Skip to main content

CWE archive

CWE-326 CVEs

Programmatic archive

461 CVEs tagged with CWE-32650 Critical, 191 High, 198 Medium, 22 Low, 0 Unrated.

CVE-2023-21444

Published Feb 9, 2023

Improper cryptographic implementation in Samsung Flow for PC 4.9.14.0 allows adjacent attackers to decrypt encrypted messages or inject commands.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-21443

Published Feb 9, 2023

Improper cryptographic implementation in Samsung Flow for Android prior to version 4.9.04 allows adjacent attackers to decrypt encrypted messages or inject commands.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-2582

Published Dec 27, 2022

The AWS S3 Crypto SDK sends an unencrypted hash of the plaintext alongside the ciphertext as a metadata field. This hash can be used to brute force the plaintext, if the hash is r…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-4036

Published Nov 29, 2022

The Appointment Hour Booking plugin for WordPress is vulnerable to CAPTCHA bypass in versions up to, and including, 1.3.72. This is due to the use of insufficiently strong hashing…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-45379

Published Nov 15, 2022

Jenkins Script Security Plugin 1189.vb_a_b_7c8fd5fde and earlier stores whole-script approvals as the SHA-1 hash of the script, making it vulnerable to collision attacks.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-4099

Published Nov 1, 2022

The application was signed using a key length less than or equal to 1024 bits, making it potentially vulnerable to forged digital signatures. An attacker could forge the same digi…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-41209

Published Oct 11, 2022

SAP Customer Data Cloud (Gigya mobile app for Android) - version 7.4, uses encryption method which lacks proper diffusion and does not hide the patterns well. This can lead to inf…

CVSS 5.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-35226

Published Oct 10, 2022

An entity in Network Configuration Manager product is misconfigured and exposing password field to Solarwinds Information Service (SWIS). Exposed credentials are encrypted and req…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-3433

Published Oct 10, 2022

The aeson library is not safe to use to consume untrusted JSON input. A remote user could abuse this flaw to produce a hash collision in the underlying unordered-containers librar…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-29835

Published Sep 19, 2022

WD Discovery software executable files were signed with an unsafe SHA-1 hashing algorithm. An attacker could use this weakness to create forged certificate signatures due to the u…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-35931

Published Sep 6, 2022

Nextcloud Password Policy is an app that enables a Nextcloud server admin to define certain rules for passwords. Prior to versions 22.2.10, 23.0.7, and 24.0.3 the random password…

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-30285

Published Aug 2, 2022

In Quest KACE Systems Management Appliance (SMA) through 12.0, a hash collision is possible during authentication. This may allow authentication with invalid credentials.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-26307

Published Jul 25, 2022

LibreOffice supports the storage of passwords for web connections in the user’s configuration database. The stored passwords are encrypted with a single master key provided by the…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 176-200 of 461 CVEsPage 8 of 19