VulnSea

CWE-295

CVEs classified under CWE-295, newest first.

151 CVEsRSS

CVE-2026-84081High· 8.1
3d ago

IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to improper certificate validation.

IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to improper certificate validation.

TwilightIBM · Guardium Data ProtectionEPSS 0.20%via NVD
CVE-2026-84975High· 7.4
3d ago

PJSIP is a free and open source multimedia communication library written in C

PJSIP is a free and open source multimedia communication library written in C. In 2.17 and earlier, the OpenSSL and GnuTLS backends in pjlib/src/pj/ssl_sock_ossl.c and pjlib/src/pj/ssl_sock_gtls.c copy DNS SubjectAltName values with stri…

Twilightpjsip · pjprojectEPSS 0.15%via NVD
CVE-2026-63374Critical
3d ago

AnyIO: TLSStream IDNA 2003 host name encoding enables potential TLS certificate spoofing

AnyIO: TLSStream IDNA 2003 host name encoding enables potential TLS certificate spoofing

Midnightanyio · anyiovia OSV
CVE-2026-93601Low· 2.2
3d ago

rustls-webpki (the Rust webpki fork used by rustls) versions >= 0.101.0 and prior to 0.103.12 and 0.104.0-alpha.6 incorrectly accepted permitted-subtree DNS name constraints for certificates asserting a wildcard name

rustls-webpki (the Rust webpki fork used by rustls) versions >= 0.101.0 and prior to 0.103.12 and 0.104.0-alpha.6 incorrectly accepted permitted-subtree DNS name constraints for certificates asserting a wildcard name. For example, a name…

Sunlitrustls · webpkiEPSS 0.18%via NVD
CVE-2026-93600Low· 2.2
3d ago

rustls-webpki (rustls/webpki) versions 0.101.0 through 0.103.11 and 0.104.0-alpha releases before 0.104.0-alpha.6 ignore X.509 name constraints that apply to URI names, causing such constraints to be accepted rather than enforced

rustls-webpki (rustls/webpki) versions 0.101.0 through 0.103.11 and 0.104.0-alpha releases before 0.104.0-alpha.6 ignore X.509 name constraints that apply to URI names, causing such constraints to be accepted rather than enforced. Becaus…

Sunlitrustls · webpkiEPSS 0.18%via NVD
CVE-2026-40539High· 7.1
3d ago

An improper certificate validation vulnerability in Email API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows man-in-the-middle attackers to read or write arbitrary files and conduct de…

An improper certificate validation vulnerability in Email API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows man-in-the-middle attackers to read or write arbitrary files and conduct de…

TwilightSynology · DiskStation Manager (DSM)EPSS 0.08%via NVD
CVE-2026-81868Medium· 6.5
4d ago

Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications

Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. Prior to 4.3.0, Steeltoe.Security.Authorization.Certificate deployments using AddOrgAndSpacePolicies() and UseCe…

SunlitSteeltoeOSS · security-advisoriesEPSS 0.16%via NVD
CVE-2026-81447Medium· 6.8
4d ago

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Certificate Validation vulnerability

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading t…

SunlitDell · OpenManage Server Administrator Managed Node (Patch) for WindowsEPSS 0.13%via NVD
CVE-2026-81871Medium· 6.3
5d ago

OpenTelemetry-Go is the Go implementation of OpenTelemetry

OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to version 0.21.0, the exporters/otlp/otlplog/otlploggrpc package loads OTEL_EXPORTER_OTLP_LOGS_CERTIFICATE, OTEL_EXPORTER_OTLP_CERTIFICATE, and related client certificate…

Sunlitopen-telemetry · opentelemetry-goEPSS 0.20%via NVD
CVE-2026-20323High· 8.3
5d ago

A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure FMC Software and Cisco Secure FTD Software could allow an unauthenticated, adjacent attacker to impersonate the peer device and obtain access at the leve…

A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure FMC Software and Cisco Secure FTD Software could allow an unauthenticated, adjacent attacker to impersonate the peer device and obtain access at the leve…

TwilightCisco · Cisco Secure Firewall Management Center (FMC)EPSS 0.09%via NVD
CVE-2026-86474High· 7.7
5d ago

The lack of TLS certificate validation when downloading firmware updates in VEO and VEO-XS Wi-Fi monitors, in versions prior to 01.48.001, allows an attacker to perform man-in-the-middle attacks on the update channel.

The lack of TLS certificate validation when downloading firmware updates in VEO and VEO-XS Wi-Fi monitors, in versions prior to 01.48.001, allows an attacker to perform man-in-the-middle attacks on the update channel.

TwilightFermax Electronica S.A.U. · DUOX PLUS monitor firmware (VEO Wi-Fi range)EPSS 0.11%via NVD
CVE-2026-13327High· 8.3
6d ago

Improper certificate validation on LDAPS connections to Active Directory in Devolutions Server 2026.2.16 and earlier allows a network-positioned attacker to intercept privileged directory service credentials via a spoofed domain controll…

Improper certificate validation on LDAPS connections to Active Directory in Devolutions Server 2026.2.16 and earlier allows a network-positioned attacker to intercept privileged directory service credentials via a spoofed domain controll…

TwilightDevolutions · ServerEPSS 0.13%via NVD
CVE-2026-84850Medium· 4.8
6d ago

Improper certificate validation in the shared HTTP client used by synchronization and integration features in Devolutions Server 2026.2.16 and earlier allows a network-positioned attacker to intercept and tamper with outbound TLS connect…

Improper certificate validation in the shared HTTP client used by synchronization and integration features in Devolutions Server 2026.2.16 and earlier allows a network-positioned attacker to intercept and tamper with outbound TLS connect…

