Skip to main content

CWE archive

CWE-295 CVEs

Programmatic archive

1,454 CVEs tagged with CWE-295137 Critical, 575 High, 679 Medium, 63 Low, 0 Unrated.

CVE-2026-18141

Published Jul 31, 2026

A flaw was found in aap-gateway, a component of Ansible Automation Platform's Event-Driven Ansible (EDA). An unauthenticated remote attacker can bypass mutual Transport Layer Secu…

CVSS 8.2 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-8497

Published Jul 29, 2026

Improper certificate validation in the Devolutions Server connection handling in Devolutions Password Manager 2026.2.1.0 and earlier on Android, iOS, and macOS allows an adjacent-…

CVSS 7.4 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-18257

Published Jul 29, 2026

Improper validity period check for root issuer certificate in CycloneCrypto cryptographic wrapper of S2OPC allows a certificate issued by this root issuer to be considered trusted

CVSS 5.6 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-58162

Published Jul 29, 2026

The Apache Traffic Server certifier plugin generates certificates based on attacker-controlled client SNI. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, fro…

CVSS 8.4 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-65325

Published Jul 29, 2026

Apache Traffic Server reuses multiplexed HTTP/2 origin connections without verifying the server certificate covers the new request hostname. This issue affects Apache Traffic Ser…

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-16107

Published Jul 28, 2026

IBM TS4500 CLI tool Versions:  0.1.31 through 1.12.0.0 does not validate or improperly validates TLS certificate validation, which could allow an attacker to obtain sensitive info…

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-54342

Published Jul 24, 2026

In epa4all, prior to version 2026-05-20, an attacker on the network path between epa4all and any backend (ePA Aktensystem, Konnektor, IDP, TSS) can present a self-signed TLS certi…

CVSS 8.1 · High
evidence mentions
4
Buzz score
26.1

CVE-2026-48021

Published Jul 24, 2026

In epa4all, prior to version 2026-05-20, an attacker who can intercept the TLS connection between epa4all and the ePA backend can complete the VAU handshake with attacker-controll…

CVSS 9.1 · Critical
evidence mentions
3
Buzz score
23.9

CVE-2026-52688

Published Jul 23, 2026

RRSIGs with too few labels can lead to bypass of DNSSEC wildcard validation

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-56820

Published Jul 21, 2026

Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and prior to 4.1.135.Final, `OcspClient` doe…

CVSS 7.4 · High
evidence mentions
5
Buzz score
22.9
Vendor/product tagsBeta · best-effort

CVE-2026-56624

Published Jul 20, 2026

Improper certificate validation in Apache MINA SSHD (server-side). Apache MINA SSHD is a Java library for client-side and server-side SSH. Server-side OpenSSH user certificate…

CVSS 7.3 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-46428

Published Jul 20, 2026

lettre is a a mailer library for Rust. Starting in version 0.10.1 and prior to version 0.11.22, an inverted-boolean bug in lettre's `boring-tls` integration silently disables TLS…

CVSS 9.1 · Critical
evidence mentions
4
Buzz score
22.6

CVE-2026-13410

Published Jul 17, 2026

Dancer::Plugin::Auth::Google versions through 0.07 for Perl have TLS verification disabled. The default user agent is initialised with SSL_verify_mode explicitly disabled. An at…

CVSS 8.2 · High
evidence mentions
4
Buzz score
32.6

CVE-2026-38974

Published Jul 15, 2026

Dulwich through 1.1.0 was found to be missing SSH host key verification in contrib/paramiko_vendor.py.

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-13385

Published Jul 15, 2026

An Improper Validation of Integrity Check Value and Improper Certificate Validation in certain ASUS router models allows a remote man-in-the-middle(MITM) user to make the router d…

CVSS 9.5 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-59836

Published Jul 14, 2026

A improper certificate validation vulnerability in Fortinet FortiClientEMS 7.4.3 through 7.4.5, FortiClientEMS 7.4.0 through 7.4.1, FortiClientEMS 7.2 all versions may allow attac…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-15683

Published Jul 13, 2026

Lorex 2K Indoor Wi-Fi Security Camera Device Management Server Improper Certificate Validation Vulnerability. This vulnerability allows network-adjacent attackers to execute arbit…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-22093

Published Jul 13, 2026

The EVbee Service Android app uses TLS encrypted communication (HTTPS), but does not validate the certificate provided by the server. This allows an attacker on the network path b…

CVSS 9.5 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-54919

Published Jul 10, 2026

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. In affected Mbed TLS backend versions from 0.31.0 through 0.46.1 and wolfSSL backend versions fro…

CVSS 7.4 · High
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-59818

Published Jul 8, 2026

etcd is a distributed key-value store for the data of a distributed system. Prior to 3.5.32 and 3.6.13, when etcd is configured with --listen-client-http-urls to split HTTP and gR…

CVSS 6.5 · Medium
evidence mentions
10
Buzz score
34.0
Vendor/product tagsBeta · best-effort
Showing 1-25 of 1,454 CVEsPage 1 of 59