Skip to main content

CWE archive

CWE-323 CVEs

Programmatic archive

42 CVEs tagged with CWE-3235 Critical, 10 High, 25 Medium, 2 Low, 0 Unrated.

CVE-2026-59099

Published Jul 2, 2026

Apereo CAS 7.3.0 before 8.0.0-RC6 contains a cryptographic vulnerability that allows remote unauthenticated attackers to recover plaintext conversation state by exploiting AES-GCM…

CVSS 9.3 · Critical
evidence mentions
5
Buzz score
29.4

CVE-2026-13602

Published Jul 1, 2026

We found a chain of combining multiple weaknesses in the product that could allow an attacker to become any user in the backend and access any data: * The payment int…

CVSS 7.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-56369

Published Jun 30, 2026

ImageMagick before 7.1.2-22 contains an information disclosure vulnerability in the PasskeyEncipherImage method due to AES-CTR nonce reuse. Attackers can exploit nonce reuse in th…

CVSS 6.3 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-55967

Published Jun 25, 2026

AES-GCM encryption/decryption with extremely large cumulative single message sizes (>64 GiB) were not properly rejected by the streaming APIs, allowing counter wrap, keystream reu…

CVSS 2.0 · Low
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2026-12205

Published Jun 15, 2026

Crypt::DSA versions before 1.21 for Perl reused the nonce across signatures, leading to private-key recovery. Crypt::DSA::sign caches the per-signature nonce material in the Key…

CVSS 9.1 · Critical
evidence mentions
3
Buzz score
23.9

CVE-2026-49952

Published Jun 15, 2026

Discuz! X5.0 releases 20260320 through 20260501 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to gain unauthorized access to databas…

CVSS 9.3 · Critical
evidence mentions
5
Buzz score
27.4

CVE-2026-45028

Published May 13, 2026

Astro is a web framework. Astro versions prior to 6.1.10 used AES-GCM encryption to protect the confidentiality and integrity of server island props and slots parameters, but did…

CVSS 2.9 · Low
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-5446

Published Apr 9, 2026

In wolfSSL, ARIA-GCM cipher suites used in TLS 1.2 and DTLS 1.2 reuse an identical 12-byte GCM nonce for every application-data record. Because wc_AriaEncrypt is stateless and pas…

CVSS 6.0 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-3099

Published Mar 12, 2026

A flaw was found in Libsoup. The server-side digest authentication implementation in the SoupAuthDomainDigest class does not properly track issued nonces or enforce the required i…

CVSS 5.8 · Medium
evidence mentions
4
Buzz score
32.6
Vendor/product tagsBeta · best-effort

CVE-2026-25998

Published Feb 19, 2026

strongMan is a management interface for strongSwan, an OpenSource IPsec-based VPN. When storing credentials in the database (private keys, EAP secrets), strongMan encrypts the cor…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-59870

Published Jan 16, 2026

HCL MyXalytics  is affected by improper management of a static JWT signing secret in the web application, where the secret lacks rotation , introducing a security risk

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2025-61739

Published Dec 22, 2025

Due to Nonce reuse, attackers can perform reply attack or decrypt captured packets.

CVSS 7.2 · High

CVE-2025-64767

Published Nov 21, 2025

hpke-js is a Hybrid Public Key Encryption (HPKE) module built on top of Web Cryptography API. Prior to version 1.7.5, the public SenderContext Seal() API has a race condition whic…

CVSS 9.1 · Critical

CVE-2025-46632

Published May 1, 2025

Initialization vector (IV) reuse in the web management portal of the Tenda RX2 Pro 16.03.30.14 may allow an attacker to discern information about or more easily decrypt encrypted…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-37660

Published Feb 11, 2025

In hostapd 2.10 and earlier, the PKEX code remains active even after a successful PKEX association. An attacker that successfully bootstrapped public keys with another entity usin…

CVSS 6.5 · Medium
evidence mentions
5
Buzz score
37.9
Vendor/product tagsBeta · best-effort

CVE-2024-11022

Published Dec 6, 2024

The authentication process to the web server uses a challenge response procedure which inludes the nonce and additional information. This challenge can be used several times for l…

CVSS 5.6 · Medium

CVE-2024-21530

Published Oct 2, 2024

Versions of the package cocoon before 0.4.0 are vulnerable to Reusing a Nonce, Key Pair in Encryption when the encrypt, wrap, and dump functions are sequentially called. An attack…

CVSS 4.5 · Medium

CVE-2024-41951

Published Jul 31, 2024

Pheonix App is a Python application designed to streamline various tasks, from managing files to playing mini-games. The issue is that the map of encoding/decoding languages are v…

CVSS 4.4 · Medium

CVE-2024-36289

Published Jun 17, 2024

Reusing a nonce, key pair in encryption issue exists in "FreeFrom - the nostr client" App versions prior to 1.3.5 for Android and iOS. If this vulnerability is exploited, the cont…

CVSS 5.3 · Medium

CVE-2023-7003

Published Mar 15, 2024

The AES key utilized in the pairing process between a lock using Sciener firmware and a wireless keypad is not unique, and can be reused to compromise other locks using the Sciene…

CVSS 6.8 · Medium
evidence mentions
1
Buzz score
11.9
Showing 1-25 of 42 CVEsPage 1 of 2