CWE-327
High likelihoodUse of a Broken or Risky Cryptographic Algorithm
The product uses a broken or risky cryptographic algorithm or protocol.
669 vulnerabilities with CWE-327
CVE-2021-39058
HIGH
IBM Spectrum Copy Data Management < 2.2.13 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 7.5
CVE-2021-39002
HIGH
IBM DB2 9.7, 10.1, 10.5, 11.1, 11.5 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 7.5
CVE-2021-43808
MEDIUM
Laravel <8.75.0, 7.30.6, 6.20.42 - XSS
CVSS 5.3
CVE-2021-22170
MEDIUM
GitLab 11.6.0-13.5.5 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 6.2
CVE-2021-22356
MEDIUM
Huawei IPS/NGFW/USG Modules - Information Disclosure via Weak Cryptographic Algorithm
CVSS 5.9
CVE-2021-41278
MEDIUM
EdgeX Foundry app-functions-sdk-go < 2.1.0 - Use of a Broken or Risky Cryptographic Algorithm in AES Transform
CVSS 5.7
CVE-2021-41263
HIGH
rails_multisite <4 - Info Disclosure
CVSS 8.3
CVE-2021-39182
HIGH
EnroCrypt < 1.1.4 - Use of Broken MD5 Hashing Algorithm
CVSS 7.5
CVE-2021-41168
MEDIUM
reddit/snudown < 1.7.0 - Denial of Service via Reference Table Hash Collision
CVSS 6.5
CVE-2021-31352
MEDIUM
Juniper Session and Resource Control < 4.130r6 - Information Exposure via Weak NETCONF Cipher Negotiation
CVSS 5.3
CVE-2021-36298
HIGH
Dell EMC InsightIQ <4.1.4 - Auth Bypass
CVSS 8.1
CVE-2021-29894
HIGH
IBM Cloud Pak for Security 1.7.0.0, 1.7.1.0, 1.7.2.0, 1.8.0.0 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 7.5
CVE-2021-41096
HIGH
Rucky < 2.2 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 7.5
CVE-2021-29750
HIGH
IBM QRadar SIEM 7.3 and 7.4 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 7.5
CVE-2021-40530
MEDIUM
Crypto++ < 8.5 - Plaintext Recovery via ElGamal Cross-Configuration Attack
CVSS 5.9
CVE-2021-40529
MEDIUM
Botan < 2.18.1 - Plaintext Recovery via ElGamal Cross-Configuration Attack
CVSS 5.9
CVE-2021-40528
MEDIUM
libgcrypt < 1.9.4 - Plaintext Recovery via ElGamal Cross-Configuration Attack
CVSS 5.9
CVE-2021-31796
HIGH
CyberArk Credential Provider < 12.1 - Information Disclosure via Inadequate Encryption
CVSS 7.5
CVE-2021-33003
MEDIUM
Delta Electronics DIAEnergie <1.7.5 - Info Disclosure
CVSS 5.5
CVE-2021-29723
HIGH
IBM Sterling Secure Proxy 6.0.1, 6.0.2, 2.4.3.2, and 3.4.3.2 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 7.5
CVE-2021-29722
HIGH
IBM Sterling Secure Proxy 6.0.1, 6.0.2, 2.4.3.2, and 3.4.3.2 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 7.5
CVE-2021-27913
LOW
Mautic <3.3.4, <4.0.0 - Info Disclosure
CVSS 3.5
CVE-2021-29704
HIGH
IBM Security SOAR < 42.0 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 7.5
CVE-2021-37546
MEDIUM
JetBrains TeamCity < 2021.1 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 5.3
CVE-2021-37588
MEDIUM
Charm 0.43 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 5.9
Details
Vulnerabilities
669
Exploit Likelihood
High