Skip to main content

CWE archive

CWE-1240 CVEs

Programmatic archive

20 CVEs tagged with CWE-12401 Critical, 6 High, 9 Medium, 4 Low, 0 Unrated.

CVE-2026-50303

Published Jul 14, 2026

Use of a cryptographic primitive with a risky implementation in Windows Key Guard allows an authorized attacker to bypass a security feature locally.

CVSS 5.5 · Medium
evidence mentions
4
Buzz score
29.1

CVE-2026-46654

Published Jun 10, 2026

Plonky3 is a toolkit for polynomial IOPs (PIOPs). Prior to versions 0.4.3 and 0.5.3, an attacker controlling prover-side observations can craft distinct transcripts that produce i…

CVSS 8.9 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-44410

Published May 26, 2026

This vulnerability stems from a business logic flaw.Attackers can exploit legitimate application functions in unintended and abnormal ways, deviating from the designer's expectati…

CVSS 3.8 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-29146

Published Apr 9, 2026

Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.0.0-M1 th…

CVSS 7.5 · High
evidence mentions
20
Buzz score
44.5
Vendor/product tagsBeta · best-effort

CVE-2025-64647

Published Mar 25, 2026

IBM Concert 1.0.0 through 2.2.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2026-27017

Published Feb 20, 2026

uTLS is a fork of crypto/tls, created to customize ClientHello for fingerprinting resistance while still using it for the handshake. Versions 1.6.0 through 1.8.0 contain a fingerp…

CVSS 2.3 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-62514

Published Jan 29, 2026

Parsec is a cloud-based application for cryptographically secure file sharing. In versions on the 3.x branch prior to 3.6.0, `libparsec_crypto`, a component of the Parsec applicat…

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2026-22705

Published Jan 10, 2026

RustCrypto: Signatures offers support for digital signatures, which provide authentication of data using public-key cryptography. Prior to version 0.1.0-rc.2, a timing side-channe…

CVSS 6.4 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2025-14505

Published Jan 8, 2026

The ECDSA implementation of the Elliptic package generates incorrect signatures if an interim value of 'k' (as computed based on step 3.2 of RFC 6979 https://datatracker.ietf.org…

CVSS 5.6 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2025-53960

Published Dec 12, 2025

When issuing JSON Web Tokens (JWT), Apache StreamPark directly uses the user's password as the HMAC signing key (e.g., with the HS256 algorithm). An attacker can exploit this vuln…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-46424

Published Nov 5, 2025

Dell CloudLink, versions prior to 8.2, contain use of a Cryptographic Primitive with a Risky Implementation vulnerability. A high privileged attacker could potentially exploit thi…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-58720

Published Oct 14, 2025

Use of a cryptographic primitive with a risky implementation in Windows Cryptographic Services allows an authorized attacker to disclose information locally.

CVSS 7.8 · High

CVE-2025-29808

Published Apr 8, 2025

Use of a cryptographic primitive with a risky implementation in Windows Cryptographic Services allows an authorized attacker to disclose information locally.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-29779

Published Mar 14, 2025

Post-Quantum Secure Feldman's Verifiable Secret Sharing provides a Python implementation of Feldman's Verifiable Secret Sharing (VSS) scheme. In versions 0.8.0b2 and prior, the `s…

CVSS 5.4 · Medium

CVE-2025-22475

Published Feb 4, 2025

Dell PowerProtect DD, versions prior to DDOS 8.3.0.0, 7.10.1.50, and 7.13.1.10 contains a use of a Cryptographic Primitive with a Risky Implementation vulnerability. A remote atta…

CVSS 3.7 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-24802

Published Jan 30, 2025

Plonky2 is a SNARK implementation based on techniques from PLONK and FRI. Lookup tables, whose length is not divisible by 26 = floor(num_routed_wires / 3) always include the 0 ->…

CVSS 8.6 · High

CVE-2024-37137

Published Jun 28, 2024

Dell Key Trust Platform, v3.0.6 and prior, contains Use of a Cryptographic Primitive with a Risky Implementation vulnerability. A local privileged attacker could potentially explo…

CVSS 3.8 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-51392

Published Feb 23, 2024

Ember ZNet between v7.2.0 and v7.4.0 used software AES-CCM instead of integrated hardware cryptographic accelerators, potentially increasing risk of electromagnetic and differenti…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-0323

Published Feb 5, 2024

The FTP server used on the B&R Automation Runtime supports unsecure encryption mechanisms, such as SSLv3, TLSv1.0 and TLS1.1. An network-based attacker can exploit the flaws to co…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-20 of 20 CVEsPage 1 of 1