VulnSea

CWE-327

CVEs classified under CWE-327, newest first.

35 CVEsRSS

CVE-2025-33147Medium· 5.9
4d ago

IBM Cognos Analytics 12.1.0 through 12.1.3 FP1, and 12.0.4 through 12.0.4 FP2 could allow an attacker on a shared network to obtain sensitive information caused by insecure network communication.

IBM Cognos Analytics 12.1.0 through 12.1.3 FP1, and 12.0.4 through 12.0.4 FP2 could allow an attacker on a shared network to obtain sensitive information caused by insecure network communication.

SunlitIBM · Cognos AnalyticsEPSS 0.21%via NVD
CVE-2024-56344Medium· 5.9
4d ago

IBM Cognos Analytics 12.0.4 through 12.0.4 FP2, and 12.1.0 through 12.1.3 FP1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security

IBM Cognos Analytics 12.0.4 through 12.0.4 FP2, and 12.1.0 through 12.1.3 FP1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could explo…

SunlitIBM · Cognos AnalyticsEPSS 0.17%via NVD
CVE-2026-54147Medium· 6.5
4d ago

http4k is a functional toolkit for Kotlin HTTP applications

http4k is a functional toolkit for Kotlin HTTP applications. Prior to 4.51.0.0, 5.42.0.0, and 6.50.0.0, DigestAuthProvider.verify in http4k-security-digest ignores its configured algorithm parameter and verifies every Digest response wit…

Sunlithttp4k · http4kEPSS 0.20%via NVD
CVE-2026-81438Low· 3.7
5d ago

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains Use of a Broken or Risky Cryptographic Algorithm vulnerability

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains Use of a Broken or Risky Cryptographic Algorithm vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leadi…

SunlitDell · Dell OpenManage Server Administrator Managed Node (Patch) for WindowsEPSS 0.18%via NVD
CVE-2025-36591Medium· 4.4
6d ago

Dell ECS versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.4.0.0, contains an Use of a Broken or Risky Cryptographic Algorithm vulnerability

Dell ECS versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.4.0.0, contains an Use of a Broken or Risky Cryptographic Algorithm vulnerability. A high privileged attacker with local access could potentially exploit…

SunlitDell · Elastic Cloud Storage (ECS)EPSS 0.11%via NVD
CVE-2026-15638Critical· 9.1
6d ago

An unauthenticated user with access to Secret Server could leverage a padding oracle to decrypt or encrypt data using one of the server's cryptographic keys

An unauthenticated user with access to Secret Server could leverage a padding oracle to decrypt or encrypt data using one of the server's cryptographic keys. The key itself is not exposed.

MidnightDelinea · Secret Server (On-Prem)EPSS 0.20%via NVD
CVE-2026-11929High· 7.5
1w ago

IBM Security Verify Identity Access Reverse Proxy in certain configurations may provide weaker than expected cryptographic validation of user supplied data.

IBM Security Verify Identity Access Reverse Proxy in certain configurations may provide weaker than expected cryptographic validation of user supplied data.

TwilightIBM · Verify Identity AccessEPSS 0.16%via NVD
CVE-2026-17467High· 8.2
1w ago

IBM Cloud Pak for Data System (Yosemite 1.0) 3.0.5.2 could allow a remote attacker to obtain sensitive information due to the use of weak or deprecated cryptographic protocols.

IBM Cloud Pak for Data System (Yosemite 1.0) 3.0.5.2 could allow a remote attacker to obtain sensitive information due to the use of weak or deprecated cryptographic protocols.

TwilightIBM · Cloud Pak for Data System (Yosemite 1.0)EPSS 0.28%via NVD
CVE-2026-81822High· 8.4
2w ago

The vulnerability, if exploited, could allow a miscreant with read access to PIMBoards project files to reverse engineer PIMBoards users’ app-native passwords through computational brute-forcing of weak hashes, potentially allowing eleva…

The vulnerability, if exploited, could allow a miscreant with read access to PIMBoards project files to reverse engineer PIMBoards users’ app-native passwords through computational brute-forcing of weak hashes, potentially allowing eleva…

TwilightAVEVA · Pipeline Integrity MonitorEPSS 0.08%via NVD
CVE-2026-69382Medium· 5.9
2w ago

Use of a broken or risky cryptographic algorithm in Microsoft Exchange Server allows an unauthorized attacker to disclose information over a network.

