An issue in beego v.2.2.0 and before allows a remote attacker to escalate privileges via the sendMail function located i
The Planet Fitness Workouts iOS and Android mobile apps fail to properly validate TLS certificates, allowing an attacker
An insufficient certification validation issue in the Palo Alto Networks GlobalProtect app enables attackers to connect
Windows Cryptographic Services Remote Code Execution Vulnerability
Improper certificate validation in Ivanti ITSM on-prem and Neurons for ITSM Versions 2023.4 and earlier allows a remote
An improper certificate validation vulnerability in TLS certificate validation allows an attacker on the same network to
IBM Security Verify Access 10.0.0.0 through 10.0.6.1 could allow a privileged user to install a configuration file that
A privilege escalation vulnerability exists in the Foxit Reader 2024.2.0.25138. The vulnerability occurs due to improper
Collabora Online is a collaborative online office suite based on LibreOffice. In affected versions of Collabora Online,
Vault and Vault Enterprise (“Vault”) TLS certificate auth method did not correctly validate client certificates when con
Windows Cryptographic Services Remote Code Execution Vulnerability
A flaw was found in the openstack-tripleo-common component of the Red Hat OpenStack Platform (RHOSP) director. This vuln
qBittorrent before 5.0.1 proceeds with use of https URLs even after certificate validation errors.
An improper certificate validation vulnerability was reported in LADM that could allow a network attacker with the abili
Boundary and Boundary Enterprise (“Boundary”) is vulnerable to session hijacking through TLS certificate tampering. An a
A vulnerability has been identified within Rancher that can be exploited in narrow circumstances through a man-in-the-m
A privilege escalation vulnerability was reported in Lenovo Vantage that could allow a local attacker to bypass integrit
In TBD of TBD, there is a possible confusion of OEM and DRM certificates due to improperly used crypto. This could lead
Certificate Validation user interface in LibreOffice allows potential vulnerability. Signed macros are scripts that
An improper certificate validation vulnerability has been reported to affect QuMagie. If exploited, the vulnerability co
An improper validation vulnerability was reported in the firmware update mechanism of LADM and LDCC that could allow a l
IBM Security Verify Access Docker 10.0.0 through 10.0.6 could allow a local user to escalate their privileges due to imp
IBM Security Verify Access 10.0.0.0 through 10.0.6.1 uses insecure calls that could allow an attacker on the network to
In ca-certificates, there is a possible way to read encrypted TLS data due to untrusted cryptographic certificates. This
PDF-XChange Editor Updater Improper Certificate Validation Remote Code Execution Vulnerability. This vulnerability allow
IBM Security Verify Access Appliance 10.0.0 through 10.0.7 could allow a malicious actor to conduct a man in the middle
IBM Security Verify Access Appliance 10.0.0 through 10.0.7 could allow a malicious actor to conduct a man in the middle
electron-updater allows for automatic updates for Electron apps. The file `packages/electron-updater/src/windowsExecutab
An issue discovered in casdoor v1.636.0 allows attackers to obtain sensitive information via the ssh.InsecureIgnoreHostK
An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor ca
Validating the order of the public keys in the Diffie-Hellman Key Agreement Protocol, when an approved safe prime is use
Anbox Management Service, in versions 1.17.0 through 1.23.0, does not validate the TLS certificate provided to it by the
NETGEAR RAX30 Improper Certificate Validation Remote Code Execution Vulnerability. This vulnerability allows network-adj
An improper certificate validation vulnerability has been reported to affect several QNAP operating system versions. If
Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.5.2, co
Due to improper validation of certificate in SAP Cloud Connector - version 2.0, attacker can impersonate the genuine ser
Serverpod is an app and web server, built for the Flutter and Dart ecosystem. This bug bypassed the validation of TSL ce
A vulnerability exists in the FOXMAN-UN/UNEM server that affects the message queueing mechanism’s certificate validatio
An improper certificate validation vulnerability [CWE-295] in FortiADC 7.4.0, 7.2.0 through 7.2.3, 7.1 all versions, 7.0
A flaw was found in libnbd. The client did not always correctly verify the NBD server's certificate when using TLS to co
Improper Certificate Validation in Checkmk Exchange plugin MikroTik allows attackers in MitM position to intercept traff
Windows Secure Channel Spoofing Vulnerability
A vulnerability has been identified in Bitdefender Total Security HTTPS scanning functionality where the software fails
A vulnerability has been discovered in Bitdefender Total Security HTTPS scanning functionality that results in the impro
A vulnerability has been discovered in Bitdefender Total Security HTTPS scanning functionality that results in the impro
A vulnerability has been identified in Bitdefender Total Security HTTPS scanning functionality where the software trusts
A vulnerability in the certificate validation of Cisco Expressway-C and Cisco TelePresence VCS could allow an
Because the HttpUtils class did not verify certificates, an attacker that could perform a Man-in-the-Middle (MITM) attac
A vulnerability classified as critical has been found in cym1102 nginxWebUI up to 3.9.9. This affects the function handl
An Improper Certificate Validation on the UniFi iOS App managing a standalone UniFi Access Point (not using UniFi Networ
Frequently Asked Questions
What is CWE-295?
CWE-295 (CWE-295) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-295?
There are 1,771 CVE records associated with CWE-295 in our database. Of these, 124 are critical severity, 576 are high severity, and 675 are medium severity.
How can I protect against CWE-295 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-295 using AI-powered security agents.
Detect CWE-295 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-295 vulnerabilities across your infrastructure.
Get Started