CWE-295— Improper Certificate Validation
The product does not validate, or incorrectly validates, a certificate.— MITRE CWE catalog
1,456 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-295page 30 of 30
- CVE-2026-8992HIGHCVSS 8.8EG 8.82026-05-22
An improper certificate validation vulnerability in Ivanti Secure Access Client before 22.8R6 allows a remote unauthenticated attacker to execute arbitrary code.
- CVE-2026-9058CRITICALCVSS 9.3EG 9.32026-05-25
For untrusted certificates that contain the "Authority Information Access - caIssuers URI" extension, Szafir SDK will automatically download the parent CA certificate from the specified URL and will import it to its trust store as a "nonqu…
- CVE-2026-9258CRITICALCVSS 9.8EG 9.82026-06-16
Improper validation of SSH host keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier
- CVE-2026-9259CRITICALCVSS 9.8EG 9.82026-06-16
Improper validation of server certificates in Canon EOS Network Setting Tool Version 1.5.0 or earlier
- CVE-2026-9697HIGHCVSS 7.4EG 7.42026-06-17
Impact: undici's ProxyAgent silently drops the requestTls option when configured with a SOCKS5 proxy URI (socks5:// or socks://). The target HTTPS connection through the SOCKS5 tunnel falls back to Node's default trust store, ignoring user…
- CVE-2026-9758HIGHCVSS 7.3EG 7.32026-06-10
Improper comparison with the certificates trusted list in S2OPC allows an attacker well-formed untrusted certificate to be considered trusted
Map vulnerabilities like CWE-295 to your infrastructure
EchelonGraph correlates every CVE — across CWE-295 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →