VulnSea

CWE-325

CVEs classified under CWE-325, newest first.

13 CVEsRSS

CVE-2026-81235High· 8.0
1w ago

Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain a Missing Cryptographic Step vulnerability

Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain a Missing Cryptographic Step vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Information tampering.

Twilightdell · wyse_management_suiteEPSS 0.15%via NVD
CVE-2026-25250Medium· 6.0PoC
3w ago

EAZ EazyFix 12.9 allows a Security Feature Bypass related to a "Missing Cryptographic Step" associated with "Secure Boot disable."

EAZ EazyFix 12.9 allows a Security Feature Bypass related to a "Missing Cryptographic Step" associated with "Secure Boot disable."

Twilighteazsolution · EazyFixEPSS 0.09%via NVD
CVE-2026-17666Critical· 9.1
1mo ago

Cryptographic Flaw in Enterprise in Google Chrome prior to 151.0.7922.72 allowed an attacker in a privileged network position to bypass discretionary access control via malicious network traffic

Cryptographic Flaw in Enterprise in Google Chrome prior to 151.0.7922.72 allowed an attacker in a privileged network position to bypass discretionary access control via malicious network traffic. (Chromium security severity: High)

Midnightgoogle · chromeEPSS 0.24%via NVD
CVE-2026-55144High· 7.1
2mo ago

Windows Cryptography API: Next Generation (CNG) Tampering Vulnerability

Missing cryptographic step in Windows CryptoAPI allows an authorized attacker to perform tampering locally.

TwilightMicrosoft · Windows 11 Version 24H2EPSS 0.22%via CVEORG
CVE-2026-58638Medium· 6.0
2mo ago

Windows Boot Loader Security Feature Bypass Vulnerability

Missing cryptographic step in Windows Boot Loader allows an authorized attacker to bypass a security feature locally.

SunlitMicrosoft · Windows 10 Version 1809EPSS 0.24%via CVEORG
CVE-2026-48480Medium
3mo ago

OHttpVersionChunkDraft: Missing Final-Chunk Enforcement Leads to Undetected Stream Truncation

OHttpVersionChunkDraft: Missing Final-Chunk Enforcement Leads to Undetected Stream Truncation

Sunlitnetty · io.netty.incubator:netty-incubator-codec-ohttpEPSS 0.17%via GHSA
CVE-2026-49440High· 7.4
3mo ago

Deno: Miller-Rabin Primality Test Allows Zero Rounds

Deno: Miller-Rabin Primality Test Allows Zero Rounds

Twilightdeno · denoEPSS 0.24%via GHSA
CVE-2026-42246High· 7.4
4mo ago

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.3.10, 0.4.24, 0.5.14, and 0.6.4, a man-in-the-middle attacker can cause Net::IMAP#starttls to return "successfully", without s…

Twilightruby-lang · net::imapEPSS 0.31%via NVD
CVE-2026-40542High· 7.3
5mo ago

Missing critical step in authentication in Apache HttpClient 5.6 allows an attacker to cause the client to accept SCRAM-SHA-256 authentication without proper mutual authentication verification

Missing critical step in authentication in Apache HttpClient 5.6 allows an attacker to cause the client to accept SCRAM-SHA-256 authentication without proper mutual authentication verification. Users are recommended to upgrade to version…

Twilightapache · httpclientEPSS 0.56%via NVD
CVE-2026-4601High· 8.7
6mo ago

Versions of the package jsrsasign before 11.1.1 are vulnerable to Missing Cryptographic Step via the KJUR.crypto.DSA.signWithMessageHash process in the DSA signing implementation

Versions of the package jsrsasign before 11.1.1 are vulnerable to Missing Cryptographic Step via the KJUR.crypto.DSA.signWithMessageHash process in the DSA signing implementation. An attacker can recover the private key by forcing r or s…

Twilightkjur · jsrsasignEPSS 0.30%via NVD
CVE-2026-4258High· 7.5
6mo ago

Versions of the package sjcl before 1.0.9 are vulnerable to Improper Verification of Cryptographic Signature due to missing point-on-curve validation in sjcl.ecc.basicKey.publicKey()

Versions of the package sjcl before 1.0.9 are vulnerable to Improper Verification of Cryptographic Signature due to missing point-on-curve validation in sjcl.ecc.basicKey.publicKey(). An attacker can recover a victim's ECDH private key b…

Twilightbitwiseshiftleft · stanford_javascript_crypto_libraryEPSS 0.25%via NVD
CVE-2026-28498High· 7.5PoC
6mo ago

Authlib is a Python library which builds OAuth and OpenID Connect servers

Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a library-level vulnerability was identified in the Authlib Python library concerning the validation of OpenID Connect (OIDC) ID Tokens. S…

Midnightauthlib · authlibEPSS 0.23%via NVD
CVE-2025-61730Medium· 5.3
7mo ago

crypto/tls: Handshake messages may be processed at the incorrect encryption level in crypto/tls (CVE-2025-61730)

A TLS connection handling flaw has been discovered in the golang crypto/tls library. During the TLS 1.3 handshake if multiple messages are sent in records that span encryption level boundaries (for instance the Client Hello and Encrypted E…

SunlitRed Hat · Red Hat Ceph Storage 6EPSS 0.29%via CSAF
CWE-325 vulnerabilities (CVEs) · VulnSea