CWE-327
High likelihoodUse of a Broken or Risky Cryptographic Algorithm
The product uses a broken or risky cryptographic algorithm or protocol.
687 vulnerabilities with CWE-327
CVE-2026-65309
HIGH
ANDRITZ HIPASE-250 - Storage of Passwords in a Reversible Format
CVSS 7.5
CVE-2026-56582
LOW
HCL MyCloud was affected with SSL/TLS Protocol Affected with LUCKY13 Vulnerability.
CVSS 3.1
CVE-2026-63761
MEDIUM
SurrealDB before 3.1.0 Algorithm Downgrade via ES512
CVSS 4.3
CVE-2026-56454
MEDIUM
HCL DFXAnalytics is affected by a Deprecated Protocol vulnerability due to the use of TLS 1.0 and TLS 1.1.
CVSS 5.9
CVE-2026-15605
LOW
wandb Artifact Integrity Validation hashutil.py ArtifactManifestEntry.download weak hash
CVSS 3.1
CVE-2026-54780
LOW
CoreWCF: WS-Security Reference DigestMethod Algorithm-Suite Bypass
CVSS 3.7
CVE-2026-14742
LOW
langchain-ai langgraph Task Result Cache _cache.py _freeze weak hash
CVSS 3.1
CVE-2026-14738
LOW
exo-explore exo Vision Feature Cache vision.py _image_cache_key weak hash
CVSS 3.7
CVE-2026-14630
LOW
ForceInjection AI-fundermentals Memory Recall smart_customer_service.py get_conversation_history weak hash
CVSS 3.1
CVE-2026-57997
MEDIUM
Strapi users-permissions - JWT Algorithm Confusion via Missing Algorithm Configuration
CVSS 4.8
CVE-2026-13510
LOW
SimStudioAI sim Password Protection deployment.ts weak hash
CVSS 3.7
CVE-2026-13482
LOW
skypilot-org skypilot User ID server.py username.encode weak hash
CVSS 3.7
CVE-2026-47775
MEDIUM
Envoy OAuth2 Filter: Padding Oracle via AES-256-CBC Cookie Decryption
CVSS 6.8
CVE-2026-9221
HIGH
Setracker2 Children's Smartwatch Ecosystem Use of a Broken or Risky Cryptographic Algorithm
CVSS 7.5
CVE-2026-6330
MEDIUM
ML-KEM ARM64 NEON ciphertext comparison only compares half of the input
CVSS 6.5
CVE-2026-6412
MEDIUM
Continued acceptance of SHA-1/MD5 digests in certificate processing
CVSS 4.3
CVE-2026-50268
LOW
Steeltoe: OAEP setting silently selects PKCS#1 v1.5 padding
CVSS 1.9
CVE-2026-40641
MEDIUM
Dell PowerFlex - Use of a Broken or Risky Cryptographic Algorithm
CVSS 4.8
CVE-2026-9261
MEDIUM
Canon Inc. Eos Network Setting Tool For Windows - Use of a Broken or Risky Cryptographic Algorithm
CVSS 6.8
CVE-2026-50086
CRITICAL
Aqara unauthenticated AES oracle
CVSS 10.0
CVE-2026-40996
MEDIUM
Spring Web Services - Inbound RSA PKCS#1 v1.5 Key Transport Accepted by Default
CVSS 4.8
CVE-2026-11481
LOW
yoanbernabeu grepai Postgres Embedding Cache chunker.go PostgresStore.LookupByContentHash weak hash
CVSS 2.5
CVE-2026-11479
MEDIUM
yoanbernabeu grepai Qdrant Backend chunker.go weak hash
CVSS 4.2
CVE-2026-46395
CRITICAL
HAX CMS Vulnerable to Private Key Disclosure via Broken HMAC Implementation
CVE-2026-11330
LOW
thedotmack claude-mem Observation Content Hash store.ts computeObservationContentHash weak hash
CVSS 3.6
Details
Vulnerabilities
687
Exploit Likelihood
High