A certificate expiration is not validated or is incorrectly validated.
Volume of CVEs assigned to CWE-298 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-67108CRITICAL eProsima Fast-DDS v3.3 was discovered to contain improper validation for ticket revocation, resulting in insecure communications and connections. | Dec 23, 2025 | 10.0 | 38 | NO | NO |
CVE-2025-67109CRITICAL Improper verification of the time certificate in Eclipse Cyclone DDS before v0.10.5 allows attackers to bypass certificate checks and execute commands with System privileges. | Dec 23, 2025 | 10.0 | 37 | NO | NO |
CVE-2024-1248MEDIUM The silent Just-In-Time (JIT) provisioning feature in federated authentication implementations fails to properly segregate user roles during account creation when a federated user | Jul 4, 2026 | 5.3 | 28 | NO | NO |
CVE-2025-61736HIGH Successful exploitation of this vulnerability could result in the product failing to re-establish communication once the certificate expires. | Dec 17, 2025 | 7.1 | 24 | NO | NO |
CVE-2025-59036MEDIUM Infrahub offers a central hub to manage data, templates, and playbooks. Prior to versiond 1.3.9 and 1.4.5, a bug in the authentication logic will cause API tokens that were deleted | Sep 9, 2025 | 5.5 | 20 | NO | NO |
CVE-2023-42446MEDIUM Pow is a authentication and user management solution for Phoenix and Plug-based apps. Starting in version 1.0.14 and prior to version 1.0.34, use of `Pow.Store.Backend.MnesiaCache` | Sep 18, 2023 | 6.5 | 20 | NO | NO |
CVE-2025-4384MEDIUM The MQTT add-on of PcVue fails to verify that a remote device’s certificate has not already expired or has not yet become valid. This allows malicious devices to present certificat | May 6, 2025 | 6.0 | 17 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.