SunlitDevolutions · ServerEPSS 0.10%via NVD
CVE-2026-52724Medium· 5.8
6d ago

Kuma is a modern Envoy-based service mesh that can run on every cloud across both Kubernetes and VMs

Kuma is a modern Envoy-based service mesh that can run on every cloud across both Kubernetes and VMs. Prior to 2.7.26, 2.9.16, 2.11.14, 2.12.11, and 2.13.7, Universal mode kuma-dp connections to an HTTPS control plane disable TLS peer ve…

Sunlitkumahq · kumaEPSS 0.24%via NVD
CVE-2026-50166Medium· 5.5
6d ago

Kuma is a modern Envoy-based service mesh that can run on every cloud across both Kubernetes and VMs

Kuma is a modern Envoy-based service mesh that can run on every cloud across both Kubernetes and VMs. Prior to 2.7.26, 2.9.16, 2.11.14, 2.12.11, and 2.13.7, a kumactl profile manually configured for an HTTPS control plane without --ca-ce…

Sunlitkumahq · kumaEPSS 0.18%via NVD
CVE-2026-61668High· 8.1
6d ago

DIRAC is an interware, meaning a software framework for distributed computing

DIRAC is an interware, meaning a software framework for distributed computing. Prior to versions 8.0.79, 9.0.22, and 9.1.10, WorkloadManagementSystem/Utilities/PilotWrapper.py pilotWrapperScript uses ssl._create_unverified_context to dow…

TwilightDIRACGrid · DIRACEPSS 0.24%via NVD
CVE-2026-86881Critical· 9.1
1w ago

A certificate validation issue was addressed with improved certificate validation

A certificate validation issue was addressed with improved certificate validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, w…

Midnightapple · ipadosEPSS 0.31%via NVD
CVE-2026-86889Medium· 4.8
1w ago

A certificate validation issue was addressed with improved certificate validation

A certificate validation issue was addressed with improved certificate validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An attacker in a privileged network position may be able to intercept n…

Sunlitapple · macosEPSS 0.19%via NVD
CVE-2026-90623Low· 3.7PoC
1w ago

A weakness has been identified in andreashappe cochise up to 0.4.1

A weakness has been identified in andreashappe cochise up to 0.4.1. Affected is the function asyncssh.connect of the file src/cochise/ssh_connection.py of the component SSH Host Key Handler. Executing a manipulation can lead to improper …

Twilightandreashappe · cochiseEPSS 0.26%via NVD
CVE-2026-90651High· 8.1
1w ago

Socket Firewall (socketdev/socket-registry-firewall) in registry mode before 2.0.0 does not verify upstream TLS certificates by default

Socket Firewall (socketdev/socket-registry-firewall) in registry mode before 2.0.0 does not verify upstream TLS certificates by default. When the api_ssl_verify and upstream_ssl_verify configuration keys are omitted from socket.yml, the …

TwilightSocket · socketdev/socket-registry-firewallEPSS 0.19%via NVD
CVE-2026-90647High· 7.4
1w ago

ASE/Kalkitech ASE2000 V2 Communication Test Set 2.35 through 2.37 on Windows contains an improper certificate validation vulnerability in the IEC 60870-5-104 TLS client (Task Mode)

ASE/Kalkitech ASE2000 V2 Communication Test Set 2.35 through 2.37 on Windows contains an improper certificate validation vulnerability in the IEC 60870-5-104 TLS client (Task Mode). This allows a network-positioned attacker to bypass cer…

TwilightKalkitech · ASE2000 V2 Communication Test SetEPSS 0.14%via NVD
CVE-2026-90452Medium· 6.0
1w ago

Requests from the reverse proxy to the identity-provider service for token discovery, introspection, and credential exchange do not verify the identity provider's server certificate

Requests from the reverse proxy to the identity-provider service for token discovery, introspection, and credential exchange do not verify the identity provider's server certificate. An attacker positioned on the network path between the…

SunlitCISA · MalcolmEPSS 0.09%via NVD
CVE-2026-78491High· 8.2
1w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially ex…

TwilightDell · Secure Connect Gateway 5.0 - ApplicationEPSS 0.16%via CVEORG
CVE-2026-87872Medium· 6.8
1w ago

A flaw was found in the OCAPI modules (ocapi_command, ocapi_info) of the community.general Ansible collection

A flaw was found in the OCAPI modules (ocapi_command, ocapi_info) of the community.general Ansible collection. The shared OCAPI request helper disables TLS certificate validation on every request and the modules expose no parameter to re…

SunlitRed Hat · ansible-collection-community-generalEPSS 0.09%via NVD
CVE-2026-79729Low· 3.7
1w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially ex…

Sunlitdell · secure_connect_gatewayEPSS 0.12%via NVD
CVE-2026-85102Critical· 9.8
1w ago

Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.

Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.

Midnightcheckpoint · Quantum Security GatewayEPSS 0.33%via NVD
CVE-2026-78489Medium· 5.9
1w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially ex…

Sunlitdell · secure_connect_gatewayEPSS 0.13%via NVD
CVE-2026-79967Medium· 5.6
1w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially ex…

Sunlitdell · secure_connect_gatewayEPSS 0.10%via NVD
CVE-2026-80122High· 7.3
1w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially ex…

Twilightdell · secure_connect_gatewayEPSS 0.14%via NVD
CVE-2026-78483Medium· 5.9
1w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially ex…

Sunlitdell · secure_connect_gatewayEPSS 0.13%via NVD
CWE-295 vulnerabilities (CVEs) · VulnSea