CWE-295: CWE-295

264
Total CVEs
39
Critical
149
High
7.4
Avg CVSS

Yearly Trend

2026
39
2025
90
2024
48
2023
31
2022
19

Top Affected Vendors

1 Ibm 10
2 Debian 8
3 Fortinet 7
4 Google 7
5 Libreoffice 6
6 Qnap 6
7 Fedoraproject 5
8 Dell 5
9 Hashicorp 5
10 Asustor 5

All CWE-295 CVEs (264)

CVE-2025-12893
4.2

This CVE describes a TLS certificate validation bypass vulnerability in MongoDB servers. On Windows and Apple systems, MongoDB may accept client certi...

Nov 25, 2025
CVE-2025-35434
4.2

CISA Thorium versions before 1.1.2 fail to validate TLS certificates when connecting to Elasticsearch, allowing man-in-the-middle attacks. An unauthen...

Sep 17, 2025
CVE-2024-52510
4.2

The Nextcloud Desktop Client vulnerability allows attackers to bypass signature validation when a manipulated server sends an empty initial signature....

Nov 15, 2024
CVE-2025-0239
4.0

This vulnerability allows attackers to bypass certificate validation when Firefox or Thunderbird redirects from a secure server to an insecure one usi...

Jan 7, 2025
CVE-2025-15323
3.7

Tanium Appliance has an improper certificate validation vulnerability that could allow man-in-the-middle attacks or spoofing of trusted servers. This ...

Feb 5, 2026
CVE-2026-24934
3.7

This CVE describes an insecure DDNS implementation in ASUSTOR ADM software where HTTP connections lack SSL/TLS certificate validation. Unauthenticated...

Feb 3, 2026
CVE-2025-53869
3.7

This vulnerability affects Brother MFP devices that fail to properly validate server certificates, allowing man-in-the-middle attackers to replace roo...

Jan 29, 2026
CVE-2025-52598
3.7

This vulnerability allows man-in-the-middle attacks against Hanwha Vision cameras due to missing certificate validation in the client service. Attacke...

Dec 26, 2025
CVE-2025-69412
3.4

KDE messagelib versions before 25.11.90 ignore SSL certificate validation errors when contacting Google's Safe Browsing Lookup API, potentially allowi...

Jan 1, 2026
CVE-2025-65083
3.2

GoSign Desktop versions through 2.4.1 disable TLS certificate validation when configured to use a proxy server, allowing man-in-the-middle attacks tha...

Nov 17, 2025
CVE-2026-22250
2.5

CVE-2026-22250 is a vulnerability in the wlc Weblate command-line client where SSL certificate verification can be bypassed for certain crafted URLs. ...

Jan 12, 2026
CVE-2026-0872
N/A

This vulnerability allows attackers to spoof digital signatures by exploiting improper certificate validation in Thales SafeNet Agent for Windows Logo...

Feb 13, 2026
CVE-2025-9293
N/A

This vulnerability allows attackers to intercept or modify TLS-encrypted communications by exploiting improper certificate validation. Applications us...

Feb 13, 2026
CVE-2026-0228
N/A

This vulnerability in PAN-OS allows Windows Terminal Server Agents to connect using expired certificates even when the system is configured to reject ...

Feb 11, 2026

About CWE-295 (CWE-295)

Our database tracks 264 CVEs classified as CWE-295, with 39 rated critical and 149 rated high severity. The average CVSS score for CWE-295 vulnerabilities is 7.4.

External reference: View CWE-295 on MITRE CWE →

Monitor CWE-295 Vulnerabilities

Get alerted when new CWE-295 CVEs affect your infrastructure.

Start Monitoring Free