The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.
457 vulnerabilities with CWE-326
CVE-2019-17598
HIGH
Lightbend Play Framework 2.5.0-2.5.18 and 2.6.0-2.6.23 - Proxy Credential Exposure via HTTPS Connection
CVSS 7.5
CVE-2019-4339
HIGH
IBM Security Guardium Big Data Intelligence - Info Disclosure
CVSS 7.5
CVE-2019-16649
CRITICAL
Supermicro X11DAI-N & X11/H11/H12/M11/X9/X10 Firmware - Virtual Media Service Credential Exposure
CVSS 10.0
CVE-2019-4175
HIGH
IBM Cognos Controller 10.3.0, 10.3.1, 10.4.0, 10.4.1 - Inadequate Encryption Strength
CVSS 7.5
CVE-2019-15806
CRITICAL
CommScope ARRIS TR4400 - Auth Bypass
CVSS 9.8
CVE-2019-15805
CRITICAL
CommScope ARRIS TR4400 - Auth Bypass
CVSS 9.8
CVE-2019-14332
HIGH
D-Link 6600-AP & DWL-3600AP Ax - Info Disclosure
CVSS 7.8
CVE-2019-10639
HIGH
Linux kernel 4.1-4.20.9 - Information Exposure via IP ID Hash Collision
CVSS 7.5
CVE-2019-10638
MEDIUM
Linux Kernel < 5.1.7 - Information Exposure via IP ID Hash Collision
CVSS 6.5
CVE-2019-4102
MEDIUM
IBM DB2 9.7, 10.1, 10.5, 11.0 - Inadequate Encryption Strength
CVSS 5.9
CVE-2019-4151
MEDIUM
IBM Security Access Manager 9.0.1-9.0.6 - Inadequate Encryption Strength
CVSS 5.9
CVE-2019-6972
HIGH
TP-Link TL-WR1043ND V2 - Info Disclosure
CVSS 7.5
CVE-2019-4256
HIGH
IBM API Connect 5.0.0.0-5.0.8.6 - Inadequate Encryption Strength
CVSS 7.5
CVE-2019-10855
HIGH
Computrols CBAS < 19.0.0 - Inadequate Encryption Strength via MD5 Password Hashing
CVSS 7.5
CVE-2019-10112
HIGH
GitLab <11.7.8-11.9.2 - Info Disclosure
CVSS 7.5
CVE-2019-10907
CRITICAL
Airsonic 10.2.1 - Inadequate Encryption Strength in Remember-Me Mechanism
CVSS 9.8
CVE-2019-7648
HIGH
Hotels_Server <2018-11-05 - Info Disclosure
CVSS 7.5
CVE-2018-25272
CRITICAL
ELBA5 5.8.0 Remote Code Execution via Database Access
CVSS 9.8
CVE-2018-16499
MEDIUM
Versa Operating System - Inadequate Encryption Strength
CVSS 5.9
CVE-2018-21080
MEDIUM
Android - Lockscreen Bypass via NFC Magnet Activation
CVSS 4.6
CVE-2018-18325
HIGH
KEV
Dnnsoftware Dotnetnuke < 9.2.2 - Weak Encryption
CVSS 7.5
CVE-2018-15811
HIGH
KEV
Dnnsoftware Dotnetnuke < 9.2.1 - Weak Encryption
CVSS 7.5
CVE-2018-20810
CRITICAL
Pulse Secure Pulse Connect Secure <8.3R2 & Pulse Policy Secure <5.4R2 - Weak Cluster Sync Encryption
CVSS 9.8
CVE-2018-1608
MEDIUM
IBM Rational Engineering Lifecycle Manager <6.0.6 - Info Disclosure
CVSS 5.9
CVE-2018-2007
MEDIUM
IBM API Connect 2018.1-2018.4.1.2 - Inadequate Encryption Strength
CVSS 5.9
Details
Vulnerabilities
457