CWE-327

High likelihood

Use of a Broken or Risky Cryptographic Algorithm

Parent: CWE-693 - Protection Mechanism Failure

The product uses a broken or risky cryptographic algorithm or protocol.

669 vulnerabilities with CWE-327
CVE-2026-9261 MEDIUM
Canon Inc. Eos Network Setting Tool For Windows - Use of a Broken or Risky Cryptographic Algorithm
CVSS 6.8
CVE-2026-50086 CRITICAL
Aqara unauthenticated AES oracle
CVSS 10.0
CVE-2026-40996 MEDIUM
Spring Web Services - Inbound RSA PKCS#1 v1.5 Key Transport Accepted by Default
CVSS 4.8
CVE-2026-11481 LOW
yoanbernabeu grepai Postgres Embedding Cache chunker.go PostgresStore.LookupByContentHash weak hash
CVSS 2.5
CVE-2026-11479 MEDIUM
yoanbernabeu grepai Qdrant Backend chunker.go weak hash
CVSS 4.2
CVE-2026-46395 CRITICAL
HAX CMS Vulnerable to Private Key Disclosure via Broken HMAC Implementation
CVE-2026-11330 LOW
thedotmack claude-mem Observation Content Hash store.ts computeObservationContentHash weak hash
CVSS 3.6
CVE-2026-11329 LOW
onnx onnx-mlir Placeholder Node Cache backend.py generate_hash_key weak hash
CVSS 3.6
CVE-2026-10814 MEDIUM
milvus-io milvus Grantee ID Hash kv_catalog.go weak hash
CVSS 4.5
CVE-2026-10813 LOW
LMCache KV Cache utils.py hex_hash_to_int16 weak hash
CVSS 3.6
CVE-2026-10812 LOW
zilliztech GPTCache Cache Key pre.py BufferedReader.peek weak hash
CVSS 3.6
CVE-2026-10804 LOW
Streamlit Palette hashing.py weak hash
CVSS 3.6
CVE-2026-10803 LOW
MLflow Dataset Digest Computation digest_utils.py mlflow.data.digest_utils weak hash
CVSS 3.6
CVE-2026-10801 LOW
modelscope ms-swift PIL Image Cache Key base.py Template._save_pil_image weak hash
CVSS 3.6
CVE-2026-10800 LOW
PaddlePaddle FastDeploy MultimodalHasher hasher.py hash_features weak hash
CVSS 3.6
CVE-2026-10783 LOW
gradio-app gradio Audio Cache Key save_audio_to_cache weak hash
CVSS 2.5
CVE-2026-10766 LOW
mlrun DataFrame Hash helpers.py mlrun.utils.helpers.calculate_dataframe_hash weak hash
CVSS 3.6
CVE-2026-36609 HIGH
Mercusys AC12G (EU) V1 - Unauthenticated Password Recovery via Static Nonce and Predictable XOR Encoding
CVSS 7.3
CVE-2026-45701 MEDIUM
Sulu: Weak Cryptographical usage for API Key generation and Reset Tokens
CVE-2026-49323 MEDIUM
Indian Scout Bobber 2025 WCM-to-ECM weak authentication
CVSS 4.3
CVE-2026-49322 MEDIUM
Indian Scout Bobber 2025 WCM - Weak PIN Authentication
CVSS 4.3
CVE-2026-44053 HIGH
Netatalk 1.5.0-4.2.2 - Use of a Broken Cryptographic Algorithm in DHCAST128 UAM
CVSS 7.4
CVE-2026-8803 LOW
opensourcepos Open Source Point of Sale Employee Login Employee.php login weak hash
CVSS 3.7
CVE-2026-44699 CRITICAL
LibJWT: Algorithm confusion allows JWT forgery with RSA JWK as empty-key HMAC
CVE-2026-8072 CRITICAL
Insecure generation of SAT access credentials in Ingecon EMS Board
Details
Vulnerabilities 669
Exploit Likelihood High