CWE-295: CWE-295

261
Total CVEs
38
Critical
147
High
7.4
Avg CVSS

Yearly Trend

2026
39
2025
90
2024
48
2023
31
2022
19

Top Affected Vendors

1 Ibm 10
2 Debian 8
3 Fortinet 7
4 Google 7
5 Qnap 6
6 Libreoffice 6
7 Hashicorp 5
8 Dell 5
9 Asustor 5
10 Fedoraproject 4

All CWE-295 CVEs (261)

CVE-2013-6662
6.5

Google Chrome cached TLS sessions before validating server certificates, allowing attackers to intercept and decrypt HTTPS traffic. This affects users...

Apr 13, 2017
CVE-2024-32865
6.4

CVE-2024-32865 is a TLS certificate validation vulnerability in exacqVision Server that allows man-in-the-middle attacks when connecting to devices. A...

Aug 1, 2024
CVE-2026-27133
5.9

This vulnerability in Strimzi allows Kafka Connect or Kafka MirrorMaker 2 operands to incorrectly trust all certificates in a CA chain when connecting...

Feb 20, 2026
CVE-2026-24932
5.9

This vulnerability allows attackers to perform Man-in-the-Middle attacks on DDNS update communications by exploiting improper TLS/SSL certificate vali...

Feb 3, 2026
CVE-2026-24933
5.9

This vulnerability allows unauthenticated remote attackers to perform Man-in-the-Middle attacks by intercepting HTTPS communications due to improper S...

Feb 3, 2026
CVE-2026-1778
5.9

This vulnerability in Amazon SageMaker Python SDK disables TLS certificate verification when importing Triton Python models, allowing HTTPS connection...

Feb 2, 2026
CVE-2025-13034
5.9

A certificate pinning bypass vulnerability in curl allows attackers to impersonate servers when specific conditions are met. The vulnerability affects...

Jan 8, 2026
CVE-2025-13052
5.9

This vulnerability allows attackers to perform man-in-the-middle attacks against SMTP email notifications in ASUSTOR ADM systems by exploiting imprope...

Dec 12, 2025
CVE-2025-66491
5.9

Traefik versions 3.5.0 through 3.6.2 have inverted TLS verification logic in the nginx.ingress.kubernetes.io/proxy-ssl-verify annotation. Setting the ...

Dec 9, 2025
CVE-2025-33099
5.9

IBM Concert Software versions 1.0.0 through 1.1.0 have improper certificate validation, allowing man-in-the-middle attacks. This enables attackers to ...

Sep 1, 2025
CVE-2025-32407
5.9

Samsung Internet for Galaxy Watch version 5.0.9 has a TLS certificate validation vulnerability that allows attackers to impersonate any website via ma...

May 16, 2025
CVE-2025-20157
5.9

An improper certificate validation vulnerability in Cisco Catalyst SD-WAN Manager (formerly vManage) allows attackers to intercept Smart Licensing tra...

May 7, 2025
CVE-2024-29171
5.9

Dell BSAFE SSL-J contains an improper certificate verification vulnerability that could allow a remote attacker to intercept or manipulate encrypted c...

Feb 12, 2025
CVE-2024-54847
5.9

This vulnerability in CP Plus CP-VNR-3104 network video recorders allows attackers to access Diffie-Hellman parameters, potentially enabling man-in-th...

Jan 10, 2025
CVE-2024-54849
5.9

This vulnerability in CP Plus CP-VNR-3104 video network recorders allows attackers to obtain the second RSA private key, potentially enabling decrypti...

Jan 10, 2025
CVE-2024-47119
5.9

IBM Storage Defender - Resiliency Service versions 2.0.0 through 2.0.9 fail to properly validate SSL/TLS certificates, allowing attackers to perform m...

Dec 18, 2024
CVE-2024-43177
5.9

IBM Concert versions 1.0.0 and 1.0.1 are vulnerable to cross-site request forgery (CSRF) and related attacks because they use cookies without the Same...

Oct 22, 2024
CVE-2024-37865
5.9

This vulnerability in S3Browser allows remote attackers to obtain sensitive information from S3-compatible storage systems through improper certificat...

Jul 9, 2024
CVE-2024-35299
5.9

This vulnerability in JetBrains YouTrack allows man-in-the-middle attacks due to improper certificate hostname validation in SMTPS protocol communicat...

May 16, 2024
CVE-2026-22613
5.7

CVE-2026-22613 is an insecure server identity check vulnerability in Eaton Network M3 firmware upgrade mechanism via command shell. This allows attack...

Feb 9, 2026
CVE-2025-48393
5.7

This CVE describes an insecure server identity check mechanism in Eaton G4 PDU firmware upgrades via command shell, allowing man-in-the-middle attacks...

Aug 6, 2025
CVE-2026-24935
5.6

This vulnerability allows a Man-in-the-Middle attacker to intercept or redirect NAT tunnel establishment due to improper SSL/TLS certificate validatio...

Feb 3, 2026
CVE-2021-25635
5.5

This vulnerability allows attackers to forge digital signatures in LibreOffice documents. An attacker can modify a signed ODF document to use an inval...

Mar 21, 2025
CVE-2024-47241
5.5

Dell Secure Connect Gateway (SCG) 5.0 Appliance - SRS versions 5.24 has an improper certificate validation vulnerability. A low-privileged attacker wi...

Oct 18, 2024
CVE-2025-20215
5.4

This vulnerability in Cisco Webex Meetings allowed an unauthenticated attacker on the same local network to intercept and complete meeting-join reques...

