VYPR

CWE-295

Improper Certificate Validation

BaseDraft

Description

The product does not validate, or incorrectly validates, a certificate.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-459 · CAPEC-475

CVEs mapped to this weakness (1,595)

page 10 of 80
  • CVE-2026-63374CriSep 22, 2026
    risk 0.53cvss —epss 0.00

    AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio. Prior to 4.14.2, connect_tcp() and TLSStream.wrap() can validate internationalized host names after the standard library converts them with IDNA 2003 instead of…

  • CVE-2026-84081HigSep 18, 2026
    risk 0.53cvss 8.1epss 0.00

    IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to improper certificate validation.

  • CVE-2026-78491HigSep 9, 2026
    risk 0.53cvss 8.2epss 0.00

    Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to…

  • CVE-2026-65084HigAug 25, 2026
    risk 0.53cvss 8.1epss 0.01

    NVIDIA NemoClaw for Linux contains a vulnerability in its deployment process, where an attacker could cause improper certificate validation. A successful exploit of this vulnerability might lead to information disclosure, data tampering, code execution, and escalation of…

  • CVE-2026-15078HigAug 19, 2026
    risk 0.53cvss 8.1epss 0.00

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow a remote attacker to gain unauthorized access to AIX systems due to improper validation of TLS certificates.

  • CVE-2026-18129HigAug 11, 2026
    risk 0.53cvss 8.1epss 0.01

    Cleartext transmission of sensitive information in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a remote unauthenticated attacker in a MITM position to leak credentials for external SQL connections.

  • CVE-2026-18141HigJul 31, 2026
    risk 0.53cvss 8.2epss 0.00

    A flaw was found in aap-gateway, a component of Ansible Automation Platform's Event-Driven Ansible (EDA). An unauthenticated remote attacker can bypass mutual Transport Layer Security (mTLS) authentication for event streams. This is achieved by manipulating the event stream URL…

  • CVE-2026-53475CriJun 10, 2026
    risk 0.53cvss 9.3epss 0.01

    A flaw was found in assisted-migration-agent. The application hardcodes insecure Transport Layer Security (TLS) connections when communicating with vCenter. This vulnerability allows a Man-in-the-Middle (MITM) attacker to intercept and harvest vCenter administrator credentials.…

  • CVE-2026-42508CriMay 22, 2026
    risk 0.53cvss 9.1epss 0.01

    Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now, both the 'key' and 'key.SignatureKey' are checked for @revoked.

  • CVE-2026-32992HigMay 13, 2026
    risk 0.53cvss 8.2epss 0.00

    SSL verification is disabled in the DNS Cluster system. This could allow for a malicious server to man-in-the-middle the request and capture credentials.

  • CVE-2026-0244HigMay 13, 2026
    risk 0.53cvss 8.1epss 0.00

    An improper certificate validation vulnerability in the Palo Alto Networks Prisma SD-WAN ION enables man-in-the-middle (MitM) attacker to impersonate the controller.

  • CVE-2026-4434HigMar 20, 2026
    risk 0.53cvss 8.1epss 0.00

    Improper certificate validation in the PAM propagation WinRM connections allows a network attacker to perform a man-in-the-middle attack via disabled TLS certificate verification.

  • CVE-2026-4396HigMar 18, 2026
    risk 0.53cvss 8.1epss 0.00

    Improper certificate validation in Devolutions Hub Reporting Service 2025.3.1.1 and earlier allows a network attacker to perform a man-in-the-middle attack via disabled TLS certificate verification.

  • CVE-2026-27134HigFeb 21, 2026
    risk 0.53cvss 8.1epss 0.00

    Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. In versions 0.49.0 through 0.50.0, when using a custom Cluster or Clients CA with a multistage CA chain consisting of multiple CAs, Strimzi incorrectly…

  • CVE-2025-9293HigFeb 13, 2026
    risk 0.53cvss 8.1epss 0.00

    A vulnerability in the certificate validation logic may allow applications to accept untrusted or improperly validated server identities during TLS communication. An attacker in a privileged network position may be able to intercept or modify traffic if they can position…

  • CVE-2026-21228HigFeb 10, 2026
    risk 0.53cvss 8.1epss 0.01

    Improper certificate validation in Azure Local allows an unauthorized attacker to execute code over a network.

  • CVE-2026-22696CriJan 26, 2026
    risk 0.53cvss —epss 0.00

    dcap-qvl implements the quote verification logic for DCAP (Data Center Attestation Primitives). A vulnerability present in versions prior to 0.3.9 involves a critical gap in the cryptographic verification process within the dcap-qvl. The library fetches QE Identity collateral…

  • CVE-2025-40801HigDec 9, 2025
    risk 0.53cvss 8.1epss 0.00

    A vulnerability has been identified in COMOS V10.6 (All versions < V10.6.1), COMOS V10.6 (All versions < V10.6.1), JT Bi-Directional Translator for STEP (All versions), NX V2412 (All versions < V2412.8900 with Cloud Entitlement (bundled as NX X)), NX V2506 (All versions <…

  • CVE-2025-64685HigNov 10, 2025
    risk 0.53cvss 8.1epss 0.00

    In JetBrains YouTrack before 2025.3.104432 missing TLS certificate validation enabled data disclosure

  • CVE-2025-61778CriOct 6, 2025
    risk 0.53cvss —epss 0.00

    Akka.NET is a .NET port of the Akka project from the Scala / Java community. In all versions of Akka.Remote from v1.2.0 to v1.5.51, TLS could be enabled via our `akka.remote.dot-netty.tcp` transport and this would correctly enforce private key validation on the server-side of…