CWE-295: CWE-295
Yearly Trend
Top Affected Vendors
All CWE-295 CVEs (264)
This CVE describes a TLS certificate validation bypass vulnerability in MongoDB servers. On Windows and Apple systems, MongoDB may accept client certi...
Nov 25, 2025CISA Thorium versions before 1.1.2 fail to validate TLS certificates when connecting to Elasticsearch, allowing man-in-the-middle attacks. An unauthen...
Sep 17, 2025The Nextcloud Desktop Client vulnerability allows attackers to bypass signature validation when a manipulated server sends an empty initial signature....
Nov 15, 2024This vulnerability allows attackers to bypass certificate validation when Firefox or Thunderbird redirects from a secure server to an insecure one usi...
Jan 7, 2025Tanium Appliance has an improper certificate validation vulnerability that could allow man-in-the-middle attacks or spoofing of trusted servers. This ...
Feb 5, 2026This CVE describes an insecure DDNS implementation in ASUSTOR ADM software where HTTP connections lack SSL/TLS certificate validation. Unauthenticated...
Feb 3, 2026This vulnerability affects Brother MFP devices that fail to properly validate server certificates, allowing man-in-the-middle attackers to replace roo...
Jan 29, 2026This vulnerability allows man-in-the-middle attacks against Hanwha Vision cameras due to missing certificate validation in the client service. Attacke...
Dec 26, 2025KDE messagelib versions before 25.11.90 ignore SSL certificate validation errors when contacting Google's Safe Browsing Lookup API, potentially allowi...
Jan 1, 2026GoSign Desktop versions through 2.4.1 disable TLS certificate validation when configured to use a proxy server, allowing man-in-the-middle attacks tha...
Nov 17, 2025CVE-2026-22250 is a vulnerability in the wlc Weblate command-line client where SSL certificate verification can be bypassed for certain crafted URLs. ...
Jan 12, 2026This vulnerability allows attackers to spoof digital signatures by exploiting improper certificate validation in Thales SafeNet Agent for Windows Logo...
Feb 13, 2026This vulnerability allows attackers to intercept or modify TLS-encrypted communications by exploiting improper certificate validation. Applications us...
Feb 13, 2026This vulnerability in PAN-OS allows Windows Terminal Server Agents to connect using expired certificates even when the system is configured to reject ...
Feb 11, 2026About CWE-295 (CWE-295)
Our database tracks 264 CVEs classified as CWE-295, with 39 rated critical and 149 rated high severity. The average CVSS score for CWE-295 vulnerabilities is 7.4.
External reference: View CWE-295 on MITRE CWE →
Monitor CWE-295 Vulnerabilities
Get alerted when new CWE-295 CVEs affect your infrastructure.
Start Monitoring Free