Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CWE-295

Improper Certificate Validation

The product does not validate, or incorrectly validates, a certificate.

1,446
Assigned CVEs
40th
Commonality Rank
6.9
Avg CVSS
0.3%
In CISA KEV

Volume and Severity of Assigned CVEs Over Time

Volume of CVEs assigned to CWE-295 and their average CVSS base score over time.

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 4, 2002
23 years ago
Most Recent CVE
Jul 23, 2026
1 day ago

Top CVEs Assigned This CWE

Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.

1,446 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2020-0601HIGH
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates.An attacker could exploit the vulnerability by u
Jan 14, 20208.197YESYES
CVE-2022-26923HIGH
Active Directory Domain Services Elevation of Privilege Vulnerability
May 10, 20228.896YESYES
CVE-2009-3555CRITICAL
The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier,
Nov 9, 20099.885NOYES
CVE-2015-4000LOW
The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-mi
May 21, 20153.776NOYES
CVE-2023-27823CRITICAL
An authentication bypass in Optoma 1080PSTX C02 allows an attacker to access the administration console without valid credentials.
May 12, 20239.872NOYES
CVE-2022-20703HIGH
Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate pr
Feb 10, 20228.069YESNO
CVE-2023-20963HIGH
In WorkSource, there is a possible parcel mismatch. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed
Mar 24, 20237.865YESNO
CVE-2023-41991MEDIUM
A certificate validation issue was addressed. This issue is fixed in macOS Ventura 13.6, iOS 16.7 and iPadOS 16.7. A malicious app may be able to bypass signature validation. Apple
Sep 21, 20235.559YESNO
CVE-2017-2800CRITICAL
A specially crafted x509 certificate can cause a single out of bounds byte overwrite in wolfSSL through 3.10.2 resulting in potential certificate validation vulnerabilities, denial
May 24, 20179.846NOYES
CVE-2026-13385CRITICAL
An Improper Validation of Integrity Check Value and Improper Certificate Validation in certain ASUS router models allows a remote man-in-the-middle(MITM) user to make the router do
Jul 15, 20269.543NONO
View all 1,446 CVEs →

CVE Severity & Scoring

This CWEGlobal (All CVEs)
0.0-0.9
1.0-1.9
2.0-2.9
3.0-3.9
10%
4.0-4.9
30%
19%
5.0-5.9
9%
16%
6.0-6.9
28%
26%
7.0-7.9
13%
11%
8.0-8.9
10%
14%
9.0-10.0
unknown
CVSS Score Range

Exploit Exposure

Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.

CISA KEV
5 CVEs
0.3% of CVEs· 83rd percentile
Metasploit
2 CVEs
0.1% of CVEs· 79th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
12 CVEs
0.8% of CVEs· 79th percentile

Social Chatter

Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.

Media Mentions

Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.

Top Affected Vendors

Top Affected Products