Skip to main content

CWE archive

CWE-327 CVEs

Programmatic archive

685 CVEs tagged with CWE-32765 Critical, 256 High, 300 Medium, 64 Low, 0 Unrated.

CVE-2023-46133

Published Oct 25, 2023

CryptoES is a cryptography algorithms library compatible with ES6 and TypeScript. Prior to version 2.1.0, CryptoES PBKDF2 is 1,000 times weaker than originally specified in 1993,…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-33160

Published Oct 6, 2023

IBM Security Directory Suite 8.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 22856…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-3350

Published Oct 3, 2023

A Cryptographic Issue vulnerability has been found on IBERMATICA RPS, affecting version 2019. By firstly downloading the log file, an attacker could retrieve the SQL query sent to…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-34039

Published Aug 29, 2023

Aria Operations for Networks contains an Authentication Bypass vulnerability due to a lack of unique cryptographic key generation. A malicious actor with network access to Aria Op…

CVSS 9.8 · Critical
evidence mentions
8
Buzz score
35.0
Vendor/product tagsBeta · best-effort

CVE-2023-34758

Published Aug 28, 2023

Sliver from v1.5.x to v1.5.39 has an improper cryptographic implementation, which allows attackers to execute a man-in-the-middle attack via intercepted and crafted responses.

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2023-38730

Published Aug 27, 2023

IBM Storage Copy Data Management 2.2.0.0 through 2.2.19.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-40371

Published Aug 24, 2023

IBM AIX 7.2, 7.3, VIOS 3.1's OpenSSH implementation could allow a non-privileged local user to access files outside of those allowed due to improper access controls. IBM X-Force…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-23347

Published Aug 9, 2023

HCL DRYiCE iAutomate is affected by the use of a broken cryptographic algorithm. An attacker can potentially compromise the confidentiality and integrity of sensitive information.

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-23346

Published Aug 9, 2023

HCL DRYiCE MyCloud is affected by the use of a broken cryptographic algorithm. An attacker can potentially compromise the confidentiality and integrity of sensitive information.

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-37484

Published Aug 8, 2023

SAP PowerDesigner - version 16.7, queries all password hashes in the backend database and compares it with the user provided one during login attempt, which might allow an attacke…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-37464

Published Jul 14, 2023

OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE). The AES GCM decryption routine incorrectly uses the Tag length from the actual Authe…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2023-21399

Published Jul 13, 2023

there is a possible way to bypass cryptographic assurances due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileg…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-35890

Published Jul 7, 2023

IBM WebSphere Application Server 8.5 and 9.0 could provide weaker than expected security, caused by the improper encoding in a local configuration file. IBM X-Force ID: 258637.

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 276-300 of 685 CVEsPage 12 of 28