CWE-295
Improper Certificate Validation
MITRENo catalog description on file. The MITRE CWE site has the canonical reference.
Recent CVEs
showing 28 of 28- CVE-2020-0601High· 8.1KEVEXPLOITEPSS 94%22 h ago
Microsoft Windows CryptoAPI Spoofing Vulnerability
- CVE-2022-26923High· 8.8KEVEXPLOITEPSS 92%22 h ago
Microsoft Active Directory Domain Services Privilege Escalation Vulnerability
- CVE-2023-41991Medium· 5.5KEVEPSS 4%22 h ago
Apple Multiple Products Improper Certificate Validation Vulnerability
- CVE-2023-20963High· 7.8KEVEPSS 1%22 h ago
Android Framework Privilege Escalation Vulnerability
- CVE-2026-45170—EPSS 0%23 h ago
Idira Privilege Cloud Connector versions prior 1.1.100504 under specific conditions and configuration scenarios, TLS certificate validation may not be fully enforced. CyberArk Security Bulletin: CA26-17
- CVE-2026-45175—EPSS 0%1 d ago
Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within internal agent validation processes. A local attacker could potentially bypass built-in security controls or cryptographic validations. Und
- CVE-2026-40992Medium· 5.0EPSS 0%1 d ago
Spring Boot's Mail auto-configuration does not enable hostname verification. Applications that set the relevant JavaMail property, such as spring.mail.properties.mail.smtp.ssl.checkserveridentity=true, are not affected. Affected versions:
- CVE-2026-9758High· 7.3EPSS 0%2 d ago
Improper comparison with the certificates trusted list in S2OPC allows an attacker well-formed untrusted certificate to be considered trusted
- CVE-2026-53475Critical· 9.3EPSS 0%2 d ago
A flaw was found in assisted-migration-agent. The application hardcodes insecure Transport Layer Security (TLS) connections when communicating with vCenter. This vulnerability allows a Man-in-the-Middle (MITM) attacker to intercept and harv
- CVE-2026-41714Medium· 4.0EPSS 0%2 d ago
Applications that configure their broker connection via RabbitConnectionFactoryBean.setUri("amqps://...") without also calling setUseSSL(true) get TLS encryption with no certificate validation and no hostname verification. Affected version
- CVE-2026-42769Medium· 5.3EPSS 0%3 d ago
Issue Summary: An error in the callback used to verify the certificate provided in a Root CA key update Certificate Management Protocol (CMP) message response rendered the certificate validation ineffectual, which could lead to escalation o
- CVE-2025-24471Medium· 6.5EPSS 0%4 d ago
An Improper Certificate Validation vulnerability [CWE-295] in FortiOS version 7.6.1 and below, version 7.4.7 and below may allow an EAP verified remote user to connect from FortiClient via revoked certificate.
- CVE-2026-45745High· 8.0EPSS 0%5 d ago
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Starting in version 1.7.0, Termix Desktop (Electron) disables TLS certificate validation, allowing a machine-in-the-middle attacke
- CVE-2026-50752High· 7.4EPSS 0%5 d ago
A weakness in the certificate validation logic of the deprecated IKEv1 key exchange may allow an unauthenticated attacker positioned as a man-in-the-middle to bypass certificate validation in VPN site-to-site connections that use certificat
- CVE-2017-2784High· 8.1EPSS 1%7 d ago
An exploitable free of a stack pointer vulnerability exists in the x509 certificate parsing code of ARM mbed TLS before 1.3.19, 2.x before 2.1.7, and 2.4.x before 2.4.2. A specially crafted x509 certificate, when parsed by mbed TLS library,
- CVE-2026-25834Medium· 6.5EPSS 0%7 d ago
Mbed TLS v3.3.0 up to 3.6.5 and 4.0.0 allows Algorithm Downgrade.
- CVE-2024-45159Critical· 9.8EPSS 1%7 d ago
An issue was discovered in Mbed TLS 3.x before 3.6.1. With TLS 1.3, when a server enables optional authentication of the client, if the client-provided certificate does not have appropriate values in if keyUsage or extKeyUsage extensions, t
- CVE-2025-14819Low· 5.3EPSS 0%25 d ago
curl/libcurl: OpenSSL partial chain store policy bypass
curl - CVE-2026-7009Medium· 5.3EPSS 0%2026-04-29
curl/libcurl: OCSP stapling bypass with Apple SecTrust
curl - CVE-2024-2379Low· 6.3EPSS 0%2026-04-25
curl/libcurl: QUIC certificate check bypass with wolfSSL
curl - CVE-2016-9952Medium· 8.1EPSS 0%2026-04-25
curl/libcurl: Win CE Schannel cert wildcard matches too much
curl - CVE-2023-28321Low· 5.9EPSS 0%2026-04-25
curl/libcurl: IDN wildcard match
curl - CVE-2021-22924Medium· 3.7EPSS 1%2026-04-25
curl/libcurl: Bad connection reuse due to flawed path name checks
curl - CVE-2025-4947Medium· 6.5EPSS 0%2026-04-25
curl/libcurl: QUIC certificate check skip with wolfSSL
curl - CVE-2021-22926Medium· 7.5EPSS 1%2026-04-25
curl/libcurl: CURLOPT_SSLCERT mix-up with Secure Transport
curl - CVE-2025-5025Medium· 4.8EPSS 0%2026-04-25
curl/libcurl: No QUIC certificate pinning with wolfSSL
curl - CVE-2024-8096Medium· 6.5EPSS 1%2026-04-25
curl/libcurl: OCSP stapling bypass with GnuTLS
curl - CVE-2025-13034Medium· 5.9EPSS 0%2026-04-25
curl/libcurl: No QUIC certificate pinning with GnuTLS
curl
CWE catalog data sourced from MITRE. CVE associations come from NVD weakness mappings; some CVEs carry multiple CWEs.