VulnSea

CWE-328

CVEs classified under CWE-328, newest first.

10 CVEsRSS

CVE-2026-46488Critical· 9.1PoC
1w ago

motionEye (mEye) is an online interface for a piece of software called "motion," which is a video surveillance program with motion detection

motionEye (mEye) is an online interface for a piece of software called "motion," which is a video surveillance program with motion detection. Prior to 0.44.0, motionEye accepts the client-controlled meye_username and meye_password_hash c…

Abyssalmotioneye-project · motioneyeEPSS 0.27%via NVD
CVE-2026-14630Low· 3.1
2mo ago

A vulnerability has been found in ForceInjection AI-fundermentals 2.0/3.0

A vulnerability has been found in ForceInjection AI-fundermentals 2.0/3.0. Affected by this vulnerability is the function get_conversation_history of the file 08_agentic_system/memory/langchain/code/smart_customer_service.py of the compo…

SunlitEPSS 0.23%via NVD
CVE-2026-13510Low· 3.7
2mo ago

A vulnerability was found in SimStudioAI sim up to 0.6.92

A vulnerability was found in SimStudioAI sim up to 0.6.92. Affected by this vulnerability is an unknown functionality in the library apps/sim/lib/core/security/deployment.ts of the component Password Protection Handler. Performing a mani…

SunlitEPSS 0.31%via NVD
CVE-2026-48488Low
3mo ago

phpMyFAQ has Weak Cryptography - SHA1 for Password Hashing

phpMyFAQ has Weak Cryptography - SHA1 for Password Hashing

Sunlitthorsten · thorsten/phpmyfaqEPSS 0.18%via GHSA
CVE-2026-54266High
3mo ago

@angular/common: Weak 32-Bit Cache Key Hashing in `HttpTransferCache` Leading to Cross-Request Data Leakage and State Poisoning

@angular/common: Weak 32-Bit Cache Key Hashing in `HttpTransferCache` Leading to Cross-Request Data Leakage and State Poisoning

Twilightangular · @angular/commonEPSS 0.13%via GHSA
CVE-2026-40164High· 7.5
5mo ago

jq is a command-line JSON processor

jq is a command-line JSON processor. Before commit 0c7d133c3c7e37c00b6d46b658a02244fdd3c784, jq used MurmurHash3 with a hardcoded, publicly visible seed (0x432A9843) for all JSON object hash table operations, which allowed an attacker to…

TwilightEPSS 0.37%via NVD
CVE-2026-21717Medium· 5.9PoC
5mo ago

A flaw in V8's string hashing mechanism causes integer-like strings to be hashed to their numeric value, making hash collisions trivially predictable

A flaw in V8's string hashing mechanism causes integer-like strings to be hashed to their numeric value, making hash collisions trivially predictable. By crafting a request that causes many such collisions in V8's internal string table, …

Twilightnodejs · node.jsEPSS 0.27%via NVD
CVE-2024-47829Medium· 6.5
1y ago

pnpm is a package manager

pnpm is a package manager. Prior to version 10.0.0, the path shortening function uses the md5 function as a path shortening compression function, and if a collision occurs, it will result in the same storage path for two different librar…

SunlitEPSS 0.23%via NVD
CVE-2025-3576Medium· 5.9
1y ago

A vulnerability in the MIT Kerberos implementation allows GSSAPI-protected messages using RC4-HMAC-MD5 to be spoofed due to weaknesses in the MD5 checksum design

A vulnerability in the MIT Kerberos implementation allows GSSAPI-protected messages using RC4-HMAC-MD5 to be spoofed due to weaknesses in the MD5 checksum design. If RC4 is preferred over stronger encryption types, an attacker could expl…

SunlitEPSS 0.34%via NVD
CVE-2023-46233Critical· 9.1
2y ago

crypto-js is a JavaScript library of crypto standards

crypto-js is a JavaScript library of crypto standards. Prior to version 4.2.0, crypto-js PBKDF2 is 1,000 times weaker than originally specified in 1993, and at least 1,300,000 times weaker than current industry standard. This is because …

Midnightcrypto-js_project · crypto-jsEPSS 0.64%via NVD
CWE-328 vulnerabilities (CVEs) · VulnSea