Skip to main content

CWE archive

CWE-325 CVEs

Programmatic archive

58 CVEs tagged with CWE-3253 Critical, 19 High, 32 Medium, 4 Low, 0 Unrated.

CVE-2026-59776

Published Jul 21, 2026

Missing Cryptographic Step (CWE-325) vulnerability exists in certain FeliCa IC chips shipped in or before 2017. If the vulnerability is exploited, information stored in the IC chi…

CVSS 7.0 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-6458

Published Jun 24, 2026

Missing cryptographic step in Caliptra Core Firmware (aes_256_gcm_update module) results in an incorrect GCM authentication tag. When the streaming AES-256-GCM API is used with em…

CVSS 5.1 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-49440

Published Jun 23, 2026

Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.8.1, node:crypto.checkPrime(candidate[, options][, callback]) and crypto.checkPrimeSync(candidate[, options])…

CVSS 7.4 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-9266

Published Jun 12, 2026

A Missing Required Cryptographic Step vulnerability has been identified in Moxa's embedded Linux firmware for industrial computers and controllers. This vulnerability represents a…

CVSS 7.0 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-45446

Published Jun 9, 2026

Issue summary: The implementations of AES-SIV (RFC 5297) and AES-GCM-SIV (RFC 8452) mishandle the authentication of AAD (Additional Authenticated Data) with an empty ciphertext al…

CVSS 4.8 · Medium
evidence mentions
7
Buzz score
35.8
Vendor/product tagsBeta · best-effort

CVE-2026-45445

Published Jun 9, 2026

Issue summary: When an application drives an AES-OCB context through the public EVP_Cipher() one-shot interface, the application-supplied initialisation vector (IV) is silently di…

CVSS 7.5 · High
evidence mentions
7
Buzz score
35.8
Vendor/product tagsBeta · best-effort

CVE-2026-42770

Published Jun 9, 2026

Issue summary: When EVP_PKEY_derive_set_peer() is called with a DHX (X9.42) peer key, the peer key is not properly checked for the subgroup membership. Impact summary: A maliciou…

CVSS 3.7 · Low
evidence mentions
7
Buzz score
35.8
Vendor/product tagsBeta · best-effort

CVE-2026-48480

Published Jun 4, 2026

The netty incubator codec.bhttp is a java language binary http parser. Prior to version 0.0.22.FInal, the codec-ohttp implementation of draft-ietf-ohai-chunked-ohttp does not veri…

CVSS 6.6 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-41395

Published Apr 28, 2026

OpenClaw before 2026.3.28 contains a webhook replay vulnerability in Plivo V3 signature verification that canonicalizes query ordering for signatures but hashes raw URLs for repla…

CVSS 8.2 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-40542

Published Apr 22, 2026

Missing critical step in authentication in Apache HttpClient 5.6 allows an attacker to cause the client to accept SCRAM-SHA-256 authentication without proper mutual authentication…

CVSS 7.3 · High
evidence mentions
5
Buzz score
32.4
Vendor/product tagsBeta · best-effort

CVE-2026-29142

Published Apr 2, 2026

SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to forge a GINA-encrypted email.

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-4601

Published Mar 23, 2026

Versions of the package jsrsasign before 11.1.1 are vulnerable to Missing Cryptographic Step via the KJUR.crypto.DSA.signWithMessageHash process in the DSA signing implementation.…

CVSS 8.8 · High
evidence mentions
15
Buzz score
43.7
Vendor/product tagsBeta · best-effort

CVE-2026-28498

Published Mar 16, 2026

Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a library-level vulnerability was identified in the Authlib Python library conce…

CVSS 8.2 · High
evidence mentions
12
Buzz score
38.6
Vendor/product tagsBeta · best-effort

CVE-2025-69418

Published Jan 27, 2026

Issue summary: When using the low-level OCB API directly with AES-NI or<br>other hardware-accelerated code paths, inputs whose length is not a multiple<br>of 16 bytes can leave th…

CVSS 4.0 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-22863

Published Jan 15, 2026

Deno is a JavaScript, TypeScript, and WebAssembly runtime. Before 2.6.0, node:crypto doesn't finalize cipher. The vulnerability allows an attacker to have infinite encryptions. Th…

CVSS 9.2 · Critical
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2025-59339

Published Sep 17, 2025

The Bastion provides authentication, authorization, traceability and auditability for SSH accesses. Session-recording ttyrec files, may be handled by the provided osh-encrypt-rsyn…

CVSS 4.4 · Medium

CVE-2025-58359

Published Sep 5, 2025

ZF FROST is a Rust implementation of FROST (Flexible Round-Optimised Schnorr Threshold signatures). In versions 2.0.0 through 2.1.0, refresh shares with smaller min_signers will r…

CVSS 6.0 · Medium

CVE-2025-49600

Published Jul 4, 2025

In MbedTLS 3.3.0 before 3.6.4, mbedtls_lms_verify may accept invalid signatures if hash computation fails and internal errors go unchecked, enabling LMS (Leighton-Micali Signature…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 58 CVEsPage 1 of 3