Skip to main content

CWE archive

CWE-327 CVEs

Programmatic archive

685 CVEs tagged with CWE-32765 Critical, 256 High, 300 Medium, 64 Low, 0 Unrated.

CVE-2022-2097

Published Jul 5, 2022

AES OCB mode for 32-bit x86 platforms using the AES-NI assembly optimised implementation will not encrypt the entirety of the data under some circumstances. This could reveal sixt…

CVSS 5.3 · Medium

CVE-2022-31230

Published Jun 28, 2022

Dell PowerScale OneFS, versions 8.2.x-9.2.x, contain broken or risky cryptographic algorithm. A remote unprivileged malicious attacker could potentially exploit this vulnerability…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2022-28166

Published Jun 27, 2022

In Brocade SANnav version before SANN2.2.0.2 and Brocade SANNav before 2.1.1.8, the implementation of TLS/SSL Server Supports the Use of Static Key Ciphers (ssl-static-key-ciphers…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-29249

Published May 24, 2022

JavaEZ is a library that adds new functions to make Java easier. A weakness in JavaEZ 1.6 allows force decryption of locked text by unauthorized actors. The issue is NOT critical…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-29217

Published May 24, 2022

PyJWT is a Python implementation of RFC 7519. PyJWT supports multiple different JWT signing algorithms. With JWT, an attacker submitting the JWT token can choose the used signing…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2022-20117

Published May 10, 2022

In (TBD) of (TBD), there is a possible way to decrypt local data encrypted by the GSC due to improperly used crypto. This could lead to local information disclosure with no additi…

CVSS 5.5 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2021-20479

Published May 9, 2022

IBM Cloud Pak System 2.3.0 through 2.3.3.3 Interim Fix 1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. I…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-28164

Published May 6, 2022

Brocade SANnav before SANnav 2.2.0 application uses the Blowfish symmetric encryption algorithm for the storage of passwords. This could allow an authenticated attacker to decrypt…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-29161

Published May 6, 2022

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The XWiki Crypto API will generate X509 certificates signed by default usi…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-39082

Published Apr 29, 2022

IBM UrbanCode Deploy (UCD) 7.1.1.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-20805

Published Apr 21, 2022

A vulnerability in the automatic decryption process in Cisco Umbrella Secure Web Gateway (SWG) could allow an authenticated, adjacent attacker to bypass the SSL decryption and con…

CVSS 4.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-22559

Published Apr 12, 2022

Dell PowerScale OneFS, version 9.3.0, contains a use of a broken or risky cryptographic algorithm. An unprivileged network attacker could exploit this vulnerability, leading to th…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-1252

Published Apr 11, 2022

Use of a Broken or Risky Cryptographic Algorithm in GitHub repository gnuboard/gnuboard5 prior to and including 5.5.5. A vulnerability in gnuboard v5.5.5 and below uses weak encry…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2022-26854

Published Apr 8, 2022

Dell PowerScale OneFS, versions 8.2.x-9.2.x, contain risky cryptographic algorithms. A remote unprivileged malicious attacker could potentially exploit this vulnerability, leading…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2021-32593

Published Apr 6, 2022

A use of a broken or risky cryptographic algorithm vulnerability [CWE-327] in the Dynamic Tunnel Protocol of FortiWAN before 4.5.9 may allow an unauthenticated remote attacker to…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-22327

Published Apr 1, 2022

IBM UrbanCode Deploy (UCD) 7.0.5, 7.1.0, 7.1.1, and 7.1.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 351-375 of 685 CVEsPage 15 of 28