Skip to main content

CWE archive

CWE-327 CVEs

Programmatic archive

685 CVEs tagged with CWE-32765 Critical, 256 High, 300 Medium, 64 Low, 0 Unrated.

CVE-2020-12702

Published Feb 24, 2021

Weak encryption in the Quick Pairing mode in the eWeLink mobile application (Android application V4.9.2 and earlier, iOS application V4.9.1 and earlier) allows physically proximat…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-23839

Published Feb 16, 2021

OpenSSL 1.0.2 supports SSLv2. If a client attempts to negotiate SSLv2 with a server that is configured to support both SSLv2 and more recent SSL and TLS versions then a check is m…

CVSS 3.7 · Low
evidence mentions
2
Buzz score
17.5

CVE-2020-25493

Published Feb 11, 2021

Oclean Mobile Application 2.1.2 communicates with an external website using HTTP so it is possible to eavesdrop the network traffic. The content of HTTP payload is encrypted using…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-14246

Published Feb 4, 2021

HCL OneTest Performance V9.5, V10.0, V10.1 uses basic authentication which is relatively weak. An attacker could potentially decode the encoded credentials.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-25763

Published Feb 3, 2021

In JetBrains Ktor before 1.4.2, weak cipher suites were enabled by default.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-28498

Published Feb 2, 2021

The package elliptic before 6.5.4 are vulnerable to Cryptographic Issues via the secp256k1 implementation in elliptic/ec/key.js. There is no check to confirm that the public key p…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-29536

Published Jan 29, 2021

Archer before 6.8 P2 (6.8.0.2) is affected by a path exposure vulnerability. A remote authenticated malicious attacker with access to service files may obtain sensitive informatio…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-23162

Published Jan 26, 2021

Sensitive information disclosure and weak encryption in Pyrescom Termod4 time management devices before 10.04k allows remote attackers to read a session-file and obtain plain-text…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2013-1053

Published Jan 13, 2021

In crypt.c of remote-login-service, the cryptographic algorithm used to cache usernames and passwords is insecure. An attacker could use this vulnerability to recover usernames an…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-4898

Published Jan 7, 2021

IBM Emptoris Strategic Supply Management 10.1.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Forc…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-25006

Published Dec 31, 2020

An issue was discovered in the streebog crate before 0.8.0 for Rust. The Streebog hash function can produce the wrong answer.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-14254

Published Dec 16, 2020

TLS-RSA cipher suites are not disabled in HCL BigFix Inventory up to v10.0.2. If TLS 2.0 and secure ciphers are not enabled then an attacker can passively record traffic and later…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-7339

Published Dec 10, 2020

Use of a Broken or Risky Cryptographic Algorithm vulnerability in McAfee Database Security Server and Sensor prior to 4.8.0 in the form of a SHA1 signed certificate that would all…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 451-475 of 685 CVEsPage 19 of 28