Vulnerabilities (CVE)

Filtered by CWE-326
Total 444 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-36823 1 Ninjaframework 1 Ninja 2026-06-17 N/A 7.5 HIGH
The encrypt() function of Ninja Core v7.0.0 was discovered to use a weak cryptographic algorithm, leading to a possible leakage of sensitive information.
CVE-2024-34113 1 Adobe 1 Coldfusion 2026-06-17 N/A 5.5 MEDIUM
ColdFusion versions 2023u7, 2021u13 and earlier are affected by a Weak Cryptography for Passwords vulnerability that could result in a security feature bypass. This vulnerability arises due to the use of insufficiently strong cryptographic algorithms or flawed implementation that compromises the confidentiality of password data. An attacker could exploit this weakness to decrypt or guess passwords, potentially gaining unauthorized access to protected resources. Exploitation of this issue does not require user interaction.
CVE-2024-33662 1 Portainer 1 Portainer 2026-06-17 N/A 7.5 HIGH
Portainer before 2.20.2 improperly uses an encryption algorithm in the AesEncrypt function.
CVE-2024-32758 1 Johnsoncontrols 2 Exacqvision Client, Exacqvision Server 2026-06-17 N/A 7.5 HIGH
Under certain circumstances the communication between exacqVision Client and exacqVision Server will use insufficient key length and exchange
CVE-2024-30119 2026-06-17 N/A 3.7 LOW
HCL DRYiCE Optibot Reset Station is impacted by a missing Strict Transport Security Header.  This could allow an attacker to intercept or manipulate data during redirection.
CVE-2024-29969 1 Broadcom 1 Brocade Sannav 2026-06-17 N/A 7.5 HIGH
When a Brocade SANnav installation is upgraded from Brocade SANnav v2.2.2 to Brocade SANnav 2.3.0, TLS/SSL weak message authentication code ciphers are added by default for port 18082.
CVE-2024-29951 1 Broadcom 1 Brocade Sannav 2026-06-17 N/A 5.7 MEDIUM
Brocade SANnav before v2.3.1 and v2.3.0a uses the SHA-1 hash in internal SSH ports that are not open to remote connection.
CVE-2024-29950 1 Broadcom 1 Brocade Sannav 2026-06-17 N/A 7.5 HIGH
The class FileTransfer implemented in Brocade SANnav before v2.3.1, v2.3.0a, uses the ssh-rsa signature scheme, which has a SHA-1 hash. The vulnerability could allow a remote, unauthenticated attacker to perform a man-in-the-middle attack.
CVE-2024-28974 1 Dell 5 Data Protection Advisor, Dp4400, Dp4400 Firmware and 2 more 2026-06-17 N/A 7.6 HIGH
Dell Data Protection Advisor, version(s) 19.9, contain(s) an Inadequate Encryption Strength vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Denial of service.
CVE-2024-28755 1 Trustedfirmware 1 Mbed Tls 2026-06-17 N/A 6.5 MEDIUM
An issue was discovered in Mbed TLS 3.5.x before 3.6.0. When an SSL context was reset with the mbedtls_ssl_session_reset() API, the maximum TLS version to be negotiated was not restored to the configured one. An attacker was able to prevent an Mbed TLS server from establishing any TLS 1.3 connection, potentially resulting in a Denial of Service or forced version downgrade from TLS 1.3 to TLS 1.2.
CVE-2024-23656 1 Linuxfoundation 1 Dex 2026-06-17 N/A 7.5 HIGH
Dex is an identity service that uses OpenID Connect to drive authentication for other apps. Dex 2.37.0 serves HTTPS with insecure TLS 1.0 and TLS 1.1. `cmd/dex/serve.go` line 425 seemingly sets TLS 1.2 as minimum version, but the whole `tlsConfig` is ignored after `TLS cert reloader` was introduced in v2.37.0. Configured cipher suites are not respected either. This issue is fixed in Dex 2.38.0.
CVE-2024-23580 2026-06-17 N/A 6.5 MEDIUM
HCL DRYiCE Optibot Reset Station is impacted by insecure encryption of One-Time Passwords (OTPs). This could allow an attacker with access to the database to recover some or all encrypted values.
CVE-2024-23579 2026-06-17 N/A 6.5 MEDIUM
HCL DRYiCE Optibot Reset Station is impacted by insecure encryption of security questions. This could allow an attacker with access to the database to recover some or all encrypted values.
CVE-2024-22894 2 Alpha-innotec, Novelan 4 Heat Pumps, Heat Pumps Firmware, Heat Pumps and 1 more 2026-06-17 N/A 6.8 MEDIUM
An issue fixed in AIT-Deutschland Alpha Innotec Heatpumps V2.88.3 or later, V3.89.0 or later, V4.81.3 or later and Novelan Heatpumps V2.88.3 or later, V3.89.0 or later, V4.81.3 or later, allows remote attackers to execute arbitrary code via the password component in the shadow file.
CVE-2024-22892 1 Openslides 1 Openslides 2026-06-17 N/A 7.5 HIGH
OpenSlides 4.0.15 was discovered to be using a weak hashing algorithm to store passwords.
CVE-2024-21881 2026-06-17 N/A N/A
Inadequate Encryption Strength vulnerability allow an authenticated attacker to execute arbitrary OS Commands via encrypted package upload.This issue affects Envoy: 4.x and 5.x
CVE-2024-21787 2026-06-17 N/A 6.4 MEDIUM
Inadequate encryption strength for some BMRA software before version 22.08 may allow an authenticated user to potentially enable escalation of privilege via local access.
CVE-2024-20692 1 Microsoft 14 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 11 more 2026-06-17 N/A 5.7 MEDIUM
Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability
CVE-2024-13454 1 Openvpn 1 Easy-rsa 2026-06-17 N/A 5.3 MEDIUM
Weak encryption algorithm in Easy-RSA version 3.0.5 through 3.1.7 allows a local attacker to more easily bruteforce the private CA key when created using OpenSSL 3
CVE-2024-13026 2026-06-17 N/A N/A
A vulnerability exists in Algo Edge up to 2.1.1 - a previously used (legacy) component of navify® Algorithm Suite. The vulnerability impacts the authentication mechanism of this component and could allow an attacker with adjacent access to the laboratory network and the Algo Edge system to craft valid authentication tokens and access the component. Other components of navify® Algorithm Suite are not affected.