CWE-327
High likelihoodUse of a Broken or Risky Cryptographic Algorithm
The product uses a broken or risky cryptographic algorithm or protocol.
669 vulnerabilities with CWE-327
CVE-2026-9261
MEDIUM
Canon Inc. Eos Network Setting Tool For Windows - Use of a Broken or Risky Cryptographic Algorithm
CVSS 6.8
CVE-2026-50086
CRITICAL
Aqara unauthenticated AES oracle
CVSS 10.0
CVE-2026-40996
MEDIUM
Spring Web Services - Inbound RSA PKCS#1 v1.5 Key Transport Accepted by Default
CVSS 4.8
CVE-2026-11481
LOW
yoanbernabeu grepai Postgres Embedding Cache chunker.go PostgresStore.LookupByContentHash weak hash
CVSS 2.5
CVE-2026-11479
MEDIUM
yoanbernabeu grepai Qdrant Backend chunker.go weak hash
CVSS 4.2
CVE-2026-46395
CRITICAL
HAX CMS Vulnerable to Private Key Disclosure via Broken HMAC Implementation
CVE-2026-11330
LOW
thedotmack claude-mem Observation Content Hash store.ts computeObservationContentHash weak hash
CVSS 3.6
CVE-2026-11329
LOW
onnx onnx-mlir Placeholder Node Cache backend.py generate_hash_key weak hash
CVSS 3.6
CVE-2026-10814
MEDIUM
milvus-io milvus Grantee ID Hash kv_catalog.go weak hash
CVSS 4.5
CVE-2026-10813
LOW
LMCache KV Cache utils.py hex_hash_to_int16 weak hash
CVSS 3.6
CVE-2026-10812
LOW
zilliztech GPTCache Cache Key pre.py BufferedReader.peek weak hash
CVSS 3.6
CVE-2026-10804
LOW
Streamlit Palette hashing.py weak hash
CVSS 3.6
CVE-2026-10803
LOW
MLflow Dataset Digest Computation digest_utils.py mlflow.data.digest_utils weak hash
CVSS 3.6
CVE-2026-10801
LOW
modelscope ms-swift PIL Image Cache Key base.py Template._save_pil_image weak hash
CVSS 3.6
CVE-2026-10800
LOW
PaddlePaddle FastDeploy MultimodalHasher hasher.py hash_features weak hash
CVSS 3.6
CVE-2026-10783
LOW
gradio-app gradio Audio Cache Key save_audio_to_cache weak hash
CVSS 2.5
CVE-2026-10766
LOW
mlrun DataFrame Hash helpers.py mlrun.utils.helpers.calculate_dataframe_hash weak hash
CVSS 3.6
CVE-2026-36609
HIGH
Mercusys AC12G (EU) V1 - Unauthenticated Password Recovery via Static Nonce and Predictable XOR Encoding
CVSS 7.3
CVE-2026-45701
MEDIUM
Sulu: Weak Cryptographical usage for API Key generation and Reset Tokens
CVE-2026-49323
MEDIUM
Indian Scout Bobber 2025 WCM-to-ECM weak authentication
CVSS 4.3
CVE-2026-49322
MEDIUM
Indian Scout Bobber 2025 WCM - Weak PIN Authentication
CVSS 4.3
CVE-2026-44053
HIGH
Netatalk 1.5.0-4.2.2 - Use of a Broken Cryptographic Algorithm in DHCAST128 UAM
CVSS 7.4
CVE-2026-8803
LOW
opensourcepos Open Source Point of Sale Employee Login Employee.php login weak hash
CVSS 3.7
CVE-2026-44699
CRITICAL
LibJWT: Algorithm confusion allows JWT forgery with RSA JWK as empty-key HMAC
CVE-2026-8072
CRITICAL
Insecure generation of SAT access credentials in Ingecon EMS Board
Details
Vulnerabilities
669
Exploit Likelihood
High