Skip to main content

CWE archive

CWE-1394 CVEs

Programmatic archive

17 CVEs tagged with CWE-13947 Critical, 1 High, 5 Medium, 4 Low, 0 Unrated.

CVE-2026-54887

Published Jul 2, 2026

Use of Default Cryptographic Key vulnerability in Erlang/OTP ssl (DTLS server) allows predictable DTLS cookie computation during the startup window, enabling source address verifi…

CVSS 6.3 · Medium
evidence mentions
5
Buzz score
30.9
Vendor/product tagsBeta · best-effort

CVE-2026-5039

Published Apr 23, 2026

TP-Link TL-WR841N v13 uses DES-CBC encryption in the TDDPv2 debug protocol with a cryptographic key derived from default web management credentials, making the key predictable if…

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-20709

Published Apr 8, 2026

Use of Default Cryptographic Key in the hardware for some Intel(R) Pentium(R) Processor Silver Series, Intel(R) Celeron(R) Processor J Series, Intel(R) Celeron(R) Processor N Seri…

CVSS 5.8 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-2215

Published Feb 9, 2026

A vulnerability was detected in rachelos WeRSS we-mp-rss up to 1.4.8. This issue affects some unknown processing of the file core/auth.py of the component JWT Handler. Performing…

CVSS 2.9 · Low
evidence mentions
4
Buzz score
22.6

CVE-2026-25815

Published Feb 5, 2026

Fortinet FortiOS through 7.6.6 allows attackers to decrypt LDAP credentials stored in device configuration files, as exploited in the wild from 2025-12-16 through 2026 (by default…

CVSS 3.2 · Low
evidence mentions
2
Buzz score
17.5

CVE-2025-41744

Published Dec 2, 2025

Sprecher Automations SPRECON-E series uses default cryptographic keys that allow an unprivileged remote attacker to access all encrypted communications, thereby compromising confi…

CVSS 9.1 · Critical

CVE-2025-41742

Published Dec 2, 2025

Sprecher Automations SPRECON-E-C,  SPRECON-E-P, SPRECON-E-T3 is vulnerable to attack by an unauthorized remote attacker via default cryptographic keys. The use of these keys allow…

CVSS 9.8 · Critical

CVE-2025-1688

Published Apr 15, 2025

Milestone Systems has discovered a security vulnerability in Milestone XProtect installer that resets system configuration password after the upgrading from older versions using s…

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-26849

Published Mar 4, 2025

There is a Hard-coded Cryptographic Key in Docusnap 13.0.1440.24261, and earlier and later versions. This key can be used to decrypt inventory files that contain sensitive informa…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-48956

Published Dec 9, 2024

Serviceware Processes 6.0 through 7.3 before 7.4 allows attackers without valid authentication to send a specially crafted HTTP request to a service endpoint resulting in remote c…

CVSS 9.8 · Critical

CVE-2024-11619

Published Nov 22, 2024

A vulnerability, which was classified as problematic, has been found in macrozheng mall up to 1.0.3. Affected by this issue is some unknown functionality of the component JWT Toke…

CVSS 2.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-10748

Published Nov 4, 2024

A vulnerability, which was classified as problematic, has been found in Cosmote Greece What's Up App 4.47.3 on Android. This issue affects some unknown processing of the file gr/d…

CVSS 2.0 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-1275

Published May 31, 2024

Use of Default Cryptographic Key vulnerability in Baxter Welch Allyn Connex Spot Monitor may allow Configuration/Environment Manipulation.This issue affects Welch Allyn Connex Spo…

CVSS 9.1 · Critical

CVE-2024-29037

Published Mar 20, 2024

datahub-helm provides the Kubernetes Helm charts for deploying Datahub and its dependencies on a Kubernetes cluster. Starting in version 0.1.143 and prior to version 0.2.182, due…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-6451

Published Feb 16, 2024

Publicly known cryptographic machine key in AlayaCare's Procura Portal before 9.0.1.2 allows attackers to forge their own authentication cookies and bypass the application's authe…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort
Showing 1-17 of 17 CVEsPage 1 of 1