To fulfill the need for a cryptographic primitive, the product implements a cryptographic algorithm using a non-standard, unproven, or disallowed/non-compliant cryptographic implementation.
Volume of CVEs assigned to CWE-1240 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
20 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-29146HIGH Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.0.0-M1 thr | Apr 9, 2026 | 7.5 | 35 | NO | NO |
CVE-2026-46654HIGH Plonky3 is a toolkit for polynomial IOPs (PIOPs). Prior to versions 0.4.3 and 0.5.3, an attacker controlling prover-side observations can craft distinct transcripts that produce id | Jun 10, 2026 | 8.9 | 33 | NO | NO |
CVE-2023-51392CRITICAL Ember ZNet between v7.2.0 and v7.4.0 used software AES-CCM instead of integrated hardware cryptographic accelerators, potentially increasing risk of electromagnetic and differentia | Feb 23, 2024 | 9.8 | 29 | NO | NO |
CVE-2026-50303MEDIUM Use of a cryptographic primitive with a risky implementation in Windows Key Guard allows an authorized attacker to bypass a security feature locally. | Jul 14, 2026 | 5.5 | 27 | NO | NO |
CVE-2025-64647HIGH IBM Concert 1.0.0 through 2.2.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information | Mar 25, 2026 | 7.5 | 24 | NO | NO |
CVE-2025-62514HIGH Parsec is a cloud-based application for cryptographically secure file sharing. In versions on the 3.x branch prior to 3.6.0, `libparsec_crypto`, a component of the Parsec applicati | Jan 29, 2026 | 7.1 | 24 | NO | NO |
CVE-2025-58720HIGH Use of a cryptographic primitive with a risky implementation in Windows Cryptographic Services allows an authorized attacker to disclose information locally. | Oct 14, 2025 | 7.8 | 24 | NO | NO |
CVE-2025-24802HIGH Plonky2 is a SNARK implementation based on techniques from PLONK and FRI. Lookup tables, whose length is not divisible by 26 = floor(num_routed_wires / 3) always include the 0 -> 0 | Jan 30, 2025 | 8.6 | 24 | NO | NO |
CVE-2024-0323CRITICAL The FTP server used on the B&R
Automation Runtime supports unsecure encryption mechanisms, such as SSLv3,
TLSv1.0 and TLS1.1. An network-based attacker can exploit the flaws to con | Feb 5, 2024 | 9.8 | 24 | NO | NO |
CVE-2026-22705MEDIUM RustCrypto: Signatures offers support for digital signatures, which provide authentication of data using public-key cryptography. Prior to version 0.1.0-rc.2, a timing side-channel | Jan 10, 2026 | 6.4 | 23 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.