Skip to main content

CWE archive

CWE-327 CVEs

Programmatic archive

685 CVEs tagged with CWE-32765 Critical, 256 High, 300 Medium, 64 Low, 0 Unrated.

CVE-2023-50937

Published Feb 2, 2024

IBM PowerSC 1.3, 2.0, and 2.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 275117.

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-50939

Published Feb 2, 2024

IBM PowerSC 1.3, 2.0, and 2.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 275129.

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-22192

Published Jan 16, 2024

Ursa is a cryptographic library for use with blockchains. The revocation scheme that is part of the Ursa CL-Signatures implementations has a flaw that could impact the privacy gua…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-21670

Published Jan 16, 2024

Ursa is a cryptographic library for use with blockchains. The revocation schema that is part of the Ursa CL-Signatures implementations has a flaw that could impact the privacy gua…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-50351

Published Jan 3, 2024

HCL DRYiCE MyXalytics is impacted by the use of an insecure key rotation mechanism which can allow an attacker to compromise the confidentiality or integrity of data.

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-50350

Published Jan 3, 2024

HCL DRYiCE MyXalytics is impacted by the use of a broken cryptographic algorithm for encryption, potentially giving an attacker ability to decrypt sensitive information.

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2021-46900

Published Dec 31, 2023

Sympa before 6.2.62 relies on a cookie parameter for certain security objectives, but does not ensure that this parameter exists and has an unpredictable value. Specifically, the…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-50481

Published Dec 21, 2023

An issue was discovered in blinksocks version 3.3.8, allows remote attackers to obtain sensitive information via weak encryption algorithms in the component /presets/ssr-auth-chai…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-50475

Published Dec 21, 2023

An issue was discovered in bcoin-org bcoin version 2.2.0, allows remote attackers to obtain sensitive information via weak hashing algorithms in the component \vendor\faye-websock…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-28053

Published Dec 18, 2023

Dell NetWorker Virtual Edition versions 19.8 and below contain the use of deprecated cryptographic algorithms in the SSH component. A remote unauthenticated attacker could potenti…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-43843

Published Dec 14, 2023

IBM Spectrum Scale 5.1.5.0 through 5.1.5.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-27795

Published Dec 6, 2023

Brocade Fabric OS (FOS) hardware platforms running any version of Brocade Fabric OS software, which supports the license string format; contain cryptographic issues that could…

CVSS 6.4 · Medium

CVE-2022-24403

Published Dec 5, 2023

The TETRA TA61 identity encryption function internally uses a 64-bit value derived exclusively from the SCK (Class 2 networks) or CCK (Class 3 networks). The structure of TA61 all…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-38361

Published Nov 18, 2023

IBM CICS TX Advanced 10.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 260770.

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-47640

Published Nov 14, 2023

DataHub is an open-source metadata platform. The HMAC signature for DataHub Frontend sessions was being signed using a SHA-1 HMAC with the frontend secret key. SHA1 with a 10 byte…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-46233

Published Oct 25, 2023

crypto-js is a JavaScript library of crypto standards. Prior to version 4.2.0, crypto-js PBKDF2 is 1,000 times weaker than originally specified in 1993, and at least 1,300,000 tim…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort
Showing 251-275 of 685 CVEsPage 11 of 28