Improper certificate validation in Azure Local allows an unauthorized attacker to execute code over a network.
A vulnerability in the certificate validation logic may allow applications to accept untrusted or improperly validated s
Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. I
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio
Improper certificate validation in Devolutions Hub Reporting Service 2025.3.1.1 and earlier allows a network attacker t
Improper certificate validation in the PAM propagation WinRM connections allows a network attacker to perform a man-in-
wolfSSL_X509_verify_cert in the OpenSSL compatibility layer accepts a certificate chain in which the leaf's signature is
An improper certificate validation vulnerability in the Palo Alto Networks Prisma SD-WAN ION enables man-in-the-middle (
epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. Prior to 1.2.1, in SignedPublic
epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. Prior to 1.2.2, an attacker on t
Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_cert and public_key modules) allows a DNS
A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live co
In epa4all, prior to version 2026-05-20, an attacker on the network path between epa4all and any backend (ePA Aktensyste
Cleartext transmission of sensitive information in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow a remote attacker to gain unauthorized access to AIX syste
NVIDIA NemoClaw for Linux contains a vulnerability in its deployment process, where an attacker could cause improper cer
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Starting i
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management).
rsync 3.2.0 through 3.2.3 (openssl mode) and rsync-ssl through 3.4.4 (stunnel mode) contain a TLS certificate validation
A network man-in-the-middle between nats-sync and the BOSH director can steal the director credentials (Basic auth heade
Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within internal agent vali
Improper certificate validation in Windows Active Directory allows an authorized attacker to elevate privileges locally.
FunJSQ, a third-party module integrated on some NETGEAR routers and Orbi WiFi Systems, does not properly validate TLS ce
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to improper ce
Traffic interception vulnerability in BOSH Director vCenter CPI allows attackers positioned between BOSH Director and vC
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE
DataHub is an open-source metadata platform. Prior to version 1.3.1.8, the LDAP ingestion source is vulnerable to MITM a
SumatraPDF is a multi-format reader for Windows. In 3.5.0 through 3.5.2, SumatraPDF's update mechanism disables TLS host
An issue in Sunbird-Ed SunbirdEd-portal v1.13.4 allows attackers to obtain sensitive information. The application disabl
An issue in the TLS certification mechanism of Guardian Gryphon v01.06.0006.22 allows attackers to execute commands as r
Improper Input Validation vulnerability in Apache Tomcat Native, Apache Tomcat. When using an OCSP responder, Tomcat Na
Improper certificate validation in PKCS7_verify() in AWS-LC allows an unauthenticated user to bypass certificate chain v
When verifying a certificate chain which contains a certificate containing multiple email address constraints which shar
UniFi Network Controller before version 5.10.22 and 5.11.x before 5.11.18 contains an improper certificate verification
Bulwark Webmail is a self-hosted webmail client for Stalwart Mail Server. Prior to 1.4.11, S/MIME signature verification
Botan is a C++ cryptography library. In 3.11.0, the function Certificate_Store::certificate_known had a misleading name;
Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a ve
Fleet is open source device management software. Prior to version 4.81.0, a vulnerability in Fleet’s Windows MDM managem
X.509 trust-chain bypass (path-depth exhaustion) in the OpenSSL compatibility certificate verifier (wolfSSL_X509_verify_
X.509 trust-chain bypass in the OpenSSL compatibility certificate verifier (wolfSSL_X509_verify_cert()). This affects on
Un-negotiated Raw Public Key (RFC 7250) accepted in place of an X.509 certificate, bypassing chain validation. A raw pub
X.509 name constraint bypass via the Subject Common Name when treated as a DNS-type name. A certificate whose Subject CN
iPAddress name constraints bypass when WOLFSSL_IP_ALT_NAME is not defined. IP address name constraints are not enforced
When a user invokes curl using a schemeless URL combined with `--proto-default` sftp (or scp), a disconnect occurs betwe
Lorex 2K Indoor Wi-Fi Security Camera Device Management Server Improper Certificate Validation Vulnerability. This vulne
A improper certificate validation vulnerability in Fortinet FortiClientEMS 7.4.3 through 7.4.5, FortiClientEMS 7.4.0 thr
RRSIGs with too few labels can lead to bypass of DNSSEC wildcard validation
Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass by verifying responses against the response-em
Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override (CWE-295)
ePA 3.x Integration implements the authorization workflow and writes Medical Information Objects to Germany's electronic
Frequently Asked Questions
What is CWE-295?
CWE-295 (CWE-295) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-295?
There are 1,771 CVE records associated with CWE-295 in our database. Of these, 124 are critical severity, 576 are high severity, and 675 are medium severity.
How can I protect against CWE-295 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-295 using AI-powered security agents.
Detect CWE-295 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-295 vulnerabilities across your infrastructure.
Get Started