VYPR

CWE-295

Improper Certificate Validation

BaseDraft

Description

The product does not validate, or incorrectly validates, a certificate.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-459 · CAPEC-475

CVEs mapped to this weakness (1,595)

page 76 of 80
  • CVE-2026-50302MedJul 14, 2026
    risk 0.00cvss 4.2epss 0.00

    Improper certificate validation in Windows Cryptographic Services allows an unauthorized attacker to bypass a security feature over a network.

  • CVE-2026-55001HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Improper certificate validation in Windows Active Directory allows an authorized attacker to elevate privileges locally.

  • CVE-2026-59836HigJul 14, 2026
    risk 0.00cvss 7.5epss 0.00

    A improper certificate validation vulnerability in Fortinet FortiClientEMS 7.4.3 through 7.4.5, FortiClientEMS 7.4.0 through 7.4.1, FortiClientEMS 7.2 all versions may allow attacker to information disclosure via

  • CVE-2026-15683HigJul 13, 2026
    risk 0.00cvss 7.5epss 0.00

    Lorex 2K Indoor Wi-Fi Security Camera Device Management Server Improper Certificate Validation Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Lorex 2K Indoor Wi-Fi Security Cameras. User interaction is…

  • CVE-2026-22093CriJul 13, 2026
    risk 0.00cvss —epss 0.00

    The EVbee Service Android app uses TLS encrypted communication (HTTPS), but does not validate the certificate provided by the server. This allows an attacker on the network path between the app and EVbee server to intercept and manipulate the communication between the app and…

  • CVE-2026-55436HigJul 8, 2026
    risk 0.00cvss 7.4epss 0.00

    Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.30.0 and prior to versions 2.32.7, 2.33.8, and 2.34.2, the AI Bridge Proxy (`aibridgeproxyd`) created a goproxy server whose default transport set `InsecureSkipVerify:…

  • CVE-2026-6900HigJul 6, 2026
    risk 0.00cvss 7.4epss 0.00

    Improper certificate validation vulnerability in B&R Industrial Automation GmbH APROL. This issue affects APROL: before R 4.4-01P5.

  • CVE-2026-8480MedJul 1, 2026
    risk 0.00cvss 4.3epss 0.00

    A vulnerability was discovered on Stormshield Network Security 4.3.0  to 4.3.41 (included), 4.4.0 to 4.8.15 (included) , 5.0.2 EA to 5.0.5 (included) A revoked client certificate can still be used to authenticate to the captive‑admin portal, allowing an attacker who…

  • CVE-2026-12374MedJul 1, 2026
    risk 0.00cvss —epss 0.00

    Improper certificate validation and a time-of-check time-of-use (TOCTOU) race condition in the PrivilegedHelperTool XPC service in Cato Client before v.5.13.1 on macOS allows a local authenticated attacker to escalate privileges to root via a self-signed certificate that…

  • CVE-2026-46734HigJun 25, 2026
    risk 0.00cvss 7.3epss 0.00

    Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3, contain an Improper Certificate Validation vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Protection mechanism bypass.

  • CVE-2026-30840HigMar 7, 2026
    risk 0.00cvss 8.8epss 0.01

    Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, there is a server-side request forgery vulnerability in notification testers. This issue has been patched in version 4.6.2.

  • CVE-2025-67752HigFeb 25, 2026
    risk 0.00cvss 8.1epss 0.00

    OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 7.0.4, OpenEMR's HTTP client wrapper (`oeHttp`/`oeHttpRequest`) disables SSL/TLS certificate verification by default (`verify: false`), making all external…

  • CVE-2025-71063HigJan 12, 2026
    risk 0.00cvss 8.2epss 0.00

    Errands before 46.2.10 does not verify TLS certificates for CalDAV servers.

  • CVE-2025-29331CriJun 26, 2025
    risk 0.00cvss 9.8epss 0.00

    An issue in MHSanaei 3x-ui before v.2.5.3 and before allows a remote attacker to execute arbitrary code via the management script x-ui passes the no check certificate option to wget when downloading updates

  • CVE-2025-4575MedMay 22, 2025
    risk 0.00cvss 6.5epss 0.00

    Issue summary: Use of -addreject option with the openssl x509 application adds a trusted use instead of a rejected use for a certificate. Impact summary: If a user intends to make a trusted certificate rejected for a particular use it will be instead marked as trusted for that…

  • CVE-2024-47619HigMay 7, 2025
    risk 0.00cvss 7.5epss 0.00

    syslog-ng is an enhanced log daemo. Prior to version 4.8.2, `tls_wildcard_match()` matches on certificates such as `foo.*.bar` although that is not allowed. It is also possible to pass partial wildcards such as `foo.a*c.bar` which glib matches but should be avoided /…

  • CVE-2024-52510MedNov 15, 2024
    risk 0.00cvss 4.2epss 0.01

    The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with your computer. The Desktop client did not stop with an error but allowed by-passing the signature validation, if a manipulated server sends an empty initial signature. It is recommended that…

  • CVE-2024-49369CriNov 12, 2024
    risk 0.00cvss 9.8epss 0.03

    Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. The TLS certificate validation in all Icinga 2 versions starting from 2.4.0 was flawed, allowing an attacker to impersonate…

  • CVE-2023-46724HigNov 1, 2023
    risk 0.00cvss 8.6epss 0.04

    Squid is a caching proxy for the Web. Due to an Improper Validation of Specified Index bug, Squid versions 3.3.0.1 through 5.9 and 6.0 prior to 6.4 compiled using `--with-openssl` are vulnerable to a Denial of Service attack against SSL Certificate validation. This problem…

  • CVE-2023-3724CriJul 17, 2023
    risk 0.00cvss 9.1epss 0.01

    If a TLS 1.3 client gets neither a PSK (pre shared key) extension nor a KSE (key share extension) when connecting to a malicious server, a default predictable buffer gets used for the IKM (Input Keying Material) value when generating the session master secret. Using a…