Skip to main content

CWE archive

CWE-327 CVEs

Programmatic archive

685 CVEs tagged with CWE-32765 Critical, 256 High, 300 Medium, 64 Low, 0 Unrated.

CVE-2015-9235

Published May 29, 2018

In jsonwebtoken node module before 4.2.2 it is possible for an attacker to bypass verification when a token digitally signed with an asymmetric key (RS/ES family) of algorithms bu…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-11209

Published May 16, 2018

An issue was discovered in Z-BlogPHP 2.0.0. zb_system/cmd.php?act=verify relies on MD5 for the password parameter, which might make it easier for attackers to bypass intended acce…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2017-12129

Published May 14, 2018

An exploitable Weak Cryptography for Passwords vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. An attacker could intercept weakly encrypt…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2018-6619

Published May 11, 2018

Easy Hosting Control Panel (EHCP) v0.37.12.b makes it easier for attackers to crack database passwords by leveraging use of a weak hashing algorithm without a salt.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-10831

Published May 9, 2018

Z-NOMP before 2018-04-05 has an incorrect Equihash solution verifier that allows attackers to spoof mining shares, as demonstrated by providing a solution with {x1=1,x2=1,x3=1,...…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-0737

Published Apr 16, 2018

The OpenSSL RSA Key generation algorithm has been shown to be vulnerable to a cache timing side channel attack. An attacker with sufficient access to mount cache timing attacks du…

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2018-10084

Published Apr 13, 2018

CMS Made Simple (CMSMS) through 2.2.6 contains a privilege escalation vulnerability from ordinary user to admin user by arranging for the eff_uid value within $_COOKIE[$this->_log…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-5458

Published Mar 26, 2018

Philips IntelliSpace Portal all versions of 8.0.x, and 7.0.x have a vulnerability using SSL legacy encryption that could allow an attacker to gain unauthorized access to resources…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-7211

Published Feb 18, 2018

An issue was discovered in iDashboards 9.6b. The SSO implementation is affected by a weak obfuscation library, allowing man-in-the-middle attackers to discover credentials.

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2018-6829

Published Feb 7, 2018

cipher/elgamal.c in Libgcrypt through 1.8.2, when used to encrypt messages directly, improperly encodes plaintexts, which allows attackers to obtain sensitive information by readi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-1598

Published Dec 20, 2017

IBM Security Guardium 10.0 Database Activity Monitor uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-8191

Published Nov 22, 2017

FusionSphere OpenStack V100R006C00SPC102(NFV)has a week cryptographic algorithm vulnerability. Attackers may exploit the vulnerability to crack the cipher text and cause informati…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4449

Published Oct 30, 2017

Apache Hadoop before 0.23.4, 1.x before 1.0.4, and 2.x before 2.0.2 generate token passwords using a 20-bit secret when Kerberos security features are enabled, which makes it easi…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 626-650 of 685 CVEsPage 26 of 28