The product does not validate, or incorrectly validates, a certificate.
Volume of CVEs assigned to CWE-295 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
1,446 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-0601HIGH A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates.An attacker could exploit the vulnerability by u | Jan 14, 2020 | 8.1 | 97 | YES | YES |
CVE-2022-26923HIGH Active Directory Domain Services Elevation of Privilege Vulnerability | May 10, 2022 | 8.8 | 96 | YES | YES |
CVE-2009-3555CRITICAL The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, | Nov 9, 2009 | 9.8 | 85 | NO | YES |
The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-mi | May 21, 2015 | 3.7 | 76 | NO | YES |
CVE-2023-27823CRITICAL An authentication bypass in Optoma 1080PSTX C02 allows an attacker to access the administration console without valid credentials. | May 12, 2023 | 9.8 | 72 | NO | YES |
CVE-2022-20703HIGH Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate pr | Feb 10, 2022 | 8.0 | 69 | YES | NO |
CVE-2023-20963HIGH In WorkSource, there is a possible parcel mismatch. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed | Mar 24, 2023 | 7.8 | 65 | YES | NO |
CVE-2023-41991MEDIUM A certificate validation issue was addressed. This issue is fixed in macOS Ventura 13.6, iOS 16.7 and iPadOS 16.7. A malicious app may be able to bypass signature validation. Apple | Sep 21, 2023 | 5.5 | 59 | YES | NO |
CVE-2017-2800CRITICAL A specially crafted x509 certificate can cause a single out of bounds byte overwrite in wolfSSL through 3.10.2 resulting in potential certificate validation vulnerabilities, denial | May 24, 2017 | 9.8 | 46 | NO | YES |
CVE-2026-13385CRITICAL An Improper Validation of Integrity Check Value and Improper Certificate Validation in certain ASUS router models allows a remote man-in-the-middle(MITM) user to make the router do | Jul 15, 2026 | 9.5 | 43 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.