Use of a broken or risky cryptographic algorithm in Microsoft Exchange Server allows an unauthorized attacker to disclose information over a network.

SunlitMicrosoft · Microsoft Exchange Server 2016 Cumulative Update 23EPSS 0.44%via NVD
CVE-2026-16693Medium· 4.4
2w ago

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to the use of hardcoded cryptographic constants to obfuscate encryption keys.

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to the use of hardcoded cryptographic constants to obfuscate encryption keys.

Sunlitibm · iEPSS 0.13%via NVD
CVE-2026-81859Medium· 6.2
2w ago

CP4BA - IBM Enterprise Records could allow a local attacker to obtain sensitive information due to the use of a broken or risky cryptographic algorithm.

CP4BA - IBM Enterprise Records could allow a local attacker to obtain sensitive information due to the use of a broken or risky cryptographic algorithm.

SunlitEPSS 0.11%via NVD
CVE-2026-39944High· 8.8
3w ago

Ceph is an open-source distributed storage platform providing object, block, and file storage

Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2.4 and 19.2.6, the RADOS Gateway (RGW) protects STS session tokens with an AES-128-CBC handler that provides no messa…

TwilightEPSS 0.17%via NVD
CVE-2025-30156High· 8.9
3w ago

Ceph is an open-source distributed storage platform providing object, block, and file storage

Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2.4 and 19.2.6, the CephX authentication protocol encrypts tickets with AES-128-CBC in an unauthenticated mode that us…

TwilightRed Hat · Red Hat Enterprise Linux BaseOS (v. 10)EPSS 0.09%via NVD
CVE-2026-67336High· 8.7
1mo ago

better-auth versions before 1.6.11 contain insecure cryptographic defaults in the oidcProvider and mcp plugins that advertise the none algorithm and accept plain PKCE by default

better-auth versions before 1.6.11 contain insecure cryptographic defaults in the oidcProvider and mcp plugins that advertise the none algorithm and accept plain PKCE by default. Attackers can exploit algorithm negotiation to accept unsi…

TwilightEPSS 0.16%via NVD
CVE-2026-65309High· 7.5
1mo ago

ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions stores and transmits user passwords using a reversible format instead of a one-way password hash

ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions stores and transmits user passwords using a reversible format instead of a one-way password hash. This allows an attacker able to read the credential store or capture network t…

TwilightEPSS 0.15%via NVD
GHSA-9h47-pqcx-hjr4High· 8.7
2mo ago

Better Auth has insecure cryptographic defaults in oidcProvider: alg=none advertised and plain PKCE accepted by default

Better Auth has insecure cryptographic defaults in oidcProvider: alg=none advertised and plain PKCE accepted by default

Twilightbetter-auth · better-authvia GHSA
CVE-2026-14630Low· 3.1
2mo ago

A vulnerability has been found in ForceInjection AI-fundermentals 2.0/3.0

A vulnerability has been found in ForceInjection AI-fundermentals 2.0/3.0. Affected by this vulnerability is the function get_conversation_history of the file 08_agentic_system/memory/langchain/code/smart_customer_service.py of the compo…

SunlitEPSS 0.23%via NVD
CVE-2026-50268Low· 1.9
2mo ago

Steeltoe: OAEP setting silently selects PKCS#1 v1.5 padding

Steeltoe: OAEP setting silently selects PKCS#1 v1.5 padding

SunlitSteeltoe · Steeltoe.Configuration.EncryptionEPSS 0.05%via GHSA
GHSA-fwg2-gr34-q3w8Medium· 4.3
2mo ago

SurrealDB: ES512 silently downgraded to ES384 due to jsonwebtoken crate limitation

SurrealDB: ES512 silently downgraded to ES384 due to jsonwebtoken crate limitation

