Skip to main content

CWE archive

CWE-326 CVEs

Programmatic archive

456 CVEs tagged with CWE-32649 Critical, 189 High, 196 Medium, 22 Low, 0 Unrated.

CVE-2021-27450

Published Mar 25, 2021

SSH server configuration file does not implement some best practices. This could lead to a weakening of the SSH protocol strength, which could lead to additional misconfiguration…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-21387

Published Mar 19, 2021

Wrongthink peer-to-peer, end-to-end encrypted messenger with PeerJS and Axolotl ratchet. In wrongthink from version 2.0.0 and before 2.3.0 there was a set of vulnerabilities causi…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2021-21474

Published Feb 9, 2021

SAP HANA Database, versions - 1.0, 2.0, accepts SAML tokens with MD5 digest, an attacker who manages to obtain an MD5-digest signed SAML Assertion issued for an SAP HANA instance…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-10554

Published Feb 5, 2021

An issue was discovered in Psyprax beforee 3.2.2. Passwords used to encrypt the data are stored in the database in an obfuscated format, which can be easily reverted. For example,…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-10375

Published Feb 5, 2021

An issue was discovered in New Media Smarty before 9.10. Passwords are stored in the database in an obfuscated format that can be easily reversed. The file data.mdb contains these…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-25761

Published Feb 3, 2021

In JetBrains Ktor before 1.5.0, a birthday attack on SessionStorage key was possible.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-4160

Published Jan 13, 2021

IBM Security Guardium Data Encryption (GDE) 3.0.0.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-3131

Published Jan 13, 2021

The Web server in 1C:Enterprise 8 before 8.3.17.1851 sends base64 encoded credentials in the creds URL parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-20001

Published Jan 1, 2021

The AES encryption project 7.x and 8.x for Drupal does not sufficiently prevent attackers from decrypting data, aka SA-CONTRIB-2017-027. NOTE: This project is not covered by Drupa…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-26263

Published Dec 21, 2020

tlslite-ng is an open source python library that implements SSL and TLS cryptographic protocols. In tlslite-ng before versions 0.7.6 and 0.8.0-alpha39, the code that performs decr…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-9128

Published Nov 12, 2020

FusionCompute versions 8.0.0 have an insecure encryption algorithm vulnerability. Attackers with high permissions can exploit this vulnerability to cause information leak.

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-14517

Published Sep 16, 2020

Protocol encryption can be easily broken for CodeMeter (All versions prior to 6.90 are affected, including Version 6.90 or newer only if CodeMeter Runtime is running as server) an…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-10125

Published Aug 21, 2020

NCR SelfServ ATMs running APTRA XFS 04.02.01 and 05.01.00 implement 512-bit RSA certificates to validate bunch note acceptor (BNA) software updates, which can be broken by an atta…

CVSS 7.6 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2020-5763

Published Jul 29, 2020

Grandstream HT800 series firmware version 1.0.17.5 and below contain a backdoor in the SSH service. An authenticated remote attacker can obtain a root shell by correctly answering…

CVSS 8.8 · High
Showing 251-275 of 456 CVEsPage 11 of 19