VulnSea

CWE-295

CVEs classified under CWE-295, newest first.

187 CVEsRSS

CVE-2025-58123Medium· 4.8
1y ago

Improper Certificate Validation in Checkmk Exchange plugin BGP Monitoring allows attackers in MitM position to intercept traffic.

Improper Certificate Validation in Checkmk Exchange plugin BGP Monitoring allows attackers in MitM position to intercept traffic.

▾ Sunlitoetiker · bgp_monitoringEPSS 0.11%via NVD
CVE-2025-32989Medium· 5.3
1y ago

A heap-buffer-overread vulnerability was found in GnuTLS in how it handles the Certificate Transparency (CT) Signed Certificate Timestamp (SCT) extension during X.509 certificate parsing

A heap-buffer-overread vulnerability was found in GnuTLS in how it handles the Certificate Transparency (CT) Signed Certificate Timestamp (SCT) extension during X.509 certificate parsing. This flaw allows a malicious user to create a cer…

▾ Sunlitgnu · gnutlsEPSS 1.3%via NVD
CVE-2025-6032High· 8.3
1y ago

A flaw was found in Podman

A flaw was found in Podman. The podman machine init command fails to verify the TLS certificate when downloading the VM images from an OCI registry. This issue results in a Man In The Middle attack.

▾ Twilightcontainers · github.com/containers/podman/v4EPSS 0.52%via NVD
CVE-2025-22874High· 7.5
1y ago

crypto/x509: Usage of ExtKeyUsageAny disables policy validation in crypto/x509 (CVE-2025-22874)

A flaw was found in Go's crypto/x509 package. This vulnerability allows improper certificate validation, bypassing policy constraints via using ExtKeyUsageAny in VerifyOptions.KeyUsages.

▾ TwilightRed Hat · Red Hat OpenShift Container Platform 4.20EPSS 0.37%via CSAF
CVE-2021-20327Medium· 6.4
5y ago

A specific version of the Node.js mongodb-client-encryption module does not perform correct validation of the KMS server’s certificate

A specific version of the Node.js mongodb-client-encryption module does not perform correct validation of the KMS server’s certificate. This vulnerability in combination with a privileged network position active MITM attack could result …

▾ Sunlitmongodb · mongodb_client_encryptionEPSS 0.20%via NVD
CVE-2020-1113Medium· 5.3
6y ago

A security feature bypass vulnerability exists in Microsoft Windows when the Task Scheduler service fails to properly verify client connections over RPC

A security feature bypass vulnerability exists in Microsoft Windows when the Task Scheduler service fails to properly verify client connections over RPC. An attacker who successfully exploited this vulnerability could run arbitrary code …

▾ Sunlitmicrosoft · windows_10EPSS 6.1%via NVD
CVE-2018-0227High· 7.5
8y ago

A vulnerability in the Secure Sockets Layer (SSL) Virtual Private Network (VPN) Client Certificate Authentication feature for Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to establish an SSL VPN…

A vulnerability in the Secure Sockets Layer (SSL) Virtual Private Network (VPN) Client Certificate Authentication feature for Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to establish an SSL VPN…

▾ Twilightcisco · secure_firewall_threat_defenseEPSS 2.0%via NVD
CWE-295 vulnerabilities (CVEs) — page 7 · VulnSea