025
CVE-2025-65291
7.4

Aqara Hub devices fail to validate TLS server certificates during discovery and CoAP communications, allowing man-in-the-middle attackers to intercept...

Dec 10, 2025
CVE-2025-40800
7.4

This vulnerability allows attackers to perform man-in-the-middle attacks by exploiting missing server certificate validation in the IAM client of affe...

Dec 9, 2025
CVE-2025-62371
7.4

OpenSearch Data Prepper versions before 2.12.2 have a vulnerability where OpenSearch sink and source plugins automatically trust all SSL certificates ...

Oct 15, 2025
CVE-2025-54809
7.4

F5 Access for Android before version 3.1.2 fails to verify remote endpoint identity during HTTPS connections, allowing man-in-the-middle attacks. This...

Aug 13, 2025
CVE-2025-46788
7.4

Zoom Workplace for Linux versions before 6.4.13 have improper certificate validation that could allow an attacker to intercept communications and acce...

Jul 10, 2025
CVE-2024-52329
7.4

The ECOVACS HOME mobile app plugins for specific robot vacuum models fail to properly validate TLS certificates, allowing man-in-the-middle attackers ...

Jan 23, 2025
CVE-2024-52330
7.4

ECOVACS robotic lawnmowers and vacuums fail to properly validate TLS certificates, allowing unauthenticated attackers to intercept and manipulate TLS ...

Jan 23, 2025
CVE-2024-54848
7.4

This vulnerability in CP Plus CP-VNR-3104 network video recorders allows attackers to intercept and decrypt communications or perform man-in-the-middl...

Jan 10, 2025
CVE-2022-20814
7.4

This vulnerability allows an unauthenticated remote attacker to perform man-in-the-middle attacks against Cisco Expressway-C and TelePresence VCS devi...

Nov 15, 2024
CVE-2023-49570
7.4

This vulnerability in Bitdefender Total Security's HTTPS scanning feature incorrectly trusts certificates that aren't authorized to issue certificates...

Oct 18, 2024
CVE-2023-6055
7.4

This vulnerability in Bitdefender Total Security's HTTPS scanning allows attackers to perform Man-in-the-Middle attacks by intercepting communications...

Oct 18, 2024
CVE-2023-6057
7.4

This vulnerability in Bitdefender Total Security's HTTPS scanning feature improperly trusts DSA-signed certificates, allowing attackers to perform man...

Oct 18, 2024
CVE-2024-38861
7.4

The Checkmk Exchange plugin for MikroTik has improper certificate validation, allowing attackers in a man-in-the-middle position to intercept and pote...

Sep 27, 2024
CVE-2024-7383
7.4

CVE-2024-7383 is a TLS certificate verification flaw in libnbd that allows man-in-the-middle attacks on NBD (Network Block Device) traffic. This vulne...

Aug 5, 2024
CVE-2023-50178
7.4

This CVE describes an improper certificate validation vulnerability in FortiADC that allows remote unauthenticated attackers to perform Man-in-the-Mid...

Jul 9, 2024
CVE-2024-29887
7.4

This vulnerability allows man-in-the-middle attacks against Serverpod's non-web HTTP clients by bypassing TLS certificate validation. Attackers can in...

Mar 27, 2024
CVE-2020-29504
7.4

This vulnerability in Dell BSAFE cryptographic libraries allows attackers to potentially bypass security controls or decrypt sensitive data when crypt...

Feb 2, 2024
CVE-2023-6680
7.4

An improper certificate validation vulnerability in GitLab EE's experimental Smartcard authentication feature allows attackers to impersonate other us...

Dec 15, 2023
CVE-2023-24461
7.4

CVE-2023-24461 is an improper certificate validation vulnerability in F5 BIG-IP Edge Client for Windows and macOS that allows attackers to impersonate...

May 3, 2023
CVE-2022-20860
7.4

This vulnerability allows an unauthenticated remote attacker to perform man-in-the-middle attacks on SSL/TLS connections between Cisco Nexus Dashboard...

Jul 21, 2022
CVE-2021-3618
7.4

ALPACA is a TLS protocol confusion attack that allows man-in-the-middle attackers to redirect traffic between different services sharing compatible ce...

Mar 23, 2022
CVE-2021-44531
7.4

This vulnerability in Node.js allows attackers to bypass certificate name constraints by using arbitrary Subject Alternative Name (SAN) types, particu...

Feb 24, 2022
CVE-2022-23632
7.4

Traefik versions before 2.6.1 incorrectly handle TLS configuration when requests use fully qualified domain names (FQDNs) in the Host header, potentia...

Feb 17, 2022
CVE-2021-44549
7.4

Apache Sling Commons Messaging Mail versions before 2.0 lack server identity verification for SMTPS connections by default, allowing man-in-the-middle...

Dec 14, 2021
CVE-2021-34599
7.4

CVE-2021-34599 is a certificate validation vulnerability in CODESYS Git versions prior to V1.1.0.0 that allows man-in-the-middle attacks by not verify...

