Skip to main content

CWE archive

CWE-326 CVEs

Programmatic archive

457 CVEs tagged with CWE-32649 Critical, 189 High, 197 Medium, 22 Low, 0 Unrated.

CVE-2026-4648

Published Jul 28, 2026

Use of an insecure cryptographic algorithm in the cashless payment system using NFC wristbands from CasfID Servicios Tecnológicos S.L.U. (version used at Resurrection Fest 2025),…

CVSS 6.8 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-50044

Published Jul 23, 2026

Pronetiqs IntraVUE versions 3.2.1a14 and prior have an inadequate encryption strength vulnerability which could allow an attacker to steal admin credentials via weak hash or a pas…

CVSS 7.6 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-49852

Published Jul 17, 2026

joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. Prior to 1.6.8, joserfc.jwt.decode accepts attacker-for…

CVSS 8.7 · High
evidence mentions
3
Buzz score
18.9

CVE-2024-23564

Published Jul 17, 2026

HCL Aftermarket EPC is affected by Business Logic Vulnerability using which a non valid user of the application can obtain passwords from the server and redirect them to their own…

CVSS 9.1 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-35146

Published Jul 16, 2026

HCL DFXServer is affected by an Unencrypted Communication vulnerability. The application permits users to establish connections over unencrypted channels via the HTTP protocol, wh…

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-45363

Published Jul 14, 2026

ruby-jwt is a Ruby implementation of the RFC 7519 OAuth JSON Web Token standard. Prior to 2.10.3 and 3.2.0, JWT.decode(token, '', true, algorithm: 'HS256') accepts an attacker-for…

CVSS 9.1 · Critical
evidence mentions
5
Buzz score
22.9

CVE-2025-63579

Published Jul 9, 2026

Unauthorized use of Kyocera printers, allows all information stored in the Kyocera address book to be exported. The security measure that encrypts incoming data ian be bypassed wi…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-14868

Published Jul 7, 2026

The encryption algorithm used to protect the configuration of user accounts, stored in the built-in user directory of PcVue projects, all versions prior to 17.0.0, is not strong e…

CVSS 8.4 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-7830

Published Jul 1, 2026

UltraVNC through 1.8.2.2 uses inadequate cryptography in the MS-Logon II authentication scheme (rfbUltraVNC_MsLogonIIAuth). In rfb/dh.cpp the Diffie-Hellman key exchange is perfor…

CVSS 7.4 · High
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-41860

Published Jun 4, 2026

CWE-326 in BOSH allows a local attacker to steal Basic-auth credentials or redirect UAA token requests via MITM. HttpRequestHelper#create_async_endpoint and #send_http_get_request…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-8878

Published Jun 3, 2026

Version 3.0.7 of the Securly Chrome Extension exposes multiple publicly accessible endpoints that allow unauthenticated access to sensitive data. The exposed information consists…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-44523

Published May 14, 2026

Note Mark is an open-source note-taking application. Prior to 0.19.4, no minimum length or entropy is enforced on the JWT_SECRET configuration value. The application accepts any b…

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-44351

Published May 13, 2026

fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to 6.2.4, a critical authentication-bypass vulnerability in fast-jwt's async key-resolver flow allows any unauthe…

CVSS 9.1 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-33361

Published May 11, 2026

In Meari IoT SDK image handling (libmrplayer.so) as observed in CloudEdge 5.5.0 (build 220), Arenti 1.8.1 (build 220), and related white-label apps (<= 1.8.x), baby monitor ".jpgx…

CVSS 7.5 · High
evidence mentions
2
Buzz score
17.5

CVE-2018-25272

Published Apr 22, 2026

ELBA5 5.8.0 contains a remote code execution vulnerability that allows attackers to obtain database credentials and execute arbitrary commands with SYSTEM level permissions. Attac…

CVSS 9.3 · Critical

CVE-2026-5363

Published Apr 16, 2026

Inadequate Encryption Strength vulnerability in TP-Link Archer C7 v5 and v5.8 (uhttpd modules) allows Password Recovery Exploitation. The web interface encrypts the admin password…

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-39349

Published Apr 7, 2026

OrangeHRM is a comprehensive human resource management (HRM) system. From 5.0 to 5.8, OrangeHRM Open Source encrypts certain sensitive fields with AES in ECB mode, which preserves…

CVSS 2.1 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-28377

Published Mar 26, 2026

A vulnerability in Grafana Tempo exposes the S3 SSE-C encryption key in plaintext through the /status/config endpoint, potentially allowing unauthorized users to obtain the key us…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-33512

Published Mar 23, 2026

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the API plugin exposes a `decryptString` action without any authentication. Anyone can submit c…

CVSS 7.5 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-33488

Published Mar 23, 2026

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `createKeys()` function in the LoginControl plugin's PGP 2FA system generates 512-bit RSA k…

CVSS 7.4 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2025-36379

Published Feb 17, 2026

IBM Security QRadar EDR 3.12 through 3.12.23 IBM Security ReaQta uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive inform…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-68703

Published Jan 13, 2026

Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, the salt is derived from sha256Sum(passphrase). Two encryption operations with…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 457 CVEsPage 1 of 19