Skip to main content

CWE archive

CWE-327 CVEs

Programmatic archive

685 CVEs tagged with CWE-32765 Critical, 256 High, 300 Medium, 64 Low, 0 Unrated.

CVE-2021-27756

Published Mar 4, 2022

"TLS-RSA cipher suites are not disabled in BigFix Compliance up to v2.0.5. If TLS 2.0 and secure ciphers are not enabled then an attacker can passively record traffic and later de…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-0377

Published Feb 28, 2022

Users of the LearnPress WordPress plugin before 4.1.5 can upload an image as a profile avatar after the registration. After this process the user crops and saves the image. Then…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-20003

Published Feb 4, 2022

Z-Wave devices from Sierra Designs (circa 2013) and Silicon Labs (using S0 security) may use a known, shared network key of all zeros, allowing an attacker within radio range to s…

CVSS 8.3 · High

CVE-2021-41835

Published Jan 21, 2022

Fresenius Kabi Agilia Link + version 3.0 does not enforce transport layer encryption. Therefore, transmitted data may be sent in cleartext. Transport layer encryption is offered o…

CVSS 7.3 · High

CVE-2021-33846

Published Jan 21, 2022

Fresenius Kabi Vigilant Software Suite (Mastermed Dashboard) version 2.0.1.3 issues authentication tokens to authenticated users that are signed with a symmetric encryption key. A…

CVSS 5.9 · Medium

CVE-2021-31562

Published Jan 21, 2022

The SSL/TLS configuration of Fresenius Kabi Agilia Link + version 3.0 has serious deficiencies that may allow an attacker to compromise SSL/TLS sessions in different ways. An atta…

CVSS 6.5 · Medium

CVE-2021-40006

Published Jan 10, 2022

Vulnerability of design defects in the security algorithm component. Successful exploitation of this vulnerability may affect confidentiality.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-38921

Published Jan 10, 2022

IBM Security Verify 10.0.0, 10.0.1.0, and 10.0.2.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-F…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-38542

Published Jan 4, 2022

Apache James prior to release 3.6.1 is vulnerable to a buffering attack relying on the use of the STARTTLS command. This can result in Man-in -the-middle command injection attacks…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-42583

Published Dec 28, 2021

A Broken or Risky Cryptographic Algorithm exists in Max Mazurov Maddy before 0.5.2, which is an unnecessary risk that may result in the exposure of sensitive information.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-45696

Published Dec 27, 2021

An issue was discovered in the sha2 crate 0.9.7 before 0.9.8 for Rust. Hashes of long messages may be incorrect when the AVX2-accelerated backend is used.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-43989

Published Dec 23, 2021

mySCADA myPRO Versions 8.20.0 and prior stores passwords using MD5, which may allow an attacker to crack the previously retrieved password hashes.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-2488

Published Dec 23, 2021

A cryptographic weakness existed in the authentication protocol of Remote Desktop. This issue was addressed by implementing the Secure Remote Password authentication protocol. Thi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-45451

Published Dec 21, 2021

In Mbed TLS before 3.1.0, psa_aead_generate_nonce allows policy bypass or oracle-based decryption when the output buffer is at memory locations accessible to an untrusted applicat…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 376-400 of 685 CVEsPage 16 of 28