Dec 1, 2021
CVE-2021-31892
7.4

This vulnerability in multiple Siemens SINUMERIK industrial software products allows man-in-the-middle attacks due to improper SSL/TLS certificate val...

Jul 13, 2021
CVE-2021-1134
7.4

This vulnerability allows unauthenticated remote attackers to intercept and modify sensitive network client data by exploiting improper X.509 certific...

Jun 29, 2021
CVE-2021-3450
7.4

This OpenSSL vulnerability allows certificate chain validation to be bypassed when the X509_V_FLAG_X509_STRICT flag is explicitly set. It affects appl...

Mar 25, 2021
CVE-2021-26911
7.4

CVE-2021-26911 is a missing SSL certificate validation vulnerability in Canary Mail's IMAP implementation when using STARTTLS mode. This allows man-in...

Feb 17, 2021
CVE-2024-3738
7.3

This critical vulnerability in cym1102 nginxWebUI allows remote attackers to bypass certificate validation through manipulation of the nginxPath param...

Apr 13, 2024
CVE-2024-43107
7.2

CVE-2024-43107 is an improper certificate validation vulnerability in Gallagher's Milestone Integration Plugin that allows unauthenticated messages (i...

Mar 10, 2025
CVE-2024-45205
7.1

The UniFi iOS app (versions 10.17.7 and earlier) fails to properly validate certificates when managing standalone UniFi Access Points, allowing attack...

Dec 4, 2024
CVE-2025-9708
6.8

This vulnerability in the Kubernetes C# client allows attackers to bypass certificate validation, accepting forged certificates from any Certificate A...

Sep 16, 2025
CVE-2025-6037
6.8

The Vault TLS certificate authentication method fails to properly validate client certificates when configured with non-CA certificates as trusted cer...

Aug 1, 2025
CVE-2024-54147
6.8

Altair GraphQL Client desktop app versions before 8.0.5 fail to validate HTTPS certificates, allowing man-in-the-middle attackers to intercept all Gra...

Dec 9, 2024
CVE-2024-31489
6.8

This vulnerability allows remote unauthenticated attackers to perform man-in-the-middle attacks during ZTNA tunnel creation between FortiGate and Fort...

Sep 10, 2024
CVE-2025-30000
6.7

A privilege escalation vulnerability in Siemens License Server allows low-privileged users to gain higher permissions. This affects all Siemens Licens...

Apr 8, 2025
CVE-2024-30134
6.7

This CVE describes a false positive detection issue where HCL Traveler for Microsoft Outlook (HTMO.exe) is incorrectly flagged as malicious software b...

Sep 26, 2024
CVE-2025-32057
6.5

This vulnerability allows attackers to impersonate legitimate update servers for Nissan Leaf infotainment systems due to improper SSL certificate vali...

Jan 22, 2026
CVE-2025-61727
6.5

This vulnerability allows certificate authorities to issue certificates with wildcard SANs that bypass excluded subdomain constraints. It affects syst...

Dec 3, 2025
CVE-2025-10548
6.5

CleverControl employee monitoring software fails to validate TLS certificates during installation, allowing man-in-the-middle attackers to intercept d...

Sep 23, 2025
CVE-2025-59347
6.5

Dragonfly Manager versions before 2.1.0 have disabled TLS certificate verification in HTTP clients, making them vulnerable to man-in-the-middle attack...

Sep 17, 2025
CVE-2025-2028
6.5

This vulnerability allows man-in-the-middle attackers to intercept and modify CSV files containing IP-to-country mappings during download due to missi...

Aug 6, 2025
CVE-2025-48802
6.5

This vulnerability allows an authorized attacker to spoof their identity on Windows SMB networks by exploiting improper certificate validation. Attack...

Jul 8, 2025
CVE-2025-4947
6.5

libcurl versions 8.9.0 through 8.10.0 fail to verify TLS certificates for QUIC connections when URLs contain IP addresses instead of hostnames. This a...

May 28, 2025
CVE-2025-4575
6.5

A copy-paste error in OpenSSL 3.5 causes the '-addreject' option in the openssl x509 command to incorrectly mark certificates as trusted for specific ...

May 22, 2025
CVE-2024-23970
6.5

This vulnerability in ChargePoint Home Flex charging stations allows network-adjacent attackers to bypass SSL certificate validation, potentially enab...

Jan 31, 2025
CVE-2013-6662
6.5

Google Chrome cached TLS sessions before validating server certificates, allowing attackers to intercept and decrypt HTTPS traffic. This affects users...

Apr 13, 2017

About CWE-295 (CWE-295)

Our database tracks 260 CVEs classified as CWE-295, with 38 rated critical and 146 rated high severity. The average CVSS score for CWE-295 vulnerabilities is 7.4.

External reference: View CWE-295 on MITRE CWE →

Monitor CWE-295 Vulnerabilities

Get alerted when new CWE-295 CVEs affect your infrastructure.

Start Monitoring Free