CWE-327

High likelihood

Use of a Broken or Risky Cryptographic Algorithm

Parent: CWE-693 - Protection Mechanism Failure

The product uses a broken or risky cryptographic algorithm or protocol.

687 vulnerabilities with CWE-327
CVE-2026-29129 HIGH
Apache Tomcat: TLS cipher order is not preserved
CVSS 7.5
CVE-2026-5682 LOW
Meesho Online Shopping App com.meesho.supply endpoint risky encryption
CVSS 3.7
CVE-2026-34950 CRITICAL
fast-jwt <=6.1.0 - JWT Algorithm Confusion
CVSS 9.1
CVE-2026-25834 MEDIUM
Mbed TLS 3.3.0-3.6.5, 4.0.0 - Algorithm Downgrade
CVSS 6.5
CVE-2026-33512 HIGH
WWBN AVideo <=26.0 - Info Disclosure
CVSS 7.5
CVE-2026-28490 MEDIUM
Authlib Vulnerable to JWE RSA1_5 Bleichenbacher Padding Oracle
CVSS 6.5
CVE-2026-20996 MEDIUM
Samsung Mobile Smart Switch <3.7.69.15 - Auth Bypass
CVSS 5.3
CVE-2026-28252 CRITICAL
Trane Tracer SC/SC+/Concierge - Auth Bypass
CVSS 9.8
CVE-2026-28479 HIGH
OpenClaw <2026.2.15 - Cache Poisoning
CVSS 7.5
CVE-2026-3598 HIGH
RustDesk Server Pro <=1.7.5 - Info Disclosure
CVSS 7.5
CVE-2026-30791 HIGH
RustDesk Client <1.4.5 - Info Disclosure
CVSS 7.5
CVE-2026-23601 MEDIUM
Wi-Fi Encryption - Auth Bypass
CVSS 5.4
CVE-2026-1627 MEDIUM
Device SSH Service - Memory Corruption
CVSS 6.5
CVE-2026-1626 MEDIUM
Device SSH Service - Memory Corruption
CVSS 6.5
CVE-2026-21718 CRITICAL
Copeland XWEB Pro <1.12.1 - Auth Bypass
CVSS 10.0
CVE-2026-27804 CRITICAL
Parse Server <8.6.3/9.1.1-alpha.4 - Auth Bypass
CVSS 9.1
CVE-2026-27519 HIGH
Binardat 10G08-0800GSM <V300SP10260209 - Info Disclosure
CVSS 7.5
CVE-2026-2618 LOW
Beetel 777VR1 <01.00.09 - Weak Cryptography
CVSS 3.7
CVE-2026-26219 CRITICAL
newbee-mall < 1.0.0 - Use of Unsalted MD5 Password Hashing
CVSS 9.1
CVE-2026-24785 CRITICAL
Clatter < 2.2.0 - Use of a Broken or Risky Cryptographic Algorithm via PSK Validity Rule Violation
CVSS 9.1
CVE-2026-22585 CRITICAL
Salesforce Marketing Cloud Engagement < 2026-01-21 - Cryptographic Algorithm Vulnerability
CVSS 9.8
CVE-2026-21907 MEDIUM
Juniper Junos Space < 24.1R5 - Use of a Broken or Risky Cryptographic Algorithm in TLS/SSL Server
CVSS 5.9
CVE-2026-20833 MEDIUM
Windows Server 2008 and later - Information Disclosure via Broken Cryptographic Algorithm in Kerberos
CVSS 5.5
CVE-2026-21444 MEDIUM
libtpms 0.10.0-0.10.1 - Use of Insufficiently Random Values in IV Generation
CVSS 5.5
CVE-2025-10237 MEDIUM
Lenovo X13 Gen 6 (Type 21RK, 21RL) Laptops (ThinkPad) Bios - Use of a Broken or Risky Cryptographic Algorithm
CVSS 6.7
Details
Vulnerabilities 687
Exploit Likelihood High