Skip to main content

CWE archive

CWE-599 CVEs

Programmatic archive

14 CVEs tagged with CWE-5991 Critical, 8 High, 5 Medium, 0 Low, 0 Unrated.

CVE-2026-62657

Published Jul 14, 2026

A security flaw in the router's certificate validation process was discovered in the NETGEAR XR1000 Gaming Router and certain Nighthawk models that could allow an unauthorized per…

CVSS 4.9 · Medium
evidence mentions
5
Buzz score
27.9

CVE-2026-25060

Published Feb 2, 2026

OpenList Frontend is a UI component for OpenList. Prior to 4.1.10, certificate verification is disabled by default for all storage driver communications. The TlsInsecureSkipVerify…

CVSS 8.1 · High
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2025-63432

Published Nov 24, 2025

Xtooltech Xtool AnyScan Android Application 4.40.40 and prior is Missing SSL Certificate Validation. The application fails to properly validate the TLS certificate from its update…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-56232

Published Nov 5, 2025

GOG Galaxy 2.0.0.2 suffers from Missing SSL Certificate Validation. An attacker who controls the local network, DNS, or a proxy can perform a man-in-the-middle (MitM) attack to in…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-56230

Published Nov 4, 2025

Tencent Docs Desktop 3.9.20 and earlier suffers from Missing SSL Certificate Validation in the update component.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-56146

Published Sep 23, 2025

Indian Bank IndSMART Android App 3.8.1 is vulnerable to Missing SSL Certificate Validation in NuWebViewActivity.

CVSS 5.3 · Medium

CVE-2024-41265

Published Aug 1, 2024

A TLS certificate verification issue discovered in cortex v0.42.1 allows attackers to obtain sensitive information via the makeOperatorRequest function.

CVSS 7.5 · High

CVE-2024-41253

Published Jul 31, 2024

goframe v2.7.2 is configured to skip TLS certificate verification, possibly allowing attackers to execute a man-in-the-middle attack via the gclient component.

CVSS 7.1 · High

CVE-2024-40464

Published Jul 31, 2024

An issue in beego v.2.2.0 and before allows a remote attacker to escalate privileges via the sendMail function located in beego/core/logs/smtp.go file

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-36755

Published Jun 27, 2024

D-Link DIR-1950 up to v1.11B03 does not validate SSL certificates when requesting the latest firmware version and downloading URL. This can allow attackers to downgrade the firmwa…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-48052

Published Nov 16, 2023

Missing SSL certificate validation in HTTPie v3.2.2 allows attackers to eavesdrop on communications between the host and server via a man-in-the-middle attack.

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2021-21374

Published Mar 26, 2021

Nimble is a package manager for the Nim programming language. In Nim release versions before versions 1.2.10 and 1.4.4, "nimble refresh" fetches a list of Nimble packages over HTT…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort
Showing 1-14 of 14 CVEsPage 1 of 1