Skip to main content

CWE archive

CWE-295 CVEs

Programmatic archive

1,448 CVEs tagged with CWE-295137 Critical, 572 High, 676 Medium, 63 Low, 0 Unrated.

CVE-2025-0309

Published Aug 14, 2025

An insufficient validation on the server connection endpoint in Netskope Client allows local users to elevate privileges on the system. The insufficient validation allows Netskope…

CVSS 6.0 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2025-2183

Published Aug 13, 2025

An insufficient certificate validation issue in the Palo Alto Networks GlobalProtect™ app enables attackers to connect the GlobalProtect app to arbitrary servers. This can enable…

CVSS 5.3 · Medium

CVE-2025-54809

Published Aug 13, 2025

F5 Access for Android before version 3.1.2 which uses HTTPS does not verify the remote endpoint identity. Note: Software versions which have reached End of Technical Support…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-8393

Published Aug 8, 2025

A TLS vulnerability exists in the phone application used to manage a connected device. The phone application accepts self-signed certificates when establishing TLS communication…

CVSS 8.5 · High

CVE-2025-20215

Published Aug 6, 2025

A vulnerability in the meeting-join functionality of Cisco Webex Meetings could have allowed an unauthenticated, network-proximate attacker to complete a meeting-join process in p…

CVSS 5.4 · Medium

CVE-2025-48393

Published Aug 6, 2025

The server identity check mechanism for firmware upgrade performed via command shell is insecurely implemented potentially allowing an attacker to perform a Man-in-the-middle atta…

CVSS 5.7 · Medium

CVE-2025-2028

Published Aug 6, 2025

Lack of TLS validation when downloading a CSV file including mapping from IPs to countries used ONLY for displaying country flags in logs

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-54607

Published Aug 6, 2025

Authentication management vulnerability in the ArkWeb module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2025-44964

Published Aug 5, 2025

A lack of SSL certificate validation in BlueStacks v5.20 allows attackers to execute a man-it-the-middle attack and obtain sensitive information.

CVSS 3.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-6037

Published Aug 1, 2025

Vault and Vault Enterprise (“Vault”) TLS certificate auth method did not correctly validate client certificates when configured with a non-CA certificate as [+trusted certificate+…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-7395

Published Jul 18, 2025

A certificate verification error in wolfSSL when building with the WOLFSSL_SYS_CA_CERTS and WOLFSSL_APPLE_NATIVE_CERT_VALIDATION options results in the wolfSSL client failing to…

CVSS 9.2 · Critical

CVE-2025-30024

Published Jul 11, 2025

The communication protocol used between client and server had a flaw that could be leveraged to execute a man in the middle attack.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-46788

Published Jul 10, 2025

Improper certificate validation in Zoom Workplace for Linux before version 6.4.13 may allow an unauthorized user to conduct an information disclosure via network access.

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2025-35983

Published Jul 10, 2025

Improper Certificate Validation (CWE-295) in the Controller 7000 OneLink implementation could allow an unprivileged attacker to perform a limited denial of service or perform priv…

CVSS 6.5 · Medium

CVE-2024-31854

Published Jul 8, 2025

A vulnerability has been identified in SICAM TOOLBOX II (All versions < V07.11). During establishment of a https connection to the TLS server of a managed device, the affected app…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2024-31853

Published Jul 8, 2025

A vulnerability has been identified in SICAM TOOLBOX II (All versions < V07.11). During establishment of a https connection to the TLS server of a managed device, the affected app…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2025-7095

Published Jul 6, 2025

A vulnerability classified as critical has been found in Comodo Internet Security Premium 12.3.4.8162. This affects an unknown part of the component Update Handler. The manipulati…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-34066

Published Jul 1, 2025

An improper certificate validation vulnerability exists in AVTECH IP cameras, DVRs, and NVRs due to the use of wget with --no-check-certificate in scripts like SyncCloudAccount.sh…

CVSS 8.3 · High

CVE-2025-29331

Published Jun 26, 2025

An issue in MHSanaei 3x-ui before v.2.5.3 and before allows a remote attacker to execute arbitrary code via the management script x-ui passes the no check certificate option to wg…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-6032

Published Jun 24, 2025

A flaw was found in Podman. The podman machine init command fails to verify the TLS certificate when downloading the VM images from an OCI registry. This issue results in a Man In…

CVSS 8.3 · High

CVE-2025-6433

Published Jun 24, 2025

If a user visited a webpage with an invalid TLS certificate, and granted an exception, the webpage was able to provide a WebAuthn challenge that the user would be prompted to comp…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 276-300 of 1,448 CVEsPage 12 of 58