The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.
448 vulnerabilities with CWE-326
CVE-2026-41860
HIGH
Cloud Foundry Foundation Bosh < 282.1.9 - Inadequate Encryption Strength
CVSS 8.8
CVE-2026-8878
HIGH
Securly Chrome Extension < 3.0.7 - Unauthenticated Sensitive Data Exposure via Public Endpoints
CVSS 7.5
CVE-2026-45787
CRITICAL
electerm's encrypt method not safe enough
CVSS 9.1
CVE-2026-44523
CRITICAL
Note Mark: JWT Secret Weakness allows Full Account Takeover via token forgery
CVSS 10.0
CVE-2026-44351
CRITICAL
fast-jwt: Empty HMAC secret accepted via async key resolver - JWT auth bypass
CVSS 9.1
CVE-2026-33361
HIGH
Meari weak XOR obfuscation
CVSS 7.5
CVE-2026-5363
HIGH
Use of weak cryptographic key in TP-Link Archer C7
CVSS 8.8
CVE-2026-5889
MEDIUM
Google Chrome <147.0.7727.55 - Info Disclosure
CVSS 4.3
CVE-2026-39349
LOW
OrangeHRM Uses AES-ECB for Sensitive Data Encryption Enables Pattern Disclosure
CVSS 2.7
CVE-2026-28377
HIGH
S3 SSE-C Encryption Key Exposed in Plaintext via Config Endpoint (CVE-2025-41118 Pattern)
CVSS 7.5
CVE-2026-33512
HIGH
WWBN AVideo <=26.0 - Info Disclosure
CVSS 7.5
CVE-2026-33488
HIGH
AVideo <=26.0 LoginControl PGP - Two-Factor Authentication Bypass
CVSS 7.4
CVE-2026-0510
LOW
NetWeaver Application Server for Java - Info Disclosure
CVSS 3.0
CVE-2025-1241
MEDIUM
Encryption vulnerable to brute-force decryption in GoAnywhere MFT
CVSS 5.8
CVE-2025-36379
MEDIUM
IBM Security QRadar EDR 3.12-3.12.23 - Info Disclosure
CVSS 5.9
CVE-2025-68703
HIGH
Jervis < 2.2 - Inadequate Encryption Strength via Predictable Salt Derivation
CVSS 7.5
CVE-2025-65295
HIGH
Aqara Hub <4.1.9_0027-4.3.6_0025 - RCE
CVSS 8.1
CVE-2025-41743
MEDIUM
Sprecher Automation - Info Disclosure
CVSS 4.0
CVE-2025-11935
HIGH
wolfssl 5.8.2-5.8.3 - Inadequate Encryption Strength via TLS 1.3 PSK Without PFS
CVSS 7.5
CVE-2025-12439
MEDIUM
Google Chrome < 142.0.7444.59 - Inadequate Encryption Strength in App-Bound Encryption
CVSS 5.5
CVE-2025-12478
CRITICAL
BLU-IC2 and BLU-IC4 Firmware < 1.20 - Inadequate Encryption Strength
CVSS 9.8
CVE-2025-55039
MEDIUM
Apache Spark <4.0.0-3.5.2-3.4.4 - Info Disclosure
CVSS 6.5
CVE-2025-55248
MEDIUM
.NET Framework - Inadequate Encryption Strength
CVSS 4.8
CVE-2025-39889
HIGH
Linux Kernel - Inadequate Encryption Key Size Validation in Bluetooth L2CAP
CVSS 8.1
CVE-2025-46409
HIGH
SS1 <16.0.0.10 - Info Disclosure
CVSS 7.5
Details
Vulnerabilities
448