CWE-326

Inadequate Encryption Strength

Parent: CWE-693 - Protection Mechanism Failure

The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.

442 vulnerabilities with CWE-326
CVE-2026-5363 MEDIUM
Use of weak cryptographic key in TP-Link Archer C7
CVE-2026-5889 MEDIUM
Google Chrome <147.0.7727.55 - Info Disclosure
CVSS 4.3
CVE-2026-39349 LOW
OrangeHRM Uses AES-ECB for Sensitive Data Encryption Enables Pattern Disclosure
CVSS 2.7
CVE-2026-28377 HIGH
S3 SSE-C Encryption Key Exposed in Plaintext via Config Endpoint (CVE-2025-41118 Pattern)
CVSS 7.5
CVE-2026-33512 HIGH
WWBN AVideo <=26.0 - Info Disclosure
CVSS 7.5
CVE-2026-33488 HIGH
AVideo has a PGP 2FA Bypass via Cryptographically Broken 512-bit RSA Key Generation in LoginControl Plugin
CVSS 7.4
CVE-2026-0510 LOW
NetWeaver Application Server for Java - Info Disclosure
CVSS 3.0
CVE-2025-1241 MEDIUM
Encryption vulnerable to brute-force decryption in GoAnywhere MFT
CVSS 5.8
CVE-2025-36379 MEDIUM
IBM Security QRadar EDR 3.12-3.12.23 - Info Disclosure
CVSS 5.9
CVE-2025-68703 HIGH
Jervis <2.2 - Info Disclosure
CVSS 7.5
CVE-2025-65295 HIGH
Aqara Hub <4.1.9_0027-4.3.6_0025 - RCE
CVSS 8.1
CVE-2025-41743 MEDIUM
Sprecher Automation - Info Disclosure
CVSS 4.0
CVE-2025-11935 HIGH
Wolfssl < 5.8.4 - Weak Encryption
CVSS 7.5
CVE-2025-12439 MEDIUM
Google Chrome < 142.0.7444.59 - Weak Encryption
CVSS 5.5
CVE-2025-12478 CRITICAL
Azure-access Blu-ic2 Firmware < 1.20 - Weak Encryption
CVSS 9.8
CVE-2025-55039 MEDIUM
Apache Spark <4.0.0-3.5.2-3.4.4 - Info Disclosure
CVSS 6.5
CVE-2025-55248 MEDIUM
.NET - Info Disclosure
CVSS 4.8
CVE-2025-39889 HIGH
Linux Kernel - Inadequate Encryption Key Size Validation in Bluetooth L2CAP
CVSS 8.1
CVE-2025-46409 HIGH
SS1 <16.0.0.10 - Info Disclosure
CVSS 7.5
CVE-2025-9513 LOW
Editso Fuso <1.0.4-beta.7 - Code Injection
CVSS 3.7
CVE-2025-9239 LOW
elunez eladmin <2.7 - Info Disclosure
CVSS 3.7
CVE-2025-45765 CRITICAL
ruby-jwt v3.0.0.beta1 - Info Disclosure
CVSS 9.1
CVE-2025-45764 LOW
jsrsasign v11.1.0 - Info Disclosure
CVSS 3.2
CVE-2025-45770 HIGH
Jwt < 5.4.3 - Weak Encryption
CVSS 7.0
CVE-2025-45769 MEDIUM
Google Firebase Php-jwt < 6.11.0 - Weak Encryption
CVSS 6.5
Details
Vulnerabilities 442