CWE-325 · 51 kayıt
Missing Cryptographic Step
Bu sınıftaki CVE’ler
51 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2025-3938İstismar yok | Missing Cryptographic Steptridium · niagara · CWE-325 | Kritik9,8 | — | %0,3 | 22 May 2025 |
36İzleyin | CVE-2026-22863İstismar yok | Deno node:crypto doesn't finalize cipherdeno · deno · CWE-325 | Kritik9,2 | — | %0,2 | 15 Oca 2026 |
36İzleyin | CVE-2026-17666İstismar yok | Cryptographic Flaw in Enterprise in Google Chrome prior to 151.0.7922.72 allowed an attacker in a privileged network position to bypass discgoogle · chrome · CWE-325 | Kritik9,1 | — | %0,2 | 29 Tem 2026 |
35İzleyin | CVE-2026-4601İstismar yok | Versions of the package jsrsasign before 11.1.1 are vulnerable to Missing Cryptographic Step via the KJUR.crypto.DSA.signWithMessageHash prokjur · jsrsasign · CWE-325 | Yüksek8,8 | — | %0,5 | 23 Mar 2026 |
34İzleyin | CVE-2025-30147İstismar yok | ALTBN128_ADD, ALTBN128_MUL, ALTBN128_PAIRING precompile functions do not check if points are on curvehyperledger · besu-native · CWE-325 | Yüksek8,7 | — | %0,3 | 7 May 2025 |
34İzleyin | CVE-2026-76784İstismar yok | Insufficient Cryptographic Protections in Local Device Communication Protocol on Multiple TP-Link Kasa Smart Home Devicestp-link systems inc. · hs103p3 / hs103p4 v5 · CWE-325 | Yüksek8,7 | — | %0,2 | 26 Ağu 2026 |
32İzleyin | CVE-2023-34471İstismar yok | Missing Cryptographic Stepami · megarac sp-x · CWE-325 | Yüksek8,1 | — | %0,3 | 5 Tem 2023 |
32İzleyin | CVE-2026-41395İstismar yok | OpenClaw < 2026.3.28 - Webhook Replay via Query Parameter Reordering in Plivo V3openclaw · openclaw · CWE-325 | Yüksek8,2 | — | %0,3 | 28 Nis 2026 |
31İzleyin | CVE-2021-22946İstismar yok | A user can tell curl >= 7.20.0 and <= 7.78.0 to require a successful upgrade to TLS when speaking to an IMAP, POP3 or FTP server (`--ssl-reqhaxx · curl · CWE-325 | Yüksek7,5 | — | %4,5 | 29 Eyl 2021 |
30İzleyin | CVE-2026-45445İstismar yok | AES-OCB IV Ignored on EVP_Cipher() Pathopenssl · openssl · CWE-325 | Yüksek7,5 | — | %0,7 | 9 Haz 2026 |
30İzleyin | CVE-2025-60704İstismar yok | Windows Kerberos Elevation of Privilege Vulnerabilitymicrosoft · windows 10 1607 · CWE-325 | Yüksek7,5 | — | %0,5 | 11 Kas 2025 |
30İzleyin | CVE-2022-1279İstismar yok | Insecure EBICS messages encryption implementation in ebics-java/ebics-java-client could allow an adjacent attacker to decrypt EBICS payloadsebics java project · ebics java · CWE-325 | Yüksek7,5 | — | %0,4 | 14 Nis 2022 |
30İzleyin | CVE-2023-40012İstismar yok | uthenticode EKU validation bypasstrailofbits · uthenticode · CWE-325 | Yüksek7,5 | — | %0,2 | 9 Ağu 2023 |
29İzleyin | CVE-2022-20742İstismar yok | Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software IPsec IKEv2 VPN Information Disclosure Vulnerabilitycisco · secure firewall threat defense · CWE-325 | Yüksek7,4 | — | %0,5 | 3 May 2022 |
29İzleyin | CVE-2026-49440İstismar yok | Deno: Miller-Rabin Primality Test Allows Zero Roundsdeno · deno · CWE-325 | Yüksek7,4 | — | %0,2 | 23 Haz 2026 |
28İzleyin | CVE-2022-29229İstismar yok | Missing Cryptographic Step in cassprojectcassproject · competency and skills system · CWE-325 | Yüksek7,2 | — | %0,3 | 18 May 2022 |
