The product does not check or incorrectly checks the revocation status of a certificate, which may cause it to use a certificate that has been compromised.
Volume of CVEs assigned to CWE-299 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-9636HIGH A security issue exists within CompactLogix® 5380, ControlLogix® 5580, and EN4 communication modules related to CIP Security certificate revocation handling. The security issue ste | Jul 14, 2026 | 8.2 | 32 | NO | NO |
CVE-2025-3085CRITICAL A MongoDB server under specific conditions running on Linux with TLS and CRL revocation status checking enabled, fails to check the revocation status of the intermediate certificat | Apr 1, 2025 | 9.8 | 30 | NO | NO |
CVE-2026-6899MEDIUM Check for certificate revocation only considers the first matching CRL and ignores other valid CRLs of the same CA in the CycloneCrypto cryptographic wrapper of S2OPC library. It m | Jun 9, 2026 | 5.6 | 27 | NO | NO |
CVE-2026-4428HIGH A logic error in CRL distribution point validation in AWS-LC before 1.71.0 causes partitioned CRLs to be incorrectly rejected as out of scope, which allows a revoked certificate t | Mar 19, 2026 | 7.4 | 26 | NO | NO |
CVE-2025-11955HIGH Incorrect validation of OCSP certificates vulnerability in TheGreenBow VPN, versions 7.5 and 7.6. During the IKEv2 authentication step, the OCSP-enabled VPN client establishes the | Oct 27, 2025 | 8.2 | 26 | NO | NO |
CVE-2023-23690HIGH
Cloud Mobility for Dell EMC Storage, versions 1.3.0.X and below contains an Improper Check for Certificate Revocation vulnerability. A threat actor does not need any specific priv | Jan 19, 2023 | 7.0 | 23 | NO | NO |
CVE-2020-1675HIGH When Security Assertion Markup Language (SAML) authentication is enabled, Juniper Networks Mist Cloud UI might incorrectly process invalid authentication certificates which could a | Oct 16, 2020 | 8.3 | 23 | NO | NO |
CVE-2020-16228MEDIUM In Patient Information Center iX (PICiX) Versions C.02 and C.03,
PerformanceBridge Focal Point Version A.01, IntelliVue patient monitors
MX100, MX400-MX550, MX750, MX850, and Int | Sep 11, 2020 | 6.4 | 17 | NO | NO |
CVE-2025-36057MEDIUM IBM Cognos Analytics Mobile (iOS) 1.1.0 through 1.1.22
is vulnerable to authentication bypass by using the Local Authentication Framework library which is not needed as biometric | Jul 21, 2025 | 4.6 | 15 | NO | NO |
CVE-2024-56138MEDIUM notion-go is a collection of libraries for supporting sign and verify OCI artifacts. Based on Notary Project specifications. This issue was identified during Quarkslab's audit of t | Jan 13, 2025 | 4.0 | 14 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.