Sunlitsurrealdb · surrealdbvia GHSA
CVE-2026-13510Low· 3.7
2mo ago

A vulnerability was found in SimStudioAI sim up to 0.6.92

A vulnerability was found in SimStudioAI sim up to 0.6.92. Affected by this vulnerability is an unknown functionality in the library apps/sim/lib/core/security/deployment.ts of the component Password Protection Handler. Performing a mani…

SunlitEPSS 0.31%via NVD
CVE-2026-54780Low· 3.7
3mo ago

CoreWCF: WS-Security Reference DigestMethod Algorithm-Suite Bypass

CoreWCF: WS-Security Reference DigestMethod Algorithm-Suite Bypass

SunlitCoreWCF · CoreWCF.PrimitivesEPSS 0.24%via GHSA
CVE-2026-40996Medium· 4.8
3mo ago

Wss4jSecurityInterceptor defaulted allowRSA15KeyTransportAlgorithm to true, overriding Apache WSS4J's safer default for validation RequestData

Wss4jSecurityInterceptor defaulted allowRSA15KeyTransportAlgorithm to true, overriding Apache WSS4J's safer default for validation RequestData. Inbound WS-Security decryption could therefore accept RSA PKCS#1 v1.5 (rsa-1_5) encrypted key…

Sunlitbroadcom · spring_web_servicesEPSS 0.13%via NVD
CVE-2026-5588High· 7.5
5mo ago

Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc

Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcpkix on all (pkix modules), Legion of the Bouncy Castle Inc. BCPKIX-FIPS bcpkix on All (pkix modules), Legion of the Bouncy Cast…

TwilightLegion of the Bouncy Castle Inc. · bcpkixEPSS 0.78%via NVD
CVE-2025-14813High· 7.5
5mo ago

: Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc

: Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on all (core modules). This vulnerability is associated with program files G3413CTRBlockCipher. This issue affects B…

TwilightLegion of the Bouncy Castle Inc. · bcprovEPSS 0.32%via NVD
CVE-2025-14859None
5mo ago

The Semtech LR11xx LoRa transceivers implement secure boot functionality using digital signatures to authenticate firmware

The Semtech LR11xx LoRa transceivers implement secure boot functionality using digital signatures to authenticate firmware. However, the implementation uses a non-standard cryptographic hashing algorithm that is vulnerable to second prei…

SunlitEPSS 0.11%via NVD
CVE-2026-5682Low· 3.7PoC
5mo ago

A vulnerability has been found in Meesho Online Shopping App up to 27.3 on Android

A vulnerability has been found in Meesho Online Shopping App up to 27.3 on Android. Affected is an unknown function of the file /api/endpoint of the component com.meesho.supply. Such manipulation leads to risky cryptographic algorithm. T…

TwilightEPSS 0.19%via NVD
CVE-2024-22347Medium· 5.9
1y ago

IBM DevOps Velocity 5.0.0 and IBM UrbanCode Velocity 4.0.0 through 4.0

IBM DevOps Velocity 5.0.0 and IBM UrbanCode Velocity 4.0.0 through 4.0. 25 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.

Sunlithcltech · devops_velocityEPSS 0.33%via NVD
CVE-2023-46233Critical· 9.1
2y ago

crypto-js is a JavaScript library of crypto standards

crypto-js is a JavaScript library of crypto standards. Prior to version 4.2.0, crypto-js PBKDF2 is 1,000 times weaker than originally specified in 1993, and at least 1,300,000 times weaker than current industry standard. This is because …

Midnightcrypto-js_project · crypto-jsEPSS 0.64%via NVD
CVE-2021-45485High· 7.5PoC
4y ago

In the IPv6 implementation in the Linux kernel before 5.13.3, net/ipv6/output_core.c has an information leak because of certain use of a hash table which, although big, doesn't properly consider that IPv6-based attackers can typically ch…

In the IPv6 implementation in the Linux kernel before 5.13.3, net/ipv6/output_core.c has an information leak because of certain use of a hash table which, although big, doesn't properly consider that IPv6-based attackers can typically ch…

Midnightnetapp · e-series_santricity_os_controllerEPSS 3.6%via NVD
CWE-327 vulnerabilities (CVEs) · VulnSea