Skip to main content

CWE archive

CWE-295 CVEs

Programmatic archive

1,448 CVEs tagged with CWE-295137 Critical, 572 High, 676 Medium, 63 Low, 0 Unrated.

CVE-2025-39205

Published Jun 24, 2025

A vulnerability exists in the IEC 61850 in MicroSCADA X SYS600 product. The certificate validation of the TLS protocol allows remote Man-in-the-Middle attack due to missing proper…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-52919

Published Jun 21, 2025

In Yealink RPS before 2025-05-26, the certificate upload function does not properly validate certificate content, potentially allowing invalid certificates to be uploaded.

CVSS 4.3 · Medium

CVE-2025-24471

Published Jun 10, 2025

An Improper Certificate Validation vulnerability [CWE-295] in FortiOS version 7.6.1 and below, version 7.4.7 and below may allow an EAP verified remote user to connect from FortiC…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-33031

Published Jun 6, 2025

An improper certificate validation vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to…

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2025-30279

Published Jun 6, 2025

An improper certificate validation vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to…

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2025-29885

Published Jun 6, 2025

An improper certificate validation vulnerability has been reported to affect File Station 5. If exploited, the vulnerability could allow remote attackers who have gained user acce…

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2025-29884

Published Jun 6, 2025

An improper certificate validation vulnerability has been reported to affect File Station 5. If exploited, the vulnerability could allow remote attackers who have gained user acce…

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2025-29883

Published Jun 6, 2025

An improper certificate validation vulnerability has been reported to affect File Station 5. If exploited, the vulnerability could allow remote attackers who have gained user acce…

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2025-22486

Published Jun 6, 2025

An improper certificate validation vulnerability has been reported to affect File Station 5. If exploited, the vulnerability could allow remote attackers who have gained user acce…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-5025

Published May 28, 2025

libcurl supports *pinning* of the server certificate public key for HTTPS transfers. Due to an omission, this check is not performed when connecting with QUIC for HTTP/3, when the…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-4947

Published May 28, 2025

libcurl accidentally skips the certificate verification for QUIC connections when connecting to a host specified as an IP address in the URL. Therefore, it does not detect imposto…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-5279

Published May 27, 2025

When the Amazon Redshift Python Connector is configured with the BrowserAzureOAuth2CredentialsProvider plugin, the driver skips the SSL certificate validation step for the Identit…

CVSS 7.0 · High

CVE-2024-13956

Published May 22, 2025

SSL Verification Bypass vulnerabilities exist in ASPECT if administrator credentials become compromisedThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*…

CVSS 8.8 · High

CVE-2025-4575

Published May 22, 2025

Issue summary: Use of -addreject option with the openssl x509 application adds a trusted use instead of a rejected use for a certificate. Impact summary: If a user intends to mak…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-32407

Published May 16, 2025

Samsung Internet for Galaxy Watch version 5.0.9, available up until Samsung Galaxy Watch 3, does not properly validate TLS certificates, allowing for an attacker to impersonate an…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-3463

Published May 9, 2025

"This issue is limited to motherboards and does not affect laptops, desktop computers, or other endpoints." An insufficient validation vulnerability in ASUS DriverHub may allow un…

CVSS 9.4 · Critical
evidence mentions
2
Buzz score
17.5

CVE-2025-20157

Published May 7, 2025

A vulnerability in certificate validation processing of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an unauthenticated, remote attacker to gain acces…

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-46551

Published May 7, 2025

JRuby-OpenSSL is an add-on gem for JRuby that emulates the Ruby OpenSSL native library. Starting in JRuby-OpenSSL version 0.12.1 and prior to version 0.15.4 (corresponding to JRub…

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-3218

Published May 7, 2025

IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 is vulnerable to authentication and authorization attacks due to incorrect validation processing in IBM i Netserver. A malicious actor could use…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-37730

Published May 6, 2025

Improper certificate validation in Logstash's TCP output could lead to a man-in-the-middle (MitM) attack in “client” mode, as hostname verification in TCP output was not being per…

CVSS 6.5 · Medium
Showing 301-325 of 1,448 CVEsPage 13 of 58