CWE-327

High likelihood

Use of a Broken or Risky Cryptographic Algorithm

Parent: CWE-693 - Protection Mechanism Failure

The product uses a broken or risky cryptographic algorithm or protocol.

686 vulnerabilities with CWE-327
CVE-2026-56582 LOW
HCL MyCloud was affected with SSL/TLS Protocol Affected with LUCKY13 Vulnerability.
CVSS 3.1
CVE-2026-63761 MEDIUM
SurrealDB before 3.1.0 Algorithm Downgrade via ES512
CVSS 4.3
CVE-2026-56454 MEDIUM
HCL DFXAnalytics is affected by a Deprecated Protocol vulnerability due to the use of TLS 1.0 and TLS 1.1.
CVSS 5.9
CVE-2026-15605 LOW
wandb Artifact Integrity Validation hashutil.py ArtifactManifestEntry.download weak hash
CVSS 3.1
CVE-2026-54780 LOW
CoreWCF: WS-Security Reference DigestMethod Algorithm-Suite Bypass
CVSS 3.7
CVE-2026-14742 LOW
langchain-ai langgraph Task Result Cache _cache.py _freeze weak hash
CVSS 3.1
CVE-2026-14738 LOW
exo-explore exo Vision Feature Cache vision.py _image_cache_key weak hash
CVSS 3.7
CVE-2026-14630 LOW
ForceInjection AI-fundermentals Memory Recall smart_customer_service.py get_conversation_history weak hash
CVSS 3.1
CVE-2026-57997 MEDIUM
Strapi users-permissions - JWT Algorithm Confusion via Missing Algorithm Configuration
CVSS 4.8
CVE-2026-13510 LOW
SimStudioAI sim Password Protection deployment.ts weak hash
CVSS 3.7
CVE-2026-13482 LOW
skypilot-org skypilot User ID server.py username.encode weak hash
CVSS 3.7
CVE-2026-47775 MEDIUM
Envoy OAuth2 Filter: Padding Oracle via AES-256-CBC Cookie Decryption
CVSS 6.8
CVE-2026-9221 HIGH
Setracker2 Children's Smartwatch Ecosystem Use of a Broken or Risky Cryptographic Algorithm
CVSS 7.5
CVE-2026-6330 MEDIUM
ML-KEM ARM64 NEON ciphertext comparison only compares half of the input
CVSS 6.5
CVE-2026-6412 MEDIUM
Continued acceptance of SHA-1/MD5 digests in certificate processing
CVSS 4.3
CVE-2026-50268 LOW
Steeltoe: OAEP setting silently selects PKCS#1 v1.5 padding
CVSS 1.9
CVE-2026-40641 MEDIUM
Dell PowerFlex - Use of a Broken or Risky Cryptographic Algorithm
CVSS 4.8
CVE-2026-9261 MEDIUM
Canon Inc. Eos Network Setting Tool For Windows - Use of a Broken or Risky Cryptographic Algorithm
CVSS 6.8
CVE-2026-50086 CRITICAL
Aqara unauthenticated AES oracle
CVSS 10.0
CVE-2026-40996 MEDIUM
Spring Web Services - Inbound RSA PKCS#1 v1.5 Key Transport Accepted by Default
CVSS 4.8
CVE-2026-11481 LOW
yoanbernabeu grepai Postgres Embedding Cache chunker.go PostgresStore.LookupByContentHash weak hash
CVSS 2.5
CVE-2026-11479 MEDIUM
yoanbernabeu grepai Qdrant Backend chunker.go weak hash
CVSS 4.2
CVE-2026-46395 CRITICAL
HAX CMS Vulnerable to Private Key Disclosure via Broken HMAC Implementation
CVE-2026-11330 LOW
thedotmack claude-mem Observation Content Hash store.ts computeObservationContentHash weak hash
CVSS 3.6
CVE-2026-11329 LOW
onnx onnx-mlir Placeholder Node Cache backend.py generate_hash_key weak hash
CVSS 3.6
Details
Vulnerabilities 686
Exploit Likelihood High