VulnSea

CWE-326

CVEs classified under CWE-326, newest first.

13 CVEsRSS

CVE-2026-86824Medium· 4.8
5d ago

The Newsletter WordPress plugin before 9.3.8 does not generate its email tracking signing key with sufficient entropy and signs its tracking links with an unkeyed hash, allowing an unauthenticated attacker who recovers that key offline …

The Newsletter WordPress plugin before 9.3.8 does not generate its email tracking signing key with sufficient entropy and signs its tracking links with an unkeyed hash, allowing an unauthenticated attacker who recovers that key offline …

SunlitEPSS 0.10%via NVD
CVE-2026-77405Critical· 9.4
6d ago

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, tlsConfigFromURI in uri.go creates tls.Config values without setting MinVersion to tls.VersionTLS12. Builds using a Go runtime whose default permits TLS 1.0 or TLS 1.1 can t…

Midnightrabbitmq · amqp091-goEPSS 0.23%via NVD
CVE-2026-86670Low· 3.7PoC
2w ago

A flaw has been found in aircheng-org iWebShop-5 up to 5.15

A flaw has been found in aircheng-org iWebShop-5 up to 5.15. This impacts an unknown function of the file controllers/admin.php of the component Authentication Storage. Executing a manipulation of the argument Password can lead to passwo…

Twilightaircheng-org · iWebShop-5EPSS 0.25%via NVD
CVE-2023-54356Low· 3.7
3w ago

Kyverno versions 1.9.4 and earlier support insecure 3DES cipher suites (TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA and TLS_RSA_WITH_3DES_EDE_CBC_SHA) on their TLS endpoints

Kyverno versions 1.9.4 and earlier support insecure 3DES cipher suites (TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA and TLS_RSA_WITH_3DES_EDE_CBC_SHA) on their TLS endpoints. These 64-bit block ciphers are vulnerable to the Sweet32 attack (CVE-2…

Sunlitkyverno · github.com/kyverno/kyvernoEPSS 0.15%via NVD
CVE-2026-17520Medium· 4.8
3w ago

The Newsletters WordPress plugin before 4.17 does not generate its API key using a sufficiently random source, deriving it from a publicly known value, allowing unauthenticated attackers to compute the key and perform privileged actions …

The Newsletters WordPress plugin before 4.17 does not generate its API key using a sufficiently random source, deriving it from a publicly known value, allowing unauthenticated attackers to compute the key and perform privileged actions …

SunlitEPSS 0.12%via NVD
CVE-2026-79084Medium· 4.3
4w ago

Inadequate encryption strength in Notifications in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page

Inadequate encryption strength in Notifications in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severit…

SunlitGoogle · ChromeEPSS 0.13%via CVEORG
CVE-2026-65777Medium· 5.3
1mo ago

Active Directory Security Feature Bypass Vulnerability

Inadequate encryption strength in Windows Active Directory allows an authorized attacker to bypass a security feature over a network.

SunlitMicrosoft · Windows 11 version 23H2EPSS 0.29%via CVEORG
CVE-2026-59651High· 7.5
1mo ago

In Bouncy Castle for Java before 1.85, BKS keystore accepts legacy version with 16-bit integrity MAC key

In Bouncy Castle for Java before 1.85, BKS keystore accepts legacy version with 16-bit integrity MAC key. This issue also affects Bouncy Castle for Java LTS before 2.73.12.

TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.16%via NVD
CVE-2026-45363Critical· 9.1
2mo ago

ruby-jwt is a Ruby implementation of the RFC 7519 OAuth JSON Web Token standard

ruby-jwt is a Ruby implementation of the RFC 7519 OAuth JSON Web Token standard. Prior to 2.10.3 and 3.2.0, JWT.decode(token, '', true, algorithm: 'HS256') accepts an attacker-forged token because OpenSSL::HMAC.digest('SHA256', '', paylo…

Midnightjwt · ruby-jwtEPSS 0.26%via NVD
CVE-2026-49852High
2mo ago

joserfc: HS256/HS384/HS512 verify accepts empty/nil HMAC key (cross-language sibling of CVE-2026-45363)

joserfc: HS256/HS384/HS512 verify accepts empty/nil HMAC key (cross-language sibling of CVE-2026-45363)

Twilightjoserfc · joserfcEPSS 0.19%via OSV
CVE-2023-29549Medium· 6.5
3y ago

Under certain circumstances, a call to the <code>bind</code> function may have resulted in the incorrect realm

Under certain circumstances, a call to the <code>bind</code> function may have resulted in the incorrect realm. This may have created a vulnerability relating to JavaScript-implemented sandboxes such as SES. This vulnerability affects Fi…

Sunlitmozilla · firefoxEPSS 0.33%via NVD
CVE-2021-42216Critical· 9.8
4y ago

A Broken or Risky Cryptographic Algorithm exists in AnonAddy 0.8.5 via VerificationController.php.

A Broken or Risky Cryptographic Algorithm exists in AnonAddy 0.8.5 via VerificationController.php.

Midnightanonaddy · anonaddyEPSS 1.2%via NVD
CVE-2020-3549High· 8.1
5y ago

A vulnerability in the sftunnel functionality of Cisco Firepower Management Center (FMC) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to obtain the device registration hash

A vulnerability in the sftunnel functionality of Cisco Firepower Management Center (FMC) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to obtain the device registration hash. T…

Twilightcisco · secure_firewall_management_centerEPSS 0.95%via NVD
CWE-326 vulnerabilities (CVEs) · VulnSea