28İzleyin | CVE-2026-55144İstismar yok | Windows Cryptography API: Next Generation (CNG) Tampering Vulnerabilitymicrosoft · windows 11 24h2 · CWE-325 | Yüksek7,1 | — | %0,2 | 14 Tem 2026 |
28İzleyin | CVE-2026-59776İstismar yok | Missing Cryptographic Step (CWE-325) vulnerability exists in certain FeliCa IC chips shipped in or before 2017.sony corporation · felica ic chips · CWE-325 | Yüksek7,0 | — | %0,2 | 21 Tem 2026 |
28İzleyin | CVE-2025-47383İstismar yok | Missing Cryptographic Step in Data Modemqualcomm · 5g fixed wireless access platform firmware · CWE-325 | Yüksek7,2 | — | %0,1 | 2 Mar 2026 |
28İzleyin | CVE-2026-9266İstismar yok | A Missing Required Cryptographic Step vulnerability has been identified in Moxa's embedded Linux firmware for industrial computers and contrmoxa · uc-1200a series · CWE-325 | Yüksek7,0 | — | %0,1 | 12 Haz 2026 |
27İzleyin | CVE-2019-3738İstismar yok | RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to a Missing Required Cryptographic Step vulnerability.dell · bsafe cert-j · CWE-325 | Orta6,5 | — | %1,7 | 18 Eyl 2019 |
27İzleyin | CVE-2020-26244İstismar yok | Cryptographic issues in Python oicpython openid connect project · python openid connect · CWE-325 | Orta6,8 | — | %0,8 | 2 Ara 2020 |
27İzleyin | CVE-2018-5383İstismar yok | Bluetooth implementations may not sufficiently validate elliptic curve parameters during Diffie-Hellman key exchangeti · wl18xx bluetooth service pack · CWE-325 | Orta6,8 | — | %0,8 | 7 Ağu 2018 |
27İzleyin | CVE-2022-20793İstismar yok | Cisco Touch 10 Device Insufficient Identity Verification Vulnerabilitycisco · telepresence collaboration endpoint · CWE-325 | Orta6,8 | — | %0,4 | 15 Kas 2024 |
26İzleyin | CVE-2023-39199İstismar yok | Cryptographic issues with In-Meeting Chat for some Zoom clients may allow a privileged user to conduct an information disclosure via networkzoom · meetings · CWE-325 | Orta6,5 | — | %0,6 | 14 Kas 2023 |
- CVE-2025-393839İzleyin
Missing Cryptographic Step
KritikCVSS 9,8İstismar yokEPSS %0tridium · niagara22 May 2025
- CVE-2026-2286336İzleyin
Deno node:crypto doesn't finalize cipher
KritikCVSS 9,2İstismar yokEPSS %0deno · deno15 Oca 2026
- CVE-2026-1766636İzleyin
Cryptographic Flaw in Enterprise in Google Chrome prior to 151.0.7922.72 allowed an attacker in a privileged network position to bypass disc
KritikCVSS 9,1İstismar yokEPSS %0google · chrome29 Tem 2026
- CVE-2026-460135İzleyin
Versions of the package jsrsasign before 11.1.1 are vulnerable to Missing Cryptographic Step via the KJUR.crypto.DSA.signWithMessageHash pro
YüksekCVSS 8,8İstismar yokEPSS %0kjur · jsrsasign23 Mar 2026
- CVE-2025-3014734İzleyin
ALTBN128_ADD, ALTBN128_MUL, ALTBN128_PAIRING precompile functions do not check if points are on curve
YüksekCVSS 8,7İstismar yokEPSS %0hyperledger · besu-native7 May 2025
- CVE-2026-7678434İzleyin
Insufficient Cryptographic Protections in Local Device Communication Protocol on Multiple TP-Link Kasa Smart Home Devices
YüksekCVSS 8,7İstismar yokEPSS %0tp-link systems inc. · hs103p3 / hs103p4 v526 Ağu 2026
- CVE-2023-3447132İzleyin
Missing Cryptographic Step
YüksekCVSS 8,1İstismar yokEPSS %0ami · megarac sp-x5 Tem 2023
- CVE-2026-4139532İzleyin
OpenClaw < 2026.3.28 - Webhook Replay via Query Parameter Reordering in Plivo V3
