CWE-326

Inadequate Encryption Strength

Parent: CWE-693 - Protection Mechanism Failure

The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.

457 vulnerabilities with CWE-326
CVE-2022-38659 MEDIUM
HCL BigFix Platform 9.5-9.5.19 - Inadequate Encryption Strength of Operator Credentials
CVSS 6.0
CVE-2022-46825 MEDIUM
JetBrains IntelliJ IDEA <2022.3 - Info Disclosure
CVSS 4.0
CVE-2022-2640 HIGH
Horner Automation's RCC 972 <15.40 - Info Disclosure
CVSS 7.5
CVE-2022-4036 MEDIUM
WordPress Appointment Hour Booking <1.3.72 - Auth Bypass
CVSS 5.3
CVE-2022-45379 HIGH
Jenkins Script Security Plugin < 1190.v65867a_a_47126 - Inadequate Encryption Strength via SHA-1 Hash Collision
CVSS 7.5
CVE-2022-41209 MEDIUM
SAP Customer Data Cloud Gigya mobile app for Android <7.4 - Info Di...
CVSS 5.2
CVE-2022-3433 MEDIUM
aeson < 2.0.1.0 - Denial of Service via Hash Collision in JSON Input
CVSS 6.5
CVE-2022-3273 CRITICAL
GitHub ikus060/rdiffweb <2.5.0a4 - DoS
CVSS 9.8
CVE-2022-29835 MEDIUM
WD Discovery < 4.4.396 - Inadequate Encryption Strength via SHA-1 Signed Executables
CVSS 5.3
CVE-2022-35931 LOW
Nextcloud <22.2.10, <23.0.7, <24.0.3 - Info Disclosure
CVSS 2.7
CVE-2022-2758 MEDIUM
LS Electric XG5000 < V4.0 and XGK/XGI/XGR/XGB PLCs - Inadequate Encryption Strength
CVSS 6.5
CVE-2022-36555 CRITICAL
Hytec Inter HWL-2511-SS <v1.05 - Info Disclosure
CVSS 9.8
CVE-2022-21139 HIGH
Intel Wireless Firmware < 22.120 - Unauthenticated Privilege Escalation via Inadequate Encryption Strength
CVSS 8.8
CVE-2022-30285 CRITICAL
Quest KACE Systems Management Appliance <= 12.0 - Authentication Bypass via Hash Collision
CVSS 9.8
CVE-2022-26307 HIGH
LibreOffice 7.2.0-7.2.6 and 7.3.0-7.3.2 - Inadequate Encryption Strength in Password Storage
CVSS 8.8
CVE-2022-26306 HIGH
LibreOffice 7.2.0-7.2.6 and 7.3.0 - Inadequate Encryption Strength in Stored Passwords
CVSS 7.5
CVE-2022-22453 HIGH
IBM Security Verify Identity Manager 10.0 - Info Disclosure
CVSS 7.5
CVE-2022-22464 HIGH
IBM Security Access Manager Appliance - Info Disclosure
CVSS 7.5
CVE-2022-31459 HIGH
Owl Labs Meeting Owl <5.2.0.15 - Info Disclosure
CVSS 7.4
CVE-2022-29249 HIGH
JavaEZ 1.6 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 7.5
CVE-2022-29161 MEDIUM
XWiki < 13.10.6 - Use of Broken Cryptographic Algorithm in X509 Certificate Generation
CVSS 5.4
CVE-2022-22368 HIGH
IBM Spectrum Scale <5.1.4 - Info Disclosure
CVSS 7.5
CVE-2022-29566 HIGH
Bulletproofs - Inadequate Encryption Strength via Frozen Heart Issue
CVSS 8.1
CVE-2022-1318 MEDIUM
Hills ComNav < 3002-19 - Inadequate Encryption Strength in Local Network Configuration Traffic
CVSS 6.2
CVE-2022-20677 MEDIUM
Cisco IOx - Path Traversal
CVSS 5.5
Details
Vulnerabilities 457