The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.
457 vulnerabilities with CWE-326
CVE-2026-4648
MEDIUM
Insufficient Encryption Level in CasfID Servicios Tecnológicos NFC Wristbands
CVE-2026-50044
MEDIUM
Inadequate Encryption Strength in Panduit IntraVUE by Pronetiqs
CVSS 6.8
CVE-2026-49852
HIGH
joserfc: HS256/HS384/HS512 verify accepts empty/nil HMAC key (cross-language sibling of CVE-2026-45363)
CVE-2026-35146
MEDIUM
HCL DFXServer is affected by an Unencrypted Communication vulnerability.
CVSS 6.3
CVE-2026-45363
CRITICAL
`jwt` (Ruby gem) - empty-key HMAC bypass
CVSS 9.1
CVE-2026-14868
MEDIUM
arcinfo PcVue - Weak Encryption Mechanism for User Directory
CVSS 5.5
CVE-2026-7830
HIGH
UltraVNC MS-Logon II uses 64-bit Diffie-Hellman and seeded libc rand() enabling credential interception
CVSS 7.4
CVE-2026-41860
HIGH
Cloud Foundry Foundation Bosh < 282.1.9 - Inadequate Encryption Strength
CVSS 8.8
CVE-2026-8878
HIGH
Securly Chrome Extension < 3.0.7 - Unauthenticated Sensitive Data Exposure via Public Endpoints
CVSS 7.5
CVE-2026-45787
CRITICAL
electerm's encrypt method not safe enough
CVSS 9.1
CVE-2026-44523
CRITICAL
Note Mark: JWT Secret Weakness allows Full Account Takeover via token forgery
CVSS 10.0
CVE-2026-44351
CRITICAL
fast-jwt: Empty HMAC secret accepted via async key resolver - JWT auth bypass
CVSS 9.1
CVE-2026-33361
HIGH
Meari weak XOR obfuscation
CVSS 7.5
CVE-2026-5363
HIGH
Use of weak cryptographic key in TP-Link Archer C7
CVSS 8.8
CVE-2026-5889
MEDIUM
Google Chrome <147.0.7727.55 - Info Disclosure
CVSS 4.3
CVE-2026-39349
LOW
OrangeHRM Uses AES-ECB for Sensitive Data Encryption Enables Pattern Disclosure
CVSS 2.7
CVE-2026-28377
HIGH
S3 SSE-C Encryption Key Exposed in Plaintext via Config Endpoint (CVE-2025-41118 Pattern)
CVSS 7.5
CVE-2026-33512
HIGH
WWBN AVideo <=26.0 - Info Disclosure
CVSS 7.5
CVE-2026-33488
HIGH
AVideo <=26.0 LoginControl PGP - Two-Factor Authentication Bypass
CVSS 7.4
CVE-2026-0510
LOW
NetWeaver Application Server for Java - Info Disclosure
CVSS 3.0
CVE-2025-63579
HIGH
Kyocera TASKalfa Printers - Unauthenticated Sensitive Information Exposure and Encryption Bypass via Address Book Export
CVSS 7.5
CVE-2025-1241
MEDIUM
Encryption vulnerable to brute-force decryption in GoAnywhere MFT
CVSS 5.8
CVE-2025-36379
MEDIUM
IBM Security QRadar EDR 3.12-3.12.23 - Info Disclosure
CVSS 5.9
CVE-2025-68703
HIGH
Jervis < 2.2 - Inadequate Encryption Strength via Predictable Salt Derivation
CVSS 7.5
CVE-2025-65295
HIGH
Aqara Hub <4.1.9_0027-4.3.6_0025 - RCE
CVSS 8.1
Details
Vulnerabilities
457