YüksekCVSS 8,2İstismar yokEPSS %0openclaw · openclaw28 Nis 2026
- CVE-2021-2294631İzleyin
A user can tell curl >= 7.20.0 and <= 7.78.0 to require a successful upgrade to TLS when speaking to an IMAP, POP3 or FTP server (`--ssl-req
YüksekCVSS 7,5İstismar yokEPSS %5haxx · curl29 Eyl 2021
- CVE-2026-4544530İzleyin
AES-OCB IV Ignored on EVP_Cipher() Path
YüksekCVSS 7,5İstismar yokEPSS %1openssl · openssl9 Haz 2026
- CVE-2025-6070430İzleyin
Windows Kerberos Elevation of Privilege Vulnerability
YüksekCVSS 7,5İstismar yokEPSS %1microsoft · windows 10 160711 Kas 2025
- CVE-2022-127930İzleyin
Insecure EBICS messages encryption implementation in ebics-java/ebics-java-client could allow an adjacent attacker to decrypt EBICS payloads
YüksekCVSS 7,5İstismar yokEPSS %0ebics java project · ebics java14 Nis 2022
- CVE-2023-4001230İzleyin
uthenticode EKU validation bypass
YüksekCVSS 7,5İstismar yokEPSS %0trailofbits · uthenticode9 Ağu 2023
- CVE-2022-2074229İzleyin
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software IPsec IKEv2 VPN Information Disclosure Vulnerability
YüksekCVSS 7,4İstismar yokEPSS %0cisco · secure firewall threat defense3 May 2022
- CVE-2026-4944029İzleyin
Deno: Miller-Rabin Primality Test Allows Zero Rounds
YüksekCVSS 7,4İstismar yokEPSS %0deno · deno23 Haz 2026
- CVE-2022-2922928İzleyin
Missing Cryptographic Step in cassproject
YüksekCVSS 7,2İstismar yokEPSS %0cassproject · competency and skills system18 May 2022
- CVE-2026-5514428İzleyin
Windows Cryptography API: Next Generation (CNG) Tampering Vulnerability
YüksekCVSS 7,1İstismar yokEPSS %0microsoft · windows 11 24h214 Tem 2026
- CVE-2026-5977628İzleyin
Missing Cryptographic Step (CWE-325) vulnerability exists in certain FeliCa IC chips shipped in or before 2017.
YüksekCVSS 7,0İstismar yokEPSS %0sony corporation · felica ic chips21 Tem 2026
- CVE-2025-4738328İzleyin
Missing Cryptographic Step in Data Modem
YüksekCVSS 7,2İstismar yokEPSS %0qualcomm · 5g fixed wireless access platform firmware2 Mar 2026
- CVE-2026-926628İzleyin
A Missing Required Cryptographic Step vulnerability has been identified in Moxa's embedded Linux firmware for industrial computers and contr
YüksekCVSS 7,0İstismar yokEPSS %0moxa · uc-1200a series12 Haz 2026
- CVE-2019-373827İzleyin
RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to a Missing Required Cryptographic Step vulnerability.
OrtaCVSS 6,5İstismar yokEPSS %2dell · bsafe cert-j18 Eyl 2019
- CVE-2020-2624427İzleyin
Cryptographic issues in Python oic
OrtaCVSS 6,8İstismar yokEPSS %1python openid connect project · python openid connect2 Ara 2020
- CVE-2018-538327İzleyin
Bluetooth implementations may not sufficiently validate elliptic curve parameters during Diffie-Hellman key exchange
OrtaCVSS 6,8İstismar yokEPSS %1ti · wl18xx bluetooth service pack7 Ağu 2018
- CVE-2022-2079327İzleyin
Cisco Touch 10 Device Insufficient Identity Verification Vulnerability
OrtaCVSS 6,8İstismar yokEPSS %0cisco · telepresence collaboration endpoint15 Kas 2024
- CVE-2023-3919926İzleyin
Cryptographic issues with In-Meeting Chat for some Zoom clients may allow a privileged user to conduct an information disclosure via network
OrtaCVSS 6,5İstismar yokEPSS %1zoom · meetings14 Kas 2023