CWE-295
1,445 CVEs • Abstraction: Base
Improper Certificate Validation
The product does not validate, or incorrectly validates, a certificate.
CVEs (1,445)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
5Broadcom CanonicalFedoraproject+2 more6Balsa Cloud BackupFabric Operating System+3 moreJun 17, 2026 May 28, 2020 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 In GNOME glib-networking through 2.64.2, the implementation of GTlsClientConnection skips hostname verification of the server's TLS certificate if the application fails to specify the expected server identity. This is in...Show more |
The boost ASIO wrapper in net/asio.cpp in Pichi before 1.3.0 lacks TLS hostname verification. |
lib/QoreSocket.cpp in Qore before 0.9.4.2 lacks hostname verification for X.509 certificates. |
3Axel Project FedoraprojectOpensuse4Axel Backports SleFedora+1 moreJun 17, 2026 May 26, 2020 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in ssl.c in Axel before 2.17.8. The TLS implementation lacks hostname verification. |
2Em Http Request Project Fedoraproject2Em Http Request FedoraJun 17, 2026 May 25, 2020 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 EM-HTTP-Request 1.1.5 uses the library eventmachine in an insecure way that allows an attacker to perform a man-in-the-middle attack against users of the library. The hostname in a TLS server certificate is not verified. |
1Microsoft 8Windows 10 Windows 7Windows 8.1+5 moreJun 17, 2026 May 21, 2020 N/A· v4 7.5 HIGH· v3 9.3 HIGH· v2 A security feature bypass vulnerability exists in Microsoft Windows when the Task Scheduler service fails to properly verify client connections over RPC, aka 'Windows Task Scheduler Security Feature Bypass Vulnerability'...Show more |
em-imap 0.5 uses the library eventmachine in an insecure way that allows an attacker to perform a man-in-the-middle attack against users of the library. The hostname in a TLS server certificate is not verified. |
A flaw was found in Keycloak in versions before 10.0.0, where it does not perform the TLS hostname verification while sending emails using the SMTP server. This flaw allows an attacker to perform a man-in-the-middle (MIT...Show more |
2Fedoraproject Nextcloud2Fedora MailJun 17, 2026 May 12, 2020 N/A· v4 7.0 HIGH· v3 6.8 MEDIUM· v2 A missing verification of the TLS host in Nextcloud Mail 1.1.3 allowed a man in the middle attack. |
The UpdateHub module disables DTLS peer checking, which allows for a man in the middle attack. This is mitigated by firmware images requiring valid signatures. However, there is no benefit to using DTLS without the peer...Show more |
Zulip Desktop before 5.2.0 has Missing SSL Certificate Validation because all validation was inadvertently disabled during an attempt to recognize the ignoreCerts option. |
1Java Websocket Project 1Java Websocket Jun 17, 2026 May 7, 2020 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 In Java-WebSocket less than or equal to 1.4.1, there is an Improper Validation of Certificate with Host Mismatch where WebSocketClient does not perform SSL hostname validation. This has been patched in 1.5.0. |
Jenkins Amazon EC2 Plugin 1.50.1 and earlier unconditionally accepts self-signed certificates and does not perform hostname validation, enabling man-in-the-middle attacks. |
1Silver Peak 24Nx 1000 Firmware Nx 10k FirmwareNx 11k Firmware+21 moreJun 17, 2026 May 5, 2020 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 The certificate used to identify the Silver Peak Cloud Portal to EdgeConnect devices is not validated. This makes it possible for someone to establish a TLS connection from EdgeConnect to an untrusted portal. |
1Silver Peak 24Nx 1000 Firmware Nx 10k FirmwareNx 11k Firmware+21 moreJun 17, 2026 May 5, 2020 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 The certificate used to identify Orchestrator to EdgeConnect devices is not validated, which makes it possible for someone to establish a TLS connection from EdgeConnect to an untrusted Orchestrator. |
1Br Automation 1Automation Studio Jun 17, 2026 Apr 29, 2020 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 A missing secure communication definition and an incomplete TLS validation in the upgrade service in B&R Automation Studio versions 4.0.x, 4.1.x, 4.2.x, < 4.3.11SP, < 4.4.9SP, < 4.5.5SP, < 4.6.4 and < 4.7.2 enable unauth...Show more |
An issue was found in Apache IoTDB .9.0 to 0.9.1 and 0.8.0 to 0.8.2. When starting IoTDB, the JMX port 31999 is exposed with no certification.Then, clients could execute code remotely. |
4Apache DebianOracle+1 more46Communications Application Session Controller Communications Billing And Revenue ManagementCommunications Eagle Ftp Table Base Retrieval+43 moreJun 17, 2026 Apr 27, 2020 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through tha...Show more |
In versions of NGINX Controller prior to 3.2.0, communication between NGINX Controller and NGINX Plus instances skip TLS verification by default. |
1Mailstore 1Mailstore Server Jun 17, 2026 Apr 23, 2020 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 In MailStore Outlook Add-in (and Email Archive Outlook Add-in) through 12.1.2, the login process does not validate the validity of the certificate presented by the server. |