Aug 6, 2025
CVE-2025-3218
5.4

IBM i Netserver has authentication and authorization validation flaws that could allow attackers to brute force credentials or bypass access controls....

May 7, 2025
CVE-2025-27377
5.3

Altium Designer 24.9.0 fails to validate self-signed server certificates for cloud connections, allowing man-in-the-middle attackers to intercept or m...

Jan 22, 2026
CVE-2025-14819
5.3

A TLS certificate validation vulnerability in libcurl where reusing easy or multi handles with altered CURLSSLOPT_NO_PARTIALCHAIN options could cause ...

Jan 8, 2026
CVE-2025-12047
5.3

A vulnerability in Lenovo Scanner Pro application allows attackers on the same logical network to access sensitive user files. This affects users of L...

Nov 12, 2025
CVE-2025-33142
5.3

IBM WebSphere Application Server 8.5 and 9.0 have a TLS security weakness that could allow attackers to downgrade or weaken TLS connections. This affe...

Aug 14, 2025
CVE-2025-32989
5.3

A heap-buffer-overread vulnerability in GnuTLS allows attackers to create malicious certificates with malformed Certificate Transparency extensions th...

Jul 10, 2025
CVE-2024-28067
5.3

This vulnerability in Samsung Exynos Modem 5300 allows a Man-in-the-Middle attacker to downgrade the security mode of packets, enabling the attacker t...

Jul 9, 2024
CVE-2023-0465
5.3

This vulnerability allows malicious Certificate Authorities to bypass certificate policy checks by including invalid policies in leaf certificates. Wh...

Mar 28, 2023
CVE-2025-60022
4.8

This CVE describes an improper certificate validation vulnerability in the 'デジラをプγƒͺ' iOS app. Attackers can perform man-in-the-middle attac...

Nov 17, 2025
CVE-2025-30669
4.8

This vulnerability in Zoom Clients involves improper certificate validation that could allow an unauthenticated attacker on the same network to potent...

Nov 13, 2025
CVE-2025-58781
4.8

The WTW-EAGLE mobile app fails to properly validate SSL/TLS server certificates, allowing man-in-the-middle attackers to intercept and decrypt encrypt...

Sep 12, 2025
CVE-2025-58125
4.8

CVE-2025-58125 is an improper certificate validation vulnerability in the Checkmk Exchange plugin Freebox v6 agent. Attackers in a man-in-the-middle p...

Aug 28, 2025
CVE-2025-58127
4.8

This vulnerability allows attackers in a man-in-the-middle position to intercept traffic between Checkmk and Dell PowerScale systems due to improper c...

Aug 28, 2025
CVE-2025-58123
4.8

CVE-2025-58123 is an improper certificate validation vulnerability in the Checkmk Exchange BGP Monitoring plugin. Attackers in a man-in-the-middle pos...

Aug 28, 2025
CVE-2023-48785
4.8

This vulnerability allows remote unauthenticated attackers to perform man-in-the-middle attacks on HTTPS communications between FortiOS devices and Fo...

Mar 14, 2025
CVE-2024-40590
4.8

This vulnerability allows man-in-the-middle attackers to intercept and tamper with encrypted communications between FortiPortal and FortiManager/Forti...

Mar 14, 2025
CVE-2024-33509
4.8

This vulnerability allows a man-in-the-middle attacker to intercept and manipulate communications between FortiWeb WAF devices and external data sourc...

Jul 9, 2024
CVE-2024-31340
4.8

This vulnerability in TP-Link Tether and Tapo mobile apps allows remote attackers to intercept encrypted communications via man-in-the-middle attacks ...

May 22, 2024
CVE-2025-52919
4.3

This vulnerability in Yealink RPS (Remote Provisioning Service) allows attackers to upload invalid certificates due to insufficient content validation...

Jun 21, 2025
CVE-2024-10445
4.3

This CVE describes an improper certificate validation vulnerability in Synology BeeStation OS and DiskStation Manager update functionality. It allows ...

Mar 19, 2025
CVE-2024-48460
4.3

A vulnerability in Eugeny Tabby terminal emulator version 1.0.213 allows remote attackers to capture SSH credentials when connecting to malicious serv...

Jan 16, 2025
CVE-2024-5918
4.3

An improper certificate validation vulnerability in Palo Alto Networks PAN-OS allows an authorized user with a specially crafted client certificate to...

Nov 14, 2024
CVE-2025-12893
4.2

This CVE describes a TLS certificate validation bypass vulnerability in MongoDB servers. On Windows and Apple systems, MongoDB may accept client certi...

Nov 25, 2025
CVE-2025-35434
4.2

CISA Thorium versions before 1.1.2 fail to validate TLS certificates when connecting to Elasticsearch, allowing man-in-the-middle attacks. An unauthen...

Sep 17, 2025
CVE-2024-52510
4.2

The Nextcloud Desktop Client vulnerability allows attackers to bypass signature validation when a manipulated server sends an empty initial signature....

Nov 15, 2024

About CWE-295 (CWE-295)

Our database tracks 261 CVEs classified as CWE-295, with 38 rated critical and 147 rated high severity. The average CVSS score for CWE-295 vulnerabilities is 7.4.

External reference: View CWE-295 on MITRE CWE →

Monitor CWE-295 Vulnerabilities

Get alerted when new CWE-295 CVEs affect your infrastructure.

Start Monitoring Free