← Back
CWE-295

1,533 CVEs • Abstraction: Base

Improper Certificate Validation

The product does not validate, or incorrectly validates, a certificate.

JSON object

Loading...

CVEs (1,533)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Atlassian
1Hipchat
May 13, 2026
May 5, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Acceptance of invalid/self-signed TLS certificates in Atlassian HipChat before 3.16.2 for iOS allows a man-in-the-middle and/or physically proximate attacker to silently intercept information sent during the login API ca...Show more
Acceptance of invalid/self-signed TLS certificates in Atlassian HipChat before 3.16.2 for iOS allows a man-in-the-middle and/or physically proximate attacker to silently intercept information sent during the login API call.Show less
121st Century Insurance
121st Century Insurance
May 13, 2026
May 5, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The 21st Century Insurance app 10.0.0 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
1Banco De Costa Rica
1Bcr Movil
May 13, 2026
May 5, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The Banco de Costa Rica BCR Movil app 3.7 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
1America's First Federal Credit Union
1America's First Fcu Mobile Banking
May 13, 2026
May 5, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The America's First Federal Credit Union (FCU) Mobile Banking app 3.1.0 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive informat...Show more
The America's First Federal Credit Union (FCU) Mobile Banking app 3.1.0 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.Show less
1Emirates Nbd Bank P.j.s.c
2Emirates Nbd
Emirates Nbd Ksa
May 13, 2026
May 5, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The Emirates NBD Bank P.J.S.C Emirates NBD KSA app 3.10.0 through 3.10.4 (UAE) and 2.0.1 through 2.1.0 (KSA) for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof...Show more
The Emirates NBD Bank P.J.S.C Emirates NBD KSA app 3.10.0 through 3.10.4 (UAE) and 2.0.1 through 2.1.0 (KSA) for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.Show less
1Dotit Corp
1Banque Zitouna
May 13, 2026
May 5, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The DOT IT Banque Zitouna app 2.1 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
1Forex
1Tradeking Forex
May 13, 2026
May 5, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The TradeKing Forex for iPhone app 1.2.1 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
1Forex
1Forextrader
May 13, 2026
May 5, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The FOREX.com FOREXTrader for iPhone app 2.9.12 through 2.9.14 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a...Show more
The FOREX.com FOREXTrader for iPhone app 2.9.12 through 2.9.14 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.Show less
1Banco Santander Mexico Sa
1Supermovil
May 13, 2026
May 5, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The Banco Santander Mexico SA Supermovil app 3.5 through 3.7 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a c...Show more
The Banco Santander Mexico SA Supermovil app 3.5 through 3.7 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.Show less
1Electronic Funds Source Llc
1Efs Mobile Driver Source
May 13, 2026
May 5, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The Electronic Funds Source (EFS) Mobile Driver Source app 2.5 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a...Show more
The Electronic Funds Source (EFS) Mobile Driver Source app 2.5 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.Show less
1Great Southern Bank
1Great Southern Mobile Banking
May 13, 2026
May 5, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The Great Southern Bank Great Southern Mobile Banking app before 4.0.4 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive informati...Show more
The Great Southern Bank Great Southern Mobile Banking app before 4.0.4 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.Show less
1Everyday Health Inc
1Diabetes In Check\
May 13, 2026
May 5, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The Everyday Health Diabetes in Check: Blood Glucose & Carb Tracker app 3.4.2 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive in...Show more
The Everyday Health Diabetes in Check: Blood Glucose & Carb Tracker app 3.4.2 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.Show less
1Dollar Bank
1Dollar Bank Mobile
May 13, 2026
May 5, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The Dollar Bank Mobile app 2.6.3 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
1Payquicker
1Mypayquicker
May 13, 2026
May 5, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The PayQuicker app 1.0.0 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
1State Bank Of India
1State Bank Anywhere
May 13, 2026
May 5, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The State Bank of India State Bank Anywhere app 5.1.0 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted...Show more
The State Bank of India State Bank Anywhere app 5.1.0 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.Show less
1Think Mutual Bank
1Think Mutual Bank Mobile Banking App
May 13, 2026
May 5, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The Think Mutual Bank Mobile Banking app 3.1.5 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certifi...Show more
The Think Mutual Bank Mobile Banking app 3.1.5 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.Show less
1Sccu
1Space Coast Credit Union
May 13, 2026
May 5, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The Space Coast Credit Union Mobile app 2.2 for iOS and 2.1.0.1104 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive informati...Show more
The Space Coast Credit Union Mobile app 2.2 for iOS and 2.1.0.1104 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.Show less
1Apache
1Qpid Proton
May 13, 2026
May 2, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The C client and C-based client bindings in the Apache Qpid Proton library before 0.13.1 on Windows do not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltNam...Show more
The C client and C-based client bindings in the Apache Qpid Proton library before 0.13.1 on Windows do not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate when using the SChannel-based security layer, which allows man-in-the-middle attackers to spoof servers via an arbitrary valid certificate.Show less
1Nissan Securities
1Access Cx
May 13, 2026
Apr 28, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The Access CX App for Android prior to 2.0.0.1 and for iOS prior to 2.0.2 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information vi...Show more
The Access CX App for Android prior to 2.0.0.1 and for iOS prior to 2.0.2 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.Show less
1Cybozu
1Remote Service Manager
May 13, 2026
Apr 28, 2017
N/A· v4
4.2 MEDIUM· v3
4.9 MEDIUM· v2
Remote Service Manager 3.0.0 to 3.1.4 fails to verify client certificates, which may allow remote attackers to gain access to systems on the network.