Skip to main content

CWE archive

CWE-327 CVEs

Programmatic archive

685 CVEs tagged with CWE-32765 Critical, 256 High, 300 Medium, 64 Low, 0 Unrated.

CVE-2022-23539

Published Dec 23, 2022

Versions `<=8.5.1` of `jsonwebtoken` library could be misconfigured so that legacy, insecure key types are used for signature verification. For example, DSA keys could be used wit…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-4610

Published Dec 19, 2022

A vulnerability, which was classified as problematic, has been found in Click Studios Passwordstate and Passwordstate Browser Extension Chrome. Affected by this issue is some unkn…

CVSS 1.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-46834

Published Dec 13, 2022

Use of a Broken or Risky Cryptographic Algorithm in SICK RFU65x firmware version < v2.21 allows a low-privileged remote attacker to decrypt the encrypted data if the user requeste…

CVSS 6.5 · Medium

CVE-2022-34320

Published Nov 14, 2022

IBM CICS TX 11.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 229464.

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-34319

Published Nov 14, 2022

IBM CICS TX 11.7 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 229463.

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-45195

Published Nov 12, 2022

SimpleXMQ before 3.4.0, as used in SimpleX Chat before 4.2, does not apply a key derivation function to intended data, which can interfere with forward secrecy and can have other…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-27784

Published Oct 31, 2022

The provided HCL Launch Container images contain non-unique HTTPS certificates and a database encryption key. The fix provides directions and tools to replace the non-unique keys…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-39237

Published Oct 6, 2022

syslabs/sif is the Singularity Image Format (SIF) reference implementation. In versions prior to 2.8.1the `github.com/sylabs/sif/v2/pkg/integrity` package did not verify that the…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-2781

Published Oct 6, 2022

In affected versions of Octopus Server it was identified that the same encryption process was used for both encrypting session cookies and variables.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-37177

Published Aug 29, 2022

HireVue Hiring Platform V1.0 suffers from Use of a Broken or Risky Cryptographic Algorithm. NOTE: this is disputed by the vendor for multiple reasons, e.g., it is inconsistent wit…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-3979

Published Aug 25, 2022

A key length flaw was found in Red Hat Ceph Storage. An attacker can exploit the fact that the key length is incorrectly passed in an encryption algorithm to create a non random k…

CVSS 6.5 · Medium

CVE-2022-38493

Published Aug 20, 2022

Rhonabwy 0.9.99 through 1.1.x before 1.1.7 doesn't check the RSA private key length before RSA-OAEP decryption. This allows attackers to cause a Denial of Service via a crafted JW…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-30320

Published Jul 28, 2022

Saia Burgess Controls (SBC) PCD through 2022-05-06 uses a Broken or Risky Cryptographic Algorithm. According to FSCT-2022-0063, there is a Saia Burgess Controls (SBC) PCD S-Bus we…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-30273

Published Jul 26, 2022

The Motorola MDLC protocol through 2022-05-02 mishandles message integrity. It supports three security modes: Plain, Legacy Encryption, and New Encryption. In Legacy Encryption mo…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-29965

Published Jul 26, 2022

The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. Access to privileged operations on the maintenance port TELNET in…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-31157

Published Jul 15, 2022

LTI 1.3 Tool Library is a library used for building IMS-certified LTI 1.3 tool providers in PHP. Prior to version 5.0, the function used to generate random nonces was not sufficie…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 326-350 of 685 CVEsPage 14 of 28