CWE-327

High likelihood

Use of a Broken or Risky Cryptographic Algorithm

Parent: CWE-693 - Protection Mechanism Failure

The product uses a broken or risky cryptographic algorithm or protocol.

687 vulnerabilities with CWE-327
CVE-2024-22347 MEDIUM
IBM DevOps Velocity 5.0.0 and UrbanCode Velocity 4.0.0-4.0.25 - Use of Weak Cryptographic Algorithms
CVSS 5.9
CVE-2024-8603 HIGH
B&R Automation Runtime <6.1, B&R mapp View <6.1 - Use After Free
CVSS 7.5
CVE-2024-51456 MEDIUM
IBM Robotic Process Automation <23.0.19 - Info Disclosure
CVSS 5.9
CVE-2024-52366 MEDIUM
IBM Concert Software <1.0.4 - Info Disclosure
CVSS 5.9
CVE-2024-41763 MEDIUM
IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 5.9
CVE-2024-47921 HIGH
Smadar SPS - Use of a Broken or Risky Cryptographic Algorithm
CVSS 8.4
CVE-2024-55539 LOW
Acronis Cyber Protect <build 39185-39938 - Info Disclosure
CVSS 2.5
CVE-2024-28980 MEDIUM
Dell RecoverPoint for Virtual Machines 6.0.x - Use of a Broken or Risky Cryptographic Algorithm in SSH
CVSS 6.5
CVE-2024-55885 HIGH
beego < 2.3.4 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 7.5
CVE-2024-53845 MEDIUM
ESPTouch <5.3.2-5.0.8 - Info Disclosure
CVE-2024-53441 CRITICAL
cookie-encrypter 1.0.1 - Bit Flipping Attack via DecryptCookie Function
CVSS 9.1
CVE-2024-48847 HIGH
ABB ASPECT/MATRIX/NEXUS Firmware < 3.08.03 - MD5 Checksum Bypass via Weak Hash Validation
CVSS 8.2
CVE-2024-41775 MEDIUM
IBM Cognos Controller 11.0.0 and 11.0.1 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 5.9
CVE-2024-52801 MEDIUM
sftpgo 2.3.0-2.6.3 - Authenticated Session Cookie Brute Force via Predictable xid Library
CVE-2024-43189 MEDIUM
IBM Concert Software <1.0.2 - Info Disclosure
CVSS 5.9
CVE-2024-51556 MEDIUM
63moons Wave 2.0 < 1.1.7 - Authenticated Sensitive Data Exposure via Insufficient API Response Encryption
CVSS 6.5
CVE-2024-51478 CRITICAL
YesWiki < 4.4.5 - Weak Password Reset Key Hashing via Hardcoded Salt
CVSS 9.9
CVE-2024-10128 LOW
Topdata Inner Rep Plus WebServer 2.01 - Info Disclosure
CVSS 2.7
CVE-2024-48016 MEDIUM
Dell Secure Connect Gateway 5.24 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 4.6
CVE-2024-47188 HIGH
Suricata < 7.0.7 - Denial of Service via Predictable Hash Table Behavior
CVSS 7.5
CVE-2024-47187 HIGH
Suricata < 7.0.7 - Predictable Hash Table Behavior via Uninitialized Random Seed
CVSS 7.5
CVE-2024-8452 HIGH
PLANET Technology - Info Disclosure
CVSS 7.5
CVE-2024-39583 HIGH
Dell PowerScale InsightIQ 5.0-5.1 - Unauthenticated Elevation of Privileges via Broken Cryptographic Algorithm
CVSS 8.1
CVE-2024-37068 MEDIUM
IBM Maximo Application Suite Manage Component 8.10, 8.11, 9.0 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 5.9
CVE-2024-45394 HIGH
Authenticator <7.0.0 - Info Disclosure
CVSS 8.8
Details
Vulnerabilities 687
Exploit Likelihood High