Skip to main content

CWE archive

CWE-295 CVEs

Programmatic archive

1,446 CVEs tagged with CWE-295136 Critical, 571 High, 676 Medium, 63 Low, 0 Unrated.

CVE-2025-61778

Published Oct 6, 2025

Akka.NET is a .NET port of the Akka project from the Scala / Java community. In all versions of Akka.Remote from v1.2.0 to v1.5.51, TLS could be enabled via our `akka.remote.dot-n…

CVSS 9.3 · Critical

CVE-2025-10548

Published Sep 23, 2025

The CleverControl employee monitoring software (v11.5.1041.6) fails to validate TLS server certificates during the installation process. The installer downloads and executes exter…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2024-13990

Published Sep 19, 2025

MicroWorld eScan AV's update mechanism failed to ensure authenticity and integrity of updates: update packages were delivered and accepted without robust cryptographic verificatio…

CVSS 9.3 · Critical

CVE-2025-59353

Published Sep 17, 2025

Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, a peer can obtain a valid TLS certificate for arbitrary IP addresses, effect…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2025-59347

Published Sep 17, 2025

Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, The Manager disables TLS certificate verification in HTTP clients. The clien…

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-35434

Published Sep 17, 2025

CISA Thorium does not validate TLS certificates when connecting to Elasticsearch. An unauthenticated attacker with access to a Thorium cluster could impersonate the Elasticsearch…

CVSS 2.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-9708

Published Sep 16, 2025

A vulnerability exists in the Kubernetes C# client where the certificate validation logic accepts properly constructed certificates from any Certificate Authority (CA) without pro…

CVSS 6.8 · Medium

CVE-2025-55109

Published Sep 16, 2025

An authentication bypass vulnerability exists in the out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 and potentially earlier unsupported versions when using an empty or d…

CVSS 9.5 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-50944

Published Sep 15, 2025

An issue was discovered in the method push.lite.avtech.com.MySSLSocketFactoryNew.checkServerTrusted in AVTECH EagleEyes 2.0.0. The custom X509TrustManager used in checkServerTrust…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-58781

Published Sep 12, 2025

WTW-EAGLE App does not properly validate server certificates, which may allow a man-in-the-middle attacker to monitor encrypted traffic.

CVSS 6.3 · Medium

CVE-2025-9785

Published Sep 3, 2025

PaperCut Print Deploy is an optional component that integrates with PaperCut NG/MF which simplifies printer deployment and management. When the component is deployed to an environ…

CVSS 7.7 · High

CVE-2025-33099

Published Sep 1, 2025

IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to perform unauthorized actions using man in the middle techniques due to improper certificate validation.

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-30278

Published Aug 29, 2025

An improper certificate validation vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to c…

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2025-30277

Published Aug 29, 2025

An improper certificate validation vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to c…

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2025-58127

Published Aug 28, 2025

Improper Certificate Validation in Checkmk Exchange plugin Dell Powerscale allows attackers in MitM position to intercept traffic.

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-58126

Published Aug 28, 2025

Improper Certificate Validation in Checkmk Exchange plugin VMware vSAN allows attackers in MitM position to intercept traffic.

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-58125

Published Aug 28, 2025

Improper Certificate Validation in Checkmk Exchange plugin Freebox v6 agent allows attackers in MitM position to intercept traffic.

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-58123

Published Aug 28, 2025

Improper Certificate Validation in Checkmk Exchange plugin BGP Monitoring allows attackers in MitM position to intercept traffic.

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-7390

Published Aug 21, 2025

A malicious client can bypass the client certificate trust check of an opc.https server when the server endpoint is configured to allow only secure communication.

CVSS 9.1 · Critical

CVE-2025-0309

Published Aug 14, 2025

An insufficient validation on the server connection endpoint in Netskope Client allows local users to elevate privileges on the system. The insufficient validation allows Netskope…

CVSS 6.0 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2025-2183

Published Aug 13, 2025

An insufficient certificate validation issue in the Palo Alto Networks GlobalProtect™ app enables attackers to connect the GlobalProtect app to arbitrary servers. This can enable…

CVSS 5.3 · Medium
Showing 251-275 of 1,446 CVEsPage 11 of 58