← Back
CWE-295

1,445 CVEs • Abstraction: Base

Improper Certificate Validation

The product does not validate, or incorrectly validates, a certificate.

JSON object

Loading...

CVEs (1,445)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Puma
1Pumatrac
May 13, 2026
May 15, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The PUMA PUMATRAC app 3.0.2 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
1Yottamark Inc.
1Shopwell Healthy Diet & Grocery Food Scanner
May 13, 2026
May 15, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The YottaMark ShopWell - Healthy Diet & Grocery Food Scanner app 5.3.7 through 5.4.2 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensi...Show more
The YottaMark ShopWell - Healthy Diet & Grocery Food Scanner app 5.3.7 through 5.4.2 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.Show less
1Interval International
1Interval International
May 13, 2026
May 15, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The Interval International app 3.3 through 3.5.1 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certi...Show more
The Interval International app 3.3 through 3.5.1 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.Show less
1Zipongo Inc.
1Healthy Recipes And Grocery Deals
May 13, 2026
May 15, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The Zipongo - Healthy Recipes and Grocery Deals app before 6.3 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a...Show more
The Zipongo - Healthy Recipes and Grocery Deals app before 6.3 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.Show less
1Warnerbros
1Ellentube
May 13, 2026
May 15, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The Warner Bros. ellentube app 3.1.1 through 3.1.3 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted cer...Show more
The Warner Bros. ellentube app 3.1.1 through 3.1.3 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.Show less
1Radiojavan
1Radio Javan
May 13, 2026
May 15, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The Radio Javan app 9.3.4 through 9.6.1 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
1Life Before Us
1Yo.
May 13, 2026
May 15, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The Life Before Us Yo app 2.5.8 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
1Changyou
1Dolphin Web Browser
May 13, 2026
May 15, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The MoboTap Dolphin Web Browser - Fast Private Internet Search app 9.23.0 through 9.23.2 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain s...Show more
The MoboTap Dolphin Web Browser - Fast Private Internet Search app 9.23.0 through 9.23.2 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.Show less
1Gocivix
1Indiana Voters
May 13, 2026
May 15, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The Quest Information Systems Indiana Voters app 1.1.24 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafte...Show more
The Quest Information Systems Indiana Voters app 1.1.24 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.Show less
1Microsoft
1.net Framework
May 13, 2026
May 12, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to bypass Enhanced Security Usage taggings when they present a certificate that is invalid for a specific use, aka ".NET Securi...Show more
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to bypass Enhanced Security Usage taggings when they present a certificate that is invalid for a specific use, aka ".NET Security Feature Bypass Vulnerability."Show less
1Watchguard
1Panda Mobile Security
May 13, 2026
May 5, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Acceptance of invalid/self-signed TLS certificates in "Panda Mobile Security" 1.1 for iOS allows a man-in-the-middle and/or physically proximate attacker to silently intercept information sent during the login API call.
1Foxitsoftware
1Foxit Pdf
May 13, 2026
May 5, 2017
N/A· v4
8.1 HIGH· v3
4.3 MEDIUM· v2
Acceptance of invalid/self-signed TLS certificates in "Foxit PDF - PDF reader, editor, form, signature" before 5.4 for iOS allows a man-in-the-middle and/or physically proximate attacker to silently intercept login infor...Show more
Acceptance of invalid/self-signed TLS certificates in "Foxit PDF - PDF reader, editor, form, signature" before 5.4 for iOS allows a man-in-the-middle and/or physically proximate attacker to silently intercept login information (username/password), in addition to the static authentication token if the user is already logged in.Show less
1Atlassian
1Hipchat
May 13, 2026
May 5, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Acceptance of invalid/self-signed TLS certificates in Atlassian HipChat before 3.16.2 for iOS allows a man-in-the-middle and/or physically proximate attacker to silently intercept information sent during the login API ca...Show more
Acceptance of invalid/self-signed TLS certificates in Atlassian HipChat before 3.16.2 for iOS allows a man-in-the-middle and/or physically proximate attacker to silently intercept information sent during the login API call.Show less
121st Century Insurance
121st Century Insurance
May 13, 2026
May 5, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The 21st Century Insurance app 10.0.0 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
1Banco De Costa Rica
1Bcr Movil
May 13, 2026
May 5, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The Banco de Costa Rica BCR Movil app 3.7 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
1America's First Federal Credit Union
1America's First Fcu Mobile Banking
May 13, 2026
May 5, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The America's First Federal Credit Union (FCU) Mobile Banking app 3.1.0 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive informat...Show more
The America's First Federal Credit Union (FCU) Mobile Banking app 3.1.0 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.Show less
1Emirates Nbd Bank P.j.s.c
2Emirates Nbd
Emirates Nbd Ksa
May 13, 2026
May 5, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The Emirates NBD Bank P.J.S.C Emirates NBD KSA app 3.10.0 through 3.10.4 (UAE) and 2.0.1 through 2.1.0 (KSA) for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof...Show more
The Emirates NBD Bank P.J.S.C Emirates NBD KSA app 3.10.0 through 3.10.4 (UAE) and 2.0.1 through 2.1.0 (KSA) for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.Show less
1Dotit Corp
1Banque Zitouna
May 13, 2026
May 5, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The DOT IT Banque Zitouna app 2.1 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
1Forex
1Tradeking Forex
May 13, 2026
May 5, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The TradeKing Forex for iPhone app 1.2.1 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
1Forex
1Forextrader
May 13, 2026
May 5, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The FOREX.com FOREXTrader for iPhone app 2.9.12 through 2.9.14 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a...Show more
The FOREX.com FOREXTrader for iPhone app 2.9.12 through 2.9.14 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.Show less