CWE-327

High likelihood

Use of a Broken or Risky Cryptographic Algorithm

Parent: CWE-693 - Protection Mechanism Failure

The product uses a broken or risky cryptographic algorithm or protocol.

669 vulnerabilities with CWE-327
CVE-2026-26219 CRITICAL
newbee-mall < 1.0.0 - Use of Unsalted MD5 Password Hashing
CVSS 9.1
CVE-2026-24785 CRITICAL
Clatter < 2.2.0 - Use of a Broken or Risky Cryptographic Algorithm via PSK Validity Rule Violation
CVSS 9.1
CVE-2026-22585 CRITICAL
Salesforce Marketing Cloud Engagement < 2026-01-21 - Cryptographic Algorithm Vulnerability
CVSS 9.8
CVE-2026-21907 MEDIUM
Juniper Junos Space < 24.1R5 - Use of a Broken or Risky Cryptographic Algorithm in TLS/SSL Server
CVSS 5.9
CVE-2026-20833 MEDIUM
Windows Server 2008 and later - Information Disclosure via Broken Cryptographic Algorithm in Kerberos
CVSS 5.5
CVE-2026-21444 MEDIUM
libtpms 0.10.0-0.10.1 - Use of Insufficiently Random Values in IV Generation
CVSS 5.5
CVE-2025-10237 MEDIUM
Lenovo X13 Gen 6 (Type 21RK, 21RL) Laptops (ThinkPad) Bios - Use of a Broken or Risky Cryptographic Algorithm
CVSS 6.7
CVE-2025-46371 LOW
Dell PowerFlex Manager (Appliance) - Use of a Broken or Risky Cryptographic Algorithm
CVSS 3.6
CVE-2025-14813 CRITICAL
GOSTCTR implementation unable to process more than 255 blocks correctly
CVE-2025-14859 HIGH
Semtech LR11xx Secure Boot Bypass
CVE-2025-13916 MEDIUM
IBM Aspera Shares 1.9.9-1.11.0 - Weak Cryptography
CVSS 5.9
CVE-2025-41711 MEDIUM
Firmware Images - Info Disclosure
CVSS 5.3
CVE-2025-13476 CRITICAL
Rakuten Viber 25.7.2.0g/25.6.0.0-25.8.1.0 - Info Disclosure
CVSS 9.8
CVE-2025-14480 MEDIUM
IBM Aspera faspio Gateway 1.3.6 - Info Disclosure
CVSS 5.1
CVE-2025-14456 MEDIUM
IBM MQ Appliance 9.4 CD 9.4.4.0-9.4.4.1 - Vuln Type
CVSS 5.9
CVE-2025-63912 HIGH
Cohesity TranZman 4.0 Build 14614 - Info Disclosure
CVSS 7.5
CVE-2025-66598 HIGH
FAST/TOOLS <10.04 - Info Disclosure
CVSS 7.5
CVE-2025-66597 HIGH
Yokogawa Electric Corporation FAST/TOOLS <10.04 - Info Disclosure
CVSS 7.5
CVE-2025-69929 CRITICAL
N3uron Web User Interface 1.21.7-240207.1047 - Privilege Escalation via MD5 Password Hashing
CVSS 9.8
CVE-2025-62514 HIGH
Parsec 3.0.0-3.5.x - Weak Curve25519 Order Point Validation in RustCrypto Backend
CVSS 8.3
CVE-2025-52026 HIGH
Aptsys gemscms_backend < 2025-05-28 - Sensitive Information Exposure via /srvs/membersrv/getCashiers
CVSS 7.5
CVE-2025-58743 HIGH
Milner ImageDirector Capture <7.6.3.25808 - Use After Free
CVSS 7.5
CVE-2025-68931 HIGH
Jervis < 2.2 - Improper Authentication via AES/CBC/PKCS5Padding
CVSS 7.5
CVE-2025-68702 HIGH
Jervis < 2.2 - Use of a Broken Cryptographic Algorithm in SHA-256 Padding
CVSS 7.5
CVE-2025-68701 HIGH
Jervis < 2.2 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 7.5
Details
Vulnerabilities 669
Exploit Likelihood High