Skip to main content

CWE archive

CWE-757 CVEs

Programmatic archive

31 CVEs tagged with CWE-7575 Critical, 9 High, 13 Medium, 4 Low, 0 Unrated.

CVE-2026-55953

Published Jul 27, 2026

The Erlang/OTP ssl TLS 1.2 (and earlier) and DTLS client does not verify that the cipher suite selected by the server in ServerHello was among the suites offered by the client in…

CVSS 9.1 · Critical
evidence mentions
7
Buzz score
33.8

CVE-2026-4942

Published Jul 17, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to send a specifically crafted message and downgrade the Transport Layer Security (TLS) protocol to a version disabled i…

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-53712

Published Jul 17, 2026

SCRAM (Salted Challenge Response Authentication Mechanism) is part of the family of Simple Authentication and Security Layer (SASL, RFC 4422) authentication mechanisms. Prior to 3…

CVSS 8.2 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-48747

Published Jul 14, 2026

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 7.4.13 and 8.0.13, MailomatRequestParser::validateSignature() parsed X-M…

CVSS 6.3 · Medium
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-54780

Published Jul 8, 2026

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, the CoreWCF WS-Security 1.0 receive pipeline validates ds:S…

CVSS 3.7 · Low
evidence mentions
6
Buzz score
24.5

CVE-2026-54291

Published Jul 6, 2026

pgjdbc is an open source postgresql JDBC Driver. In releases 42.7.4 through 42.7.11, channelBinding=require connections can be silently downgraded from SCRAM-SHA-256-PLUS with cha…

CVSS 8.2 · High
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-6092

Published Jun 25, 2026

When HAVE_ENCRYPT_THEN_MAC is configured, the implementation could fall back to MAC-then-Encrypt rather than enforcing Encrypt-then-MAC.

CVSS 2.1 · Low
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2026-1677

Published May 11, 2026

Zephyr sockets created with `IPPROTO_TLS_1_3` can still negotiate a TLS 1.2 connection when both TLS versions are enabled in Kconfig, because the socket-level protocol selection i…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-6550

Published Apr 20, 2026

Cryptographic algorithm downgrade in the caching layer of Amazon AWS Encryption SDK for Python before version 3.3.1 and before version 4.0.5 might allow an authenticated local th…

CVSS 5.7 · Medium
evidence mentions
4
Buzz score
26.1

CVE-2026-32650

Published Apr 17, 2026

Anviz CrossChex Standard is vulnerable when an attacker manipulates the TDS7 PreLogin to disable encryption, causing database credentials to be sent in plaintext and enabling un…

CVSS 7.5 · High
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2025-10693

Published Oct 31, 2025

When SmartStart Inclusion fails during the onboarding of a Z-Wave PIR sensor, the sensor will join the network as a non-secure device. This vulnerability exists in Silicon Labs' Z…

CVSS 7.6 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-59270

Published Sep 16, 2025

psPAS PowerShell module does not explicitly enforce TLS 1.2 within the 'Get-PASSAMLResponse' function during the SAML authentication process. An unauthenticated attacker in a 'Man…

CVSS 2.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-36582

Published Jul 1, 2025

Dell NetWorker, versions 19.12.0.1 and prior, contains a Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade') vulnerability. An unauthenticated attacker w…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-8773

Published Mar 24, 2025

SIMPLE.ERP client is vulnerable to MS SQL protocol downgrade request from a server side, what could lead to an unencrypted communication vulnerable to data interception and modifi…

CVSS 8.3 · High

CVE-2024-4995

Published Dec 18, 2024

Wapro ERP Desktop is vulnerable to MS SQL protocol downgrade request from a server side, what could lead to an unencrypted communication vulnerable to data interception and modifi…

CVSS 9.1 · Critical

CVE-2024-38883

Published Aug 2, 2024

An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform a Drop Encryption Level attac…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-20069

Published Jun 3, 2024

In modem, there is a possible selection of less-secure algorithm during the VoWiFi IKE due to a missing DH downgrade check. This could lead to remote information disclosure with n…

CVSS 6.5 · Medium

CVE-2024-23656

Published Jan 25, 2024

Dex is an identity service that uses OpenID Connect to drive authentication for other apps. Dex 2.37.0 serves HTTPS with insecure TLS 1.0 and TLS 1.1. `cmd/dex/serve.go` line 425…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-33160

Published Oct 6, 2023

IBM Security Directory Suite 8.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 22856…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-2974

Published Jul 4, 2023

A vulnerability was found in quarkus-core. This vulnerability occurs because the TLS protocol configured with quarkus.http.ssl.protocols is not enforced, and the client can force…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-25029

Published Feb 4, 2022

The Z-Wave specification requires that S2 security can be downgraded to S0 or other less secure protocols, allowing an attacker within radio range during pairing to downgrade and…

CVSS 8.1 · High

CVE-2021-36326

Published Nov 30, 2021

Dell EMC Streaming Data Platform, versions prior to 1.3 contain an SSL Strip Vulnerability in the User Interface (UI). A remote unauthenticated attacker could potentially exploit…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 31 CVEsPage 1 of 2