The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.
457 vulnerabilities with CWE-326
CVE-2022-38659
MEDIUM
HCL BigFix Platform 9.5-9.5.19 - Inadequate Encryption Strength of Operator Credentials
CVSS 6.0
CVE-2022-46825
MEDIUM
JetBrains IntelliJ IDEA <2022.3 - Info Disclosure
CVSS 4.0
CVE-2022-2640
HIGH
Horner Automation's RCC 972 <15.40 - Info Disclosure
CVSS 7.5
CVE-2022-4036
MEDIUM
WordPress Appointment Hour Booking <1.3.72 - Auth Bypass
CVSS 5.3
CVE-2022-45379
HIGH
Jenkins Script Security Plugin < 1190.v65867a_a_47126 - Inadequate Encryption Strength via SHA-1 Hash Collision
CVSS 7.5
CVE-2022-41209
MEDIUM
SAP Customer Data Cloud Gigya mobile app for Android <7.4 - Info Di...
CVSS 5.2
CVE-2022-3433
MEDIUM
aeson < 2.0.1.0 - Denial of Service via Hash Collision in JSON Input
CVSS 6.5
CVE-2022-3273
CRITICAL
GitHub ikus060/rdiffweb <2.5.0a4 - DoS
CVSS 9.8
CVE-2022-29835
MEDIUM
WD Discovery < 4.4.396 - Inadequate Encryption Strength via SHA-1 Signed Executables
CVSS 5.3
CVE-2022-35931
LOW
Nextcloud <22.2.10, <23.0.7, <24.0.3 - Info Disclosure
CVSS 2.7
CVE-2022-2758
MEDIUM
LS Electric XG5000 < V4.0 and XGK/XGI/XGR/XGB PLCs - Inadequate Encryption Strength
CVSS 6.5
CVE-2022-36555
CRITICAL
Hytec Inter HWL-2511-SS <v1.05 - Info Disclosure
CVSS 9.8
CVE-2022-21139
HIGH
Intel Wireless Firmware < 22.120 - Unauthenticated Privilege Escalation via Inadequate Encryption Strength
CVSS 8.8
CVE-2022-30285
CRITICAL
Quest KACE Systems Management Appliance <= 12.0 - Authentication Bypass via Hash Collision
CVSS 9.8
CVE-2022-26307
HIGH
LibreOffice 7.2.0-7.2.6 and 7.3.0-7.3.2 - Inadequate Encryption Strength in Password Storage
CVSS 8.8
CVE-2022-26306
HIGH
LibreOffice 7.2.0-7.2.6 and 7.3.0 - Inadequate Encryption Strength in Stored Passwords
CVSS 7.5
CVE-2022-22453
HIGH
IBM Security Verify Identity Manager 10.0 - Info Disclosure
CVSS 7.5
CVE-2022-22464
HIGH
IBM Security Access Manager Appliance - Info Disclosure
CVSS 7.5
CVE-2022-31459
HIGH
Owl Labs Meeting Owl <5.2.0.15 - Info Disclosure
CVSS 7.4
CVE-2022-29249
HIGH
JavaEZ 1.6 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 7.5
CVE-2022-29161
MEDIUM
XWiki < 13.10.6 - Use of Broken Cryptographic Algorithm in X509 Certificate Generation
CVSS 5.4
CVE-2022-22368
HIGH
IBM Spectrum Scale <5.1.4 - Info Disclosure
CVSS 7.5
CVE-2022-29566
HIGH
Bulletproofs - Inadequate Encryption Strength via Frozen Heart Issue
CVSS 8.1
CVE-2022-1318
MEDIUM
Hills ComNav < 3002-19 - Inadequate Encryption Strength in Local Network Configuration Traffic
CVSS 6.2
CVE-2022-20677
MEDIUM
Cisco IOx - Path Traversal
CVSS 5.5
Details
Vulnerabilities
457