Threats Tagged 'cwe-295'
View all threats tagged with 'cwe-295'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-295'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-46734: CWE-295: Improper Certificate Validation in Dell Display and Peripheral ManagerCVE-2026-46734 0 Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3, contain an Improper Certificate Validation vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Protection mechanism bypass. Join the discussion | CVE Database V5 | 06/25/2026, 13:43:51 UTC Added: 06/25/2026, 14:16:22 UTC |
CVE-2026-54323: CWE-295: Improper Certificate Validation in daytonaio daytonaCVE-2026-54323 0 Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. Prior to 0.185.0, the daemon's git clone implementation disabled TLS certificate verification. When a clone request carried Git credentials, the daemon sent the HTTP Basic Authorization header to the remote over a connection whose certificate was never validated, on both the go-git and native git CLI code paths. An attacker able to intercept clone traffic could present any TLS certificate, capture the Git credentials supplied for the clone, and serve tampered repository content into the sandbox. This vulnerability is fixed in 0.185.0. Join the discussion | CVE Database V5 | 06/23/2026, 18:06:21 UTC Added: 06/23/2026, 18:09:40 UTC |
CVE-2025-2669: CWE-295 Improper Certificate Validation in IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for DataCVE-2025-2669 0 IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions 4.8, 5.0, 5.1, 5.2, 5.3 could allow a privileged user to perform operations and obtain sensitive information outside of their authority due to improper token validation. Join the discussion | CVE Database V5 | 06/22/2026, 13:18:42 UTC Added: 06/22/2026, 13:54:17 UTC |
CVE-2024-47477: CWE-295: Improper Certificate Validation in Dell PowerFlex ManagerCVE-2024-47477 0 Dell PowerFlex Manager versions prior to 4.5.1.1 have an improper certificate validation vulnerability (CWE-295). This flaw could allow a remote unauthenticated attacker to perform a man-in-the-middle attack when combined with DNS cache poisoning. The vulnerability has a CVSS score of 6.5, indicating a medium severity level. No official patch or remediation guidance has been provided yet by the vendor. Join the discussion | CVE Database V5 | 06/17/2026, 14:11:39 UTC Added: 06/17/2026, 15:07:07 UTC |
CVE-2025-71261: CWE-295 in SUSE HarvesterCVE-2025-71261 0 An attacker with network-level access between the SUSE Virtualization and Rancher Manager in SUSE Harvester before 1.8.0 could interfere with the TLS handshake and abuse it to bypass TLS as a security control. Join the discussion | CVE Database V5 | 06/16/2026, 15:42:32 UTC Added: 06/16/2026, 18:30:58 UTC |
CVE-2026-9259: CWE-295 Improper certificate validation in Canon Inc. EOS Network Setting Tool for WindowsCVE-2026-9259 0 Improper validation of server certificates in Canon EOS Network Setting Tool Version 1.5.0 or earlier Join the discussion | CVE Database V5 | 06/15/2026, 23:36:28 UTC Added: 06/16/2026, 00:00:41 UTC |
CVE-2026-9258: CWE-295 Improper certificate validation in Canon Inc. EOS Network Setting Tool for WindowsCVE-2026-9258 0 Improper validation of SSH host keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier Join the discussion | CVE Database V5 | 06/15/2026, 23:35:41 UTC Added: 06/16/2026, 00:00:41 UTC |
CVE-2026-45170: CWE-295 - Improper Certificate Validation in CyberArk Software, a Palo Alto Networks Company Vendor PAMCVE-2026-45170 0 Idira Vendor PAM - Self-Hosted Connector versions prior 1.1.100504 under specific conditions and configuration scenarios, TLS certificate validation may not be fully enforced. CyberArk Security Bulletin: CA26-17 Join the discussion | CVE Database V5 | 06/12/2026, 00:05:43 UTC Added: 06/12/2026, 01:30:25 UTC |
CVE-2026-45175: CWE-295: Improper Certificate Validation in CyberArk Software, a Palo Alto Networks Company Idira Endpoint Privilege ManagerCVE-2026-45175 0 Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within internal agent validation processes. A local attacker could potentially bypass built-in security controls or cryptographic validations. Under specific circumstances, this could allow the attacker to circumvent agent self-defense mechanisms and execute unauthorized operations. CyberArk Security Bulletin: CA26-19 Join the discussion | CVE Database V5 | 06/11/2026, 18:57:08 UTC Added: 06/11/2026, 20:00:08 UTC |
CVE-2026-9648: CWE-295: Improper Certificate Validation in Haskell Programming Language crypton-certificateCVE-2026-9648 0 The crypton-x509-validation Haskell library does not properly enforce X.509 NameConstraints, allowing TLS clients to accept certificates with Subject Alternative Names outside the permitted subtrees of the issuing CA. This vulnerability enables an attacker who compromises a name-constrained sub-CA to impersonate domains beyond its intended scope. The issue is classified under CWE-295 (Improper Certificate Validation) and has a critical CVSS score of 9.1. Join the discussion | CVE Database V5 | 06/11/2026, 14:30:30 UTC Added: 06/11/2026, 15:30:09 UTC |
Showing 1 to 10 of 22 results