CWE-327
High likelihoodUse of a Broken or Risky Cryptographic Algorithm
The product uses a broken or risky cryptographic algorithm or protocol.
636 vulnerabilities with CWE-327
CVE-2026-7103
LOW
code-projects Chat System MD5 Hash update_user.php weak hash
CVSS 3.7
CVE-2026-5926
MEDIUM
Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access
CVSS 6.5
CVE-2026-32959
MEDIUM
silex technology SD-330AC <=Ver.1.42 - MITM
CVSS 5.9
CVE-2026-5588
CRITICAL
PKIX draft CompositeVerifier accepts empty signature sequence as valid.
CVE-2026-29129
HIGH
Apache Tomcat: TLS cipher order is not preserved
CVSS 7.5
CVE-2026-5682
LOW
Meesho Online Shopping App com.meesho.supply endpoint risky encryption
CVSS 3.7
CVE-2026-34950
CRITICAL
fast-jwt has an incomplete fix for CVE-2023-48223: JWT Algorithm Confusion via Whitespace-Prefixed RSA Public Key
CVSS 9.1
CVE-2026-25834
MEDIUM
Mbed TLS 3.3.0-3.6.5, 4.0.0 - Algorithm Downgrade
CVSS 6.5
CVE-2026-33512
HIGH
WWBN AVideo <=26.0 - Info Disclosure
CVSS 7.5
CVE-2026-28490
MEDIUM
Authlib Vulnerable to JWE RSA1_5 Bleichenbacher Padding Oracle
CVSS 6.5
CVE-2026-20996
MEDIUM
Samsung Mobile Smart Switch <3.7.69.15 - Auth Bypass
CVSS 5.3
CVE-2026-28252
CRITICAL
Trane Tracer SC/SC+/Concierge - Auth Bypass
CVSS 9.8
CVE-2026-28479
HIGH
OpenClaw <2026.2.15 - Cache Poisoning
CVSS 7.5
CVE-2026-3598
HIGH
RustDesk Server Pro <=1.7.5 - Info Disclosure
CVSS 7.5
CVE-2026-30791
HIGH
RustDesk Client <1.4.5 - Info Disclosure
CVSS 7.5
CVE-2026-23601
MEDIUM
Wi-Fi Encryption - Auth Bypass
CVSS 5.4
CVE-2026-1627
MEDIUM
Device SSH Service - Memory Corruption
CVSS 6.5
CVE-2026-1626
MEDIUM
Device SSH Service - Memory Corruption
CVSS 6.5
CVE-2026-21718
CRITICAL
Copeland XWEB Pro <1.12.1 - Auth Bypass
CVSS 10.0
CVE-2026-27804
CRITICAL
Parse Server <8.6.3/9.1.1-alpha.4 - Auth Bypass
CVSS 9.1
CVE-2026-27519
HIGH
Binardat 10G08-0800GSM <V300SP10260209 - Info Disclosure
CVSS 7.5
CVE-2026-2618
LOW
Beetel 777VR1 <01.00.09 - Weak Cryptography
CVSS 3.7
CVE-2026-26219
CRITICAL
newbee-mall - Info Disclosure
CVSS 9.1
CVE-2026-24785
CRITICAL
Crates.io Clatter < 2.2.0 - Broken Cryptographic Algorithm
CVSS 9.1
CVE-2026-22585
CRITICAL
Salesforce Marketing Cloud Engagement - Broken Cryptographic Algorithm
CVSS 9.8
Details
Vulnerabilities
636
Exploit Likelihood
High