CWE-326

Inadequate Encryption Strength

Parent: CWE-693 - Protection Mechanism Failure

The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.

448 vulnerabilities with CWE-326
CVE-2026-41860 HIGH
Cloud Foundry Foundation Bosh < 282.1.9 - Inadequate Encryption Strength
CVSS 8.8
CVE-2026-8878 HIGH
Securly Chrome Extension < 3.0.7 - Unauthenticated Sensitive Data Exposure via Public Endpoints
CVSS 7.5
CVE-2026-45787 CRITICAL
electerm's encrypt method not safe enough
CVSS 9.1
CVE-2026-44523 CRITICAL
Note Mark: JWT Secret Weakness allows Full Account Takeover via token forgery
CVSS 10.0
CVE-2026-44351 CRITICAL
fast-jwt: Empty HMAC secret accepted via async key resolver - JWT auth bypass
CVSS 9.1
CVE-2026-33361 HIGH
Meari weak XOR obfuscation
CVSS 7.5
CVE-2026-5363 HIGH
Use of weak cryptographic key in TP-Link Archer C7
CVSS 8.8
CVE-2026-5889 MEDIUM
Google Chrome <147.0.7727.55 - Info Disclosure
CVSS 4.3
CVE-2026-39349 LOW
OrangeHRM Uses AES-ECB for Sensitive Data Encryption Enables Pattern Disclosure
CVSS 2.7
CVE-2026-28377 HIGH
S3 SSE-C Encryption Key Exposed in Plaintext via Config Endpoint (CVE-2025-41118 Pattern)
CVSS 7.5
CVE-2026-33512 HIGH
WWBN AVideo <=26.0 - Info Disclosure
CVSS 7.5
CVE-2026-33488 HIGH
AVideo <=26.0 LoginControl PGP - Two-Factor Authentication Bypass
CVSS 7.4
CVE-2026-0510 LOW
NetWeaver Application Server for Java - Info Disclosure
CVSS 3.0
CVE-2025-1241 MEDIUM
Encryption vulnerable to brute-force decryption in GoAnywhere MFT
CVSS 5.8
CVE-2025-36379 MEDIUM
IBM Security QRadar EDR 3.12-3.12.23 - Info Disclosure
CVSS 5.9
CVE-2025-68703 HIGH
Jervis < 2.2 - Inadequate Encryption Strength via Predictable Salt Derivation
CVSS 7.5
CVE-2025-65295 HIGH
Aqara Hub <4.1.9_0027-4.3.6_0025 - RCE
CVSS 8.1
CVE-2025-41743 MEDIUM
Sprecher Automation - Info Disclosure
CVSS 4.0
CVE-2025-11935 HIGH
wolfssl 5.8.2-5.8.3 - Inadequate Encryption Strength via TLS 1.3 PSK Without PFS
CVSS 7.5
CVE-2025-12439 MEDIUM
Google Chrome < 142.0.7444.59 - Inadequate Encryption Strength in App-Bound Encryption
CVSS 5.5
CVE-2025-12478 CRITICAL
BLU-IC2 and BLU-IC4 Firmware < 1.20 - Inadequate Encryption Strength
CVSS 9.8
CVE-2025-55039 MEDIUM
Apache Spark <4.0.0-3.5.2-3.4.4 - Info Disclosure
CVSS 6.5
CVE-2025-55248 MEDIUM
.NET Framework - Inadequate Encryption Strength
CVSS 4.8
CVE-2025-39889 HIGH
Linux Kernel - Inadequate Encryption Key Size Validation in Bluetooth L2CAP
CVSS 8.1
CVE-2025-46409 HIGH
SS1 <16.0.0.10 - Info Disclosure
CVSS 7.5
Details
Vulnerabilities 448