CWE-327

High likelihood

Use of a Broken or Risky Cryptographic Algorithm

Parent: CWE-693 - Protection Mechanism Failure

The product uses a broken or risky cryptographic algorithm or protocol.

687 vulnerabilities with CWE-327
CVE-2025-14759 MEDIUM
Amazon S3 Encryption Client for .NET < 3.2.0 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 5.3
CVE-2025-14636 LOW
Tenda AX9 22.03.01.46 - Use of Weak Hash in httpd image_check Function
CVSS 3.7
CVE-2025-54981 HIGH
Apache StreamPark 2.0.0-2.1.6 - Weak Encryption Algorithm via AES-ECB Mode
CVSS 7.5
CVE-2025-65831 HIGH
Meatmeet - Use of Insecure Hashing Algorithm
CVSS 7.5
CVE-2025-65849 CRITICAL
Altcha Proof-of-Work >=0.8.0 - Info Disclosure
CVSS 9.1
CVE-2025-66017 HIGH
CGGMP21 <0.6.3, CGGMP24 <0.7.0-alpha.1 - Info Disclosure
CVE-2025-65951 HIGH
Inside Track / Entropy Derby <2d38d2f - Info Disclosure
CVSS 8.7
CVE-2025-36150 MEDIUM
IBM Concert 1.0.0-2.0.0 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 5.9
CVE-2025-36161 MEDIUM
IBM Concert 1.0.0-2.0.0 - Sensitive Information Exposure via Missing HSTS
CVSS 5.9
CVE-2025-9317 HIGH
Edge Project <unknown - Info Disclosure
CVSS 8.4
CVE-2025-54340 MEDIUM
Desktop Alert PingAlert Application Server 6.1.0.11-6.1.1.2 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 4.1
CVE-2025-64429 MEDIUM
duckdb 1.4.0-1.4.2 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 6.5
CVE-2025-43723 MEDIUM
Dell PowerScale OneFS < 9.10.1.3, 9.11.0.0-9.12.0.0 - Unauthenticated Info Disclosure via Broken Crypto
CVSS 5.9
CVE-2025-34500 HIGH
Deck Mate 2 < all known versions prior to 2025-10-23 - Arbitrary Code Execution via Insecure Firmware Update Chain
CVE-2025-34519 HIGH
Ilevia EVE X1 Server Firmware <= 4.7.18.0.eden - Insecure Password Hashing via Unsalted MD5
CVSS 7.5
CVE-2025-11650 LOW
Furbo 360 Dog Camera Firmware < 036 and Furbo Mini Firmware < 074 - Use of Weak Hash in Password Handler
CVSS 1.8
CVE-2025-21062 HIGH
Samsung Smart Switch < 3.7.67.2 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 7.8
CVE-2025-43913 MEDIUM
Dell PowerProtect Data Domain Unauthenticated Information Disclosure via Broken Cryptographic Algorithm
CVSS 5.3
CVE-2025-43909 LOW
Dell PowerProtect Data Domain Unauthenticated Information Exposure via DD Boost
CVSS 3.7
CVE-2025-43891 MEDIUM
Dell PowerProtect Data Domain Unauthenticated Information Disclosure via Broken Cryptographic Algorithm
CVSS 5.3
CVE-2025-34208 HIGH
Vasion Print Virtual Appliance Host and Application - Weak Password Hashing via Unsalted SHA-512 and SHA-1
CVSS 7.5
CVE-2025-59745 HIGH
AndSoft e-TMS 25.03 - Use of Broken Cryptographic Algorithm via MD5 Password Hashing
CVSS 7.5
CVE-2025-59408 HIGH
Flock Safety Bravo Compute Box Firmware BRAVO_00.00_local_20241017 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 7.3
CVE-2025-59484 HIGH
Click Plus PLC <3.60 - Info Disclosure
CVSS 8.3
CVE-2025-37127 HIGH
HPE Aruba Networking EdgeConnect - RCE
CVSS 7.2
Details
Vulnerabilities 687
Exploit Likelihood High