CWE-295
1,445 CVEs • Abstraction: Base
Improper Certificate Validation
The product does not validate, or incorrectly validates, a certificate.
CVEs (1,445)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Debian FedoraprojectSaltstack3Debian Linux FedoraSaltJun 17, 2026 Feb 27, 2021 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 In SaltStack Salt before 3002.5, when authenticating to services using certain modules, the SSL certificate is not always validated. |
3Debian FedoraprojectSaltstack3Debian Linux FedoraSaltJun 17, 2026 Feb 27, 2021 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 In SaltStack Salt before 3002.5, authentication to VMware vcenter, vsphere, and esxi servers (in the vmware.py files) does not always validate the SSL/TLS certificate. |
2Fedoraproject Keylime2Fedora KeylimeJun 17, 2026 Feb 25, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A flaw was found in keylime 5.8.1 and older. The issue in the Keylime agent and registrar code invalidates the cryptographic chain of trust from the Endorsement Key certificate to agent attestations. |
2Mongodb Quarkus2Java Driver QuarkusJun 17, 2026 Feb 25, 2021 N/A· v4 6.8 MEDIUM· v3 4.3 MEDIUM· v2 Specific versions of the Java driver that support client-side field level encryption (CSFLE) fail to perform correct host name verification on the KMS server’s certificate. This vulnerability in combination with a privil...Show more |
A specific version of the Node.js mongodb-client-encryption module does not perform correct validation of the KMS server’s certificate. This vulnerability in combination with a privileged network position active MITM att...Show more |
A flaw was found in stunnel before 5.57, where it improperly validates client certificates when it is configured to use both redirect and verifyChain options. This flaw allows an attacker with a certificate signed by a C...Show more |
The CIRA Canadian Shield app before 4.0.13 for iOS lacks SSL Certificate Validation. |
1Tweetstream Project 1Tweetstream Jun 17, 2026 Feb 19, 2021 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 TweetStream 2.6.1 uses the library eventmachine in an insecure way that does not have TLS hostname validation. This allows an attacker to perform a man-in-the-middle attack. |
1Twitter Stream Project 1Twitter Stream Jun 17, 2026 Feb 19, 2021 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 In voloko twitter-stream 0.1.10, missing TLS hostname validation allows an attacker to perform a man-in-the-middle attack against users of the library (because eventmachine is misused). |
2Canarymail Libmailcore2Canary Mail Mailcore2Jun 17, 2026 Feb 17, 2021 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 core/imap/MCIMAPSession.cpp in Canary Mail before 3.22 has Missing SSL Certificate Validation for IMAP in STARTTLS mode. |
1Opcfoundation 1Ua .netstandard Jun 17, 2026 Feb 16, 2021 N/A· v4 4.4 MEDIUM· v3 2.1 LOW· v2 A Privilege Elevation vulnerability in OPC UA .NET Standard Stack 1.4.363.107 could allow a rogue application to establish a secure connection. |
1Elecom 1Wrc 300febk S Firmware Jun 17, 2026 Feb 12, 2021 N/A· v4 4.8 MEDIUM· v3 5.8 MEDIUM· v2 ELECOM WRC-300FEBK-S contains an improper certificate validation vulnerability. Via a man-in-the-middle attack, an attacker may alter the communication response. As a result, an arbitrary OS command may be executed on th...Show more |
In verifyHostName of OkHostnameVerifier.java, there is a possible way to accept a certificate for the wrong domain due to improperly used crypto. This could lead to remote information disclosure with no additional execut...Show more |
1Ibm 1Security Identity Governance And Intelligence Jun 17, 2026 Feb 9, 2021 N/A· v4 5.3 MEDIUM· v3 1.8 LOW· v2 IBM Security Identity Governance and Intelligence 5.2.6 could allow an attacker to obtain sensitive information using main in the middle attacks due to improper certificate validation. IBM X-Force ID: 189379. |
1Tenable 1Nessus Amazon Machine Image Jun 17, 2026 Feb 6, 2021 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Nessus AMI versions 8.12.0 and earlier were found to either not validate, or incorrectly validate, a certificate which could allow an attacker to spoof a trusted entity by using a man-in-the-middle (MITM) attack. |
1Cisco 1Unified Computing System Central Software Jun 17, 2026 Feb 4, 2021 N/A· v4 3.5 LOW· v3 2.7 LOW· v2 A vulnerability in the certificate registration process of Cisco Unified Computing System (UCS) Central Software could allow an authenticated, adjacent attacker to register a rogue Cisco Unified Computing System Manager...Show more |
DoTls13CertificateVerify in tls13.c in wolfSSL before 4.7.0 does not cease processing for certain anomalous peer behavior (sending an ED22519, ED448, ECC, or RSA signature without the corresponding certificate). The clie...Show more |
packages/wekan-ldap/server/ldap.js in Wekan before 4.87 can process connections even though they are not authorized by the Certification Authority trust store, |
1Ti 1Code Composer Studio Intgrated Development Environment Jun 17, 2026 Jan 26, 2021 N/A· v4 5.3 MEDIUM· v3 4.3 MEDIUM· v2 jxbrowser in TI Code Composer Studio IDE 8.x through 10.x before 10.1.1 does not verify X.509 certificates for HTTPS. |
1Cisco 1Data Center Network Manager Jun 17, 2026 Jan 20, 2021 N/A· v4 6.5 MEDIUM· v3 5.8 MEDIUM· v2 Multiple vulnerabilities in Cisco Data Center Network Manager (DCNM) could allow an attacker to spoof a trusted host or construct a man-in-the-middle attack to extract sensitive information or alter certain API requests....Show more |