← Back
CWE-295

1,445 CVEs • Abstraction: Base

Improper Certificate Validation

The product does not validate, or incorrectly validates, a certificate.

JSON object

Loading...

CVEs (1,445)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Golang
Microsoft
13Go
Windows 10 1507Windows 10 1607+10 more
Jun 17, 2026
Jan 14, 2020
N/A· v4
8.1 HIGH· v3
5.8 MEDIUM· v2
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates.An attacker could exploit the vulnerability by using a spoofed code-signing certificate...Show more
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates.An attacker could exploit the vulnerability by using a spoofed code-signing certificate to sign a malicious executable, making it appear the file was from a trusted, legitimate source, aka 'Windows CryptoAPI Spoofing Vulnerability'.Show less
1Ovirt Engine Sdk Python Project
1Ovirt Engine Sdk Python
Nov 21, 2024
Jan 2, 2020
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
ovirt-engine-sdk-python before 3.4.0.7 and 3.5.0.4 does not verify that the hostname of the remote endpoint matches the Common Name (CN) or subjectAltName as specified by its x.509 certificate in a TLS/SSL session. This...Show more
ovirt-engine-sdk-python before 3.4.0.7 and 3.5.0.4 does not verify that the hostname of the remote endpoint matches the Common Name (CN) or subjectAltName as specified by its x.509 certificate in a TLS/SSL session. This could allow man-in-the-middle attackers to spoof remote endpoints via an arbitrary valid certificate.Show less
1Clusterlabs
1Fence Agents
Nov 21, 2024
Jan 2, 2020
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
In fence-agents before 4.0.17 does not verify remote SSL certificates in the fence_cisco_ucs.py script which can potentially allow for man-in-the-middle attackers to spoof SSL servers via arbitrary SSL certificates.
1Redhat
1Mrg Management Console
Nov 21, 2024
Dec 30, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An import error was introduced in Cumin in the code refactoring in r5310. Server certificate validation is always disabled when connecting to Aviary servers, even if the installed packages on a system support it.
1Ntv
1News 24
Jun 17, 2026
Dec 26, 2019
N/A· v4
7.4 HIGH· v3
5.8 MEDIUM· v2
The NTV News24 prior to Ver.3.0.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
1F5
1Big Ip Application Security Manager
Jun 17, 2026
Dec 23, 2019
N/A· v4
7.4 HIGH· v3
5.8 MEDIUM· v2
On versions 15.0.0-15.0.1.1, the BIG-IP ASM Cloud Security Services profile uses a built-in verification mechanism that fails to properly authenticate the X.509 certificate of remote endpoints.
1Jenkins
1Websphere Deployer
Jun 17, 2026
Dec 17, 2019
N/A· v4
7.1 HIGH· v3
5.5 MEDIUM· v2
Jenkins WebSphere Deployer Plugin 1.6.1 and earlier allows users with Overall/Read access to disable SSL/TLS certificate and hostname validation for the entire Jenkins master JVM.
1Jenkins
1Spira Importer
Jun 17, 2026
Dec 17, 2019
N/A· v4
8.2 HIGH· v3
6.4 MEDIUM· v2
Jenkins Spira Importer Plugin 3.2.3 and earlier disables SSL/TLS certificate validation for the Jenkins master JVM.
1Puppet
1Puppet Server
Nov 21, 2024
Dec 16, 2019
N/A· v4
5.4 MEDIUM· v3
4.8 MEDIUM· v2
Previous versions of Puppet Agent didn't verify the peer in the SSL connection prior to downloading the CRL. This issue is resolved in Puppet Agent 6.4.0.
1Barco
3Clickshare Cs 100 Firmware
Clickshare Cse 200 FirmwareClickshare Cse 800 Firmware
Jun 17, 2026
Dec 16, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Barco ClickShare Button R9861500D01 devices before 1.9.0 have Improper Following of a Certificate's Chain of Trust. The embedded 'dongle_bridge' program used to expose the functionalities of the ClickShare Button to a US...Show more
Barco ClickShare Button R9861500D01 devices before 1.9.0 have Improper Following of a Certificate's Chain of Trust. The embedded 'dongle_bridge' program used to expose the functionalities of the ClickShare Button to a USB host, does not properly validate the whole certificate chain.Show less
2Debian
Opensuse
3Debian Linux
DuplicityOpensuse
Nov 21, 2024
Dec 13, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
duplicity 0.6.24 has improper verification of SSL certificates
1Amazon
1Audible
Jun 17, 2026
Dec 6, 2019
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The Audible application through 2.34.0 for Android has Missing SSL Certificate Validation for Adobe SDKs, allowing MITM attackers to cause a denial of service.
1Redhat
1Keycloak
Jun 17, 2026
Dec 5, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A vulnerability was found in keycloak 7.x, when keycloak is configured with LDAP user federation and StartTLS is used instead of SSL/TLS from the LDAP server (ldaps), in this case user authentication succeeds even if inv...Show more
A vulnerability was found in keycloak 7.x, when keycloak is configured with LDAP user federation and StartTLS is used instead of SSL/TLS from the LDAP server (ldaps), in this case user authentication succeeds even if invalid password has entered.Show less
3Debian
GnupgRedhat
3Debian Linux
Enterprise LinuxGnupg
Nov 21, 2024
Nov 27, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
dirmngr before 2.1.0 improperly handles certain system calls, which allows remote attackers to cause a denial of service (DOS) via a specially-crafted certificate.
1Proftpd
1Proftpd
Jun 17, 2026
Nov 26, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in tls_verify_crl in ProFTPD before 1.3.6. A wrong iteration variable, used when checking a client certificate against CRL entries (installed by a system administrator), can cause some CRL entries...Show more
An issue was discovered in tls_verify_crl in ProFTPD before 1.3.6. A wrong iteration variable, used when checking a client certificate against CRL entries (installed by a system administrator), can cause some CRL entries to be ignored, and can allow clients whose certificates have been revoked to proceed with a connection to the server.Show less
2Fedoraproject
Proftpd
2Fedora
Proftpd
Jun 17, 2026
Nov 26, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in tls_verify_crl in ProFTPD through 1.3.6b. Failure to check for the appropriate field of a CRL entry (checking twice for subject, rather than once for subject and once for issuer) prevents some...Show more
An issue was discovered in tls_verify_crl in ProFTPD through 1.3.6b. Failure to check for the appropriate field of a CRL entry (checking twice for subject, rather than once for subject and once for issuer) prevents some valid CRLs from being taken into account, and can allow clients whose certificates have been revoked to proceed with a connection to the server.Show less
1Ovirt
1Vdsm
Nov 21, 2024
Nov 25, 2019
N/A· v4
7.5 HIGH· v3
4.3 MEDIUM· v2
vdsm: certificate generation upon node creation allowing vdsm to start and serve requests from anyone who has a matching key (and certificate)
1Wolfssl
1Wolfssl
Nov 21, 2024
Nov 21, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
wolfssl before 3.2.0 does not properly authorize CA certificate for signing other certificates.
1Wolfssl
1Wolfssl
Nov 21, 2024
Nov 21, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
wolfssl before 3.2.0 does not properly issue certificates for a server's hostname.
2Debian
Nusoap Project
2Debian Linux
Nusoap
Nov 21, 2024
Nov 19, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
nuSOAP before 0.7.3-5 does not properly check the hostname of a cert.