CWE-326 · 404 kayıt
Inadequate Encryption Strength
Bu sınıftaki CVE’ler
404 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
97Hemen | CVE-2017-1000486Silahlaştırılmış | Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code executionprimetek · primefaces · CWE-326 | Kritik9,8 | KEV | %94,1 | 3 Oca 2018 |
94Hemen | CVE-2017-11317Silahlaştırılmış | Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and R2 before R2 2017 SP2 uses weak RadAsyncUpload encryption, which atelerik · ui for asp.net ajax · CWE-326 | Kritik9,8 | KEV | %84,2 | 23 Ağu 2017 |
83Hemen | CVE-2018-15811Silahlaştırılmış | DNN (aka DotNetNuke) 9.2 through 9.2.1 uses a weak encryption algorithm to protect input parameters.dnnsoftware · dotnetnuke · CWE-326 | Yüksek7,5 | KEV | %76,1 | 3 Tem 2019 |
82Hemen | CVE-2018-18325Silahlaştırılmış | DNN (aka DotNetNuke) 9.2 through 9.2.2 uses a weak encryption algorithm to protect input parameters.dnnsoftware · dotnetnuke · CWE-326 | Yüksek7,5 | KEV | %73,9 | 3 Tem 2019 |
58Planlayın | CVE-2014-0224Silahlaştırılmış | OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, whiopenssl · openssl · CWE-326 | Yüksek7,4 | — | %95,3 | 5 Haz 2014 |
48Planlayın | CVE-2013-2566Silahlaştırılmış | The RC4 algorithm, as used in the TLS protocol and SSL protocol, has many single-byte biases, which makes it easier for remote attackers to oracle · communications application session controller · CWE-326 | Orta5,9 | — | %84,4 | 15 Mar 2013 |
41Planlayın | CVE-2020-6966İstismar yok | In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X gehealthcare · apexpro telemetry server firmware · CWE-326 | Kritik10,0 | — | %2,2 | 24 Oca 2020 |
40Planlayın | CVE-2011-4121İstismar yok | The OpenSSL extension of Ruby (Git trunk) versions after 2011-09-01 up to 2011-11-03 always generated an exponent value of '1' to be used foruby-lang · ruby · CWE-326 | Kritik9,8 | — | %2,5 | 26 Kas 2019 |
40Planlayın | CVE-2013-2166İstismar yok | python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache encryption bypassopenstack · python-keystoneclient · CWE-326 | Kritik9,8 | — | %2,1 | 10 Ara 2019 |
40Planlayın | CVE-2018-0448İstismar yok | Cisco Digital Network Architecture Center Authentication Bypass Vulnerabilitycisco · digital network architecture center · CWE-326 | Kritik9,8 | — | %2,1 | 5 Eki 2018 |
40Planlayın | CVE-2018-7242İstismar yok | Vulnerable hash algorithms exists in Schneider Electric's Modicon Premium, Modicon Quantum, Modicon M340, and BMXNOR0200 controllers in all schneider-electric · bmxnor0200 firmware · CWE-326 | Kritik9,8 | — | %1,9 | 18 Nis 2018 |
40Planlayın | CVE-2018-20810İstismar yok | Session data between cluster nodes during cluster synchronization is not properly encrypted in Pulse Secure Pulse Connect Secure (PCS) 8.3RXivanti · connect secure · CWE-326 | Kritik9,8 | — | %1,8 | 28 Haz 2019 |
40Planlayın | CVE-2025-12478İstismar yok | Non-Compliant TLS Configurationazure-access · blu-ic2 firmware · CWE-326 | Kritik10,0 | — | %0,2 | 29 Eki 2025 |
40Planlayın | CVE-2026-44523İstismar yok | Note Mark: JWT Secret Weakness allows Full Account Takeover via token forgeryenchant97 · note-mark · CWE-326 | Kritik10,0 | — | %0,2 | 14 May 2026 |
