Skip to main content

CWE archive

CWE-327 CVEs

Programmatic archive

685 CVEs tagged with CWE-32765 Critical, 256 High, 300 Medium, 64 Low, 0 Unrated.

CVE-2026-56582

Published Jul 21, 2026

HCL MyCloud was affected by the SSL/TLS LUCKY13 Vulnerability. An attacker may exploit this vulnerability to decrypt sensitive information through a TLS/SSL padding oracle attack.

CVSS 3.1 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-63761

Published Jul 20, 2026

SurrealDB before 3.1.0 silently substitutes the ES384 algorithm when a JWT access method is configured with ALGORITHM ES512 (DEFINE ACCESS ... TYPE JWT ALGORITHM ES512), because t…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-56454

Published Jul 16, 2026

HCL DFXAnalytics is affected by a Deprecated Protocol vulnerability due to the use of TLS 1.0 and TLS 1.1. These legacy protocols contain numerous cryptographic design flaws that…

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-15605

Published Jul 13, 2026

A security vulnerability has been detected in wandb 0.25.2.dev1. Affected is the function ArtifactManifestEntry.download in the library wandb/sdk/lib/hashutil.py of the component…

CVSS 2.3 · Low
evidence mentions
7
Buzz score
27.3

CVE-2026-54780

Published Jul 8, 2026

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, the CoreWCF WS-Security 1.0 receive pipeline validates ds:S…

CVSS 3.7 · Low
evidence mentions
6
Buzz score
24.5

CVE-2026-14742

Published Jul 5, 2026

A vulnerability was determined in langchain-ai langgraph up to 1.2.4. The affected element is the function _freeze of the file libs/langgraph/langgraph/_internal/_cache.py of the…

CVSS 1.3 · Low
evidence mentions
7
Buzz score
27.3

CVE-2026-14738

Published Jul 5, 2026

A security flaw has been discovered in exo-explore exo up to 1.0.71. Affected is the function _image_cache_key of the file src/exo/worker/engines/mlx/vision.py of the component Vi…

CVSS 2.9 · Low
evidence mentions
7
Buzz score
27.3

CVE-2026-14630

Published Jul 4, 2026

A vulnerability has been found in ForceInjection AI-fundermentals 2.0/3.0. Affected by this vulnerability is the function get_conversation_history of the file 08_agentic_system/me…

CVSS 1.3 · Low
evidence mentions
7
Buzz score
27.3

CVE-2026-57997

Published Jun 29, 2026

Strapi users-permissions plugin fails to restrict JWT algorithms when plugin::users-permissions.jwt.algorithm is not explicitly configured, allowing acceptance of HS384 and HS512…

CVSS 6.3 · Medium
evidence mentions
4
Buzz score
22.6
Vendor/product tagsBeta · best-effort

CVE-2026-13510

Published Jun 28, 2026

A vulnerability was found in SimStudioAI sim up to 0.6.92. Affected by this vulnerability is an unknown functionality in the library apps/sim/lib/core/security/deployment.ts of th…

CVSS 2.9 · Low
evidence mentions
7
Buzz score
27.3

CVE-2026-13482

Published Jun 28, 2026

A vulnerability was detected in skypilot-org skypilot up to 0.12.0. Impacted is the function username.encode of the file sky/users/server.py of the component User ID Handler. The…

CVSS 2.9 · Low
evidence mentions
6
Buzz score
26.0

CVE-2026-47775

Published Jun 26, 2026

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3, and 1.38.1, the OAuth2 HTTP filter's encrypt()/decrypt() f…

CVSS 6.8 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-9221

Published Jun 26, 2026

The Setracker2 Android Companion App (com.tgelec.setracker) versions 3.1.5 and earlier uses MD5 to generate a request signature for authenticating communications between the mobil…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-6330

Published Jun 25, 2026

The ML-KEM ARM64 NEON ciphertext comparison only compares half of the input, breaking the Fujisaki-Okamoto transform's implicit rejection and weakening IND-CCA2 security on that c…

CVSS 6.3 · Medium
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2026-6412

Published Jun 25, 2026

Certificate policy and RFC 8446 compliance concerns regarding the continued acceptance of SHA-1/MD5 in certificate processing.

CVSS 2.3 · Low
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2026-50268

Published Jun 17, 2026

Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Configuration.Encryption 4.0.0 through 4.1…

CVSS 1.9 · Low
evidence mentions
2
Buzz score
16.0

CVE-2026-40641

Published Jun 17, 2026

Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Use of a Broken or Risky Cryptographic Algorithm vulnerability. An unauthenticated attacker with remote access c…

CVSS 4.8 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-50086

Published Jun 12, 2026

The Aqara IAM/SSO gateway (gw-builder.aqara.com) exposes bidirectional AES round-trups against the platform's signing key without authentication. This is an instance of "CWE-306:…

CVSS 10.0 · Critical
evidence mentions
2
Buzz score
22.0
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-40996

Published Jun 11, 2026

Wss4jSecurityInterceptor defaulted allowRSA15KeyTransportAlgorithm to true, overriding Apache WSS4J's safer default for validation RequestData. Inbound WS-Security decryption coul…

CVSS 4.8 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-10237

Published Jun 10, 2026

During an internal security assessment, a potential vulnerability was discovered in some ThinkPad embedded controller firmware that could allow a privileged local user to perform…

CVSS 8.4 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-11481

Published Jun 8, 2026

A vulnerability was determined in yoanbernabeu grepai up to 0.35.0. The affected element is the function PostgresStore.LookupByContentHash of the file indexer/chunker.go of the co…

CVSS 1.1 · Low
evidence mentions
7
Buzz score
27.3

CVE-2026-11479

Published Jun 8, 2026

A vulnerability has been found in yoanbernabeu grepai 0.35.0. This issue affects some unknown processing of the file indexer/chunker.go of the component Qdrant Backend. Such manip…

CVSS 1.3 · Low
evidence mentions
7
Buzz score
27.3

CVE-2026-46395

Published Jun 5, 2026

HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0, the `hmacBase64()` function in the HAXcms Node.js backend contains two critical crypt…

CVSS 9.3 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-11330

Published Jun 5, 2026

A weakness has been identified in thedotmack claude-mem up to 11.0.1. The affected element is the function computeObservationContentHash of the file src/services/sqlite/observatio…

CVSS 2.0 · Low
evidence mentions
8
Buzz score
28.5
Showing 1-25 of 685 CVEsPage 1 of 28