39İzleyin | CVE-2011-3389Silahlaştırılmış | The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opgoogle · chrome · CWE-326 | Orta4,3 | — | %73,3 | 6 Eyl 2011 |
39İzleyin | CVE-2013-7287İstismar yok | MobileIron VSP < 5.9.1 and Sentry < 5.0 has an insecure encryption scheme.mobileiron · sentry · CWE-326 | Kritik9,8 | — | %1,4 | 13 Şub 2020 |
39İzleyin | CVE-2019-15806İstismar yok | CommScope ARRIS TR4400 devices with firmware through A1.00.004-180301 are vulnerable to an authentication bypass to the administrative intercommscope · tr4400 firmware · CWE-326 | Kritik9,8 | — | %1,2 | 29 Ağu 2019 |
39İzleyin | CVE-2019-15805İstismar yok | CommScope ARRIS TR4400 devices with firmware through A1.00.004-180301 are vulnerable to an authentication bypass to the administrative intercommscope · tr4400 firmware · CWE-326 | Kritik9,8 | — | %1,2 | 29 Ağu 2019 |
39İzleyin | CVE-2021-42216İstismar yok | A Broken or Risky Cryptographic Algorithm exists in AnonAddy 0.8.5 via VerificationController.php.anonaddy · anonaddy · CWE-326 | Kritik9,8 | — | %1,2 | 15 Ara 2021 |
39İzleyin | CVE-2016-5804İstismar yok | Moxa MGate MB3180 before 1.8, MGate MB3280 before 2.7, MGate MB3480 before 2.6, MGate MB3170 before 2.5, and MGate MB3270 before 2.7 use weamoxa · mgate mb3180 firmware · CWE-326 | Kritik9,8 | — | %1,1 | 15 Tem 2016 |
39İzleyin | CVE-2017-7888İstismar yok | Dolibarr ERP/CRM 4.0.4 stores passwords with the MD5 algorithm, which makes brute-force attacks easier.dolibarr · dolibarr erp\/crm · CWE-326 | Kritik9,8 | — | %1,1 | 10 May 2017 |
39İzleyin | CVE-2018-15124İstismar yok | Weak hashing algorithm in Zipato Zipabox Smart Home Controller BOARD REV - 1 with System Version -118 allows unauthenticated attacker extraczipato · zipabox firmware · CWE-326 | Kritik9,8 | — | %1,1 | 13 Ağu 2018 |
39İzleyin | CVE-2019-10907İstismar yok | Airsonic 10.2.1 uses Spring's default remember-me mechanism based on MD5, with a fixed key of airsonic in GlobalSecurityConfig.java.airsonic project · airsonic · CWE-326 | Kritik9,8 | — | %0,9 | 7 Nis 2019 |
39İzleyin | CVE-2017-8076İstismar yok | On the TP-Link TL-SG108E 1.0, admin network communications are RC4 encoded, even though RC4 is deprecated.tp-link · tl-sg108e firmware · CWE-326 | Kritik9,8 | — | %0,9 | 23 Nis 2017 |
39İzleyin | CVE-2022-36555İstismar yok | Hytec Inter HWL-2511-SS v1.05 and below implements a SHA512crypt hash for the root account which can be easily cracked via a brute-force atthytec · hwl-2511-ss firmware · CWE-326 | Kritik9,8 | — | %0,7 | 29 Ağu 2022 |
- CVE-2017-100048697Hemen
Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %94primetek · primefaces3 Oca 2018
- CVE-2017-1131794Hemen
Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and R2 before R2 2017 SP2 uses weak RadAsyncUpload encryption, which a
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %84telerik · ui for asp.net ajax23 Ağu 2017
- CVE-2018-1581183Hemen
DNN (aka DotNetNuke) 9.2 through 9.2.1 uses a weak encryption algorithm to protect input parameters.
YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %76dnnsoftware · dotnetnuke3 Tem 2019
- CVE-2018-1832582Hemen
DNN (aka DotNetNuke) 9.2 through 9.2.2 uses a weak encryption algorithm to protect input parameters.
YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %74dnnsoftware · dotnetnuke3 Tem 2019
- CVE-2014-022458Planlayın
OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, whi
YüksekCVSS 7,4SilahlaştırılmışEPSS %95openssl · openssl5 Haz 2014
- CVE-2013-256648Planlayın
The RC4 algorithm, as used in the TLS protocol and SSL protocol, has many single-byte biases, which makes it easier for remote attackers to
OrtaCVSS 5,9SilahlaştırılmışEPSS %84oracle · communications application session controller15 Mar 2013
- CVE-2020-696641Planlayın
In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X
KritikCVSS 10,0İstismar yokEPSS %2gehealthcare · apexpro telemetry server firmware24 Oca 2020
- CVE-2011-412140Planlayın
The OpenSSL extension of Ruby (Git trunk) versions after 2011-09-01 up to 2011-11-03 always generated an exponent value of '1' to be used fo
KritikCVSS 9,8İstismar yokEPSS %3ruby-lang · ruby26 Kas 2019
- CVE-2013-216640Planlayın
python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache encryption bypass
KritikCVSS 9,8İstismar yokEPSS %2openstack · python-keystoneclient10 Ara 2019
- CVE-2018-044840Planlayın
Cisco Digital Network Architecture Center Authentication Bypass Vulnerability
KritikCVSS 9,8İstismar yokEPSS %2cisco · digital network architecture center5 Eki 2018
- CVE-2018-724240Planlayın
Vulnerable hash algorithms exists in Schneider Electric's Modicon Premium, Modicon Quantum, Modicon M340, and BMXNOR0200 controllers in all
KritikCVSS 9,8İstismar yokEPSS %2schneider-electric · bmxnor0200 firmware18 Nis 2018
- CVE-2018-2081040Planlayın
Session data between cluster nodes during cluster synchronization is not properly encrypted in Pulse Secure Pulse Connect Secure (PCS) 8.3RX
KritikCVSS 9,8İstismar yokEPSS %2ivanti · connect secure28 Haz 2019
- CVE-2025-1247840Planlayın
Non-Compliant TLS Configuration
KritikCVSS 10,0İstismar yokEPSS %0azure-access · blu-ic2 firmware29 Eki 2025
- CVE-2026-4452340Planlayın
Note Mark: JWT Secret Weakness allows Full Account Takeover via token forgery
KritikCVSS 10,0İstismar yokEPSS %0enchant97 · note-mark14 May 2026
- CVE-2011-338939İzleyin
The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Op
OrtaCVSS 4,3SilahlaştırılmışEPSS %73google · chrome6 Eyl 2011
- CVE-2013-728739İzleyin
MobileIron VSP < 5.9.1 and Sentry < 5.0 has an insecure encryption scheme.
KritikCVSS 9,8İstismar yokEPSS %1mobileiron · sentry13 Şub 2020
- CVE-2019-1580639İzleyin
CommScope ARRIS TR4400 devices with firmware through A1.00.004-180301 are vulnerable to an authentication bypass to the administrative inter
KritikCVSS 9,8İstismar yokEPSS %1commscope · tr4400 firmware29 Ağu 2019
- CVE-2019-1580539İzleyin
CommScope ARRIS TR4400 devices with firmware through A1.00.004-180301 are vulnerable to an authentication bypass to the administrative inter
KritikCVSS 9,8İstismar yokEPSS %1commscope · tr4400 firmware29 Ağu 2019
- CVE-2021-4221639İzleyin
A Broken or Risky Cryptographic Algorithm exists in AnonAddy 0.8.5 via VerificationController.php.
KritikCVSS 9,8İstismar yokEPSS %1anonaddy · anonaddy15 Ara 2021
- CVE-2016-580439İzleyin
Moxa MGate MB3180 before 1.8, MGate MB3280 before 2.7, MGate MB3480 before 2.6, MGate MB3170 before 2.5, and MGate MB3270 before 2.7 use wea
KritikCVSS 9,8İstismar yokEPSS %1moxa · mgate mb3180 firmware15 Tem 2016
- CVE-2017-788839İzleyin
Dolibarr ERP/CRM 4.0.4 stores passwords with the MD5 algorithm, which makes brute-force attacks easier.
KritikCVSS 9,8İstismar yokEPSS %1dolibarr · dolibarr erp\/crm10 May 2017
- CVE-2018-1512439İzleyin
Weak hashing algorithm in Zipato Zipabox Smart Home Controller BOARD REV - 1 with System Version -118 allows unauthenticated attacker extrac
KritikCVSS 9,8İstismar yokEPSS %1zipato · zipabox firmware13 Ağu 2018
- CVE-2019-1090739İzleyin
Airsonic 10.2.1 uses Spring's default remember-me mechanism based on MD5, with a fixed key of airsonic in GlobalSecurityConfig.java.
KritikCVSS 9,8İstismar yokEPSS %1airsonic project · airsonic7 Nis 2019
- CVE-2017-807639İzleyin
On the TP-Link TL-SG108E 1.0, admin network communications are RC4 encoded, even though RC4 is deprecated.
KritikCVSS 9,8İstismar yokEPSS %1tp-link · tl-sg108e firmware23 Nis 2017
- CVE-2022-3655539İzleyin
Hytec Inter HWL-2511-SS v1.05 and below implements a SHA512crypt hash for the root account which can be easily cracked via a brute-force att
KritikCVSS 9,8İstismar yokEPSS %1hytec · hwl-2511-ss firmware29 Ağu 2022