Auto-created placeholder
Volume of CVEs assigned to CWE-320 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
92 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-0936CRITICAL Ceragon FibeAir IP-10 have a default SSH public key in the authorized_keys file for the mateidu user, which allows remote attackers to obtain SSH access by leveraging knowledge of | Jun 1, 2017 | 9.8 | 87 | NO | YES |
CVE-2018-0732HIGH During key agreement in a TLS handshake using a DH(E) based ciphersuite a malicious server can send a very large prime value to the client. This will cause the client to spend an u | Jun 12, 2018 | 7.5 | 51 | NO | NO |
CVE-2018-0124CRITICAL A vulnerability in Cisco Unified Communications Domain Manager could allow an unauthenticated, remote attacker to bypass security protections, gain elevated privileges, and execute | Feb 22, 2018 | 9.8 | 32 | NO | NO |
CVE-2026-56254HIGH In @capgo/capacitor-updater (Cap-go/capgo) before 12.128.2, the end-to-end encryption scheme distributes the private key to each device that downloads the app. Because the public k | Jul 10, 2026 | 7.0 | 31 | NO | NO |
CVE-2015-8542HIGH An issue was discovered in Open-Xchange Guard before 2.2.0-rev8. The "getprivkeybyid" API call is used to download a PGP Private Key for a specific user after providing authenticat | Dec 15, 2016 | 8.8 | 29 | NO | NO |
CVE-2019-5672CRITICAL NVIDIA Jetson TX1 and TX2 contain a vulnerability in the Linux for Tegra (L4T) operating system (on all versions prior to R28.3) where the Secure Shell (SSH) keys provided in the s | Apr 11, 2019 | 9.1 | 28 | NO | NO |
CVE-2025-15107HIGH A security vulnerability has been detected in actiontech sqle up to 4.2511.0. The impacted element is an unknown function of the file sqle/utils/jwt.go of the component JWT Secret | Dec 27, 2025 | 8.1 | 27 | NO | NO |
CVE-2026-6580HIGH A security vulnerability has been detected in liangliangyy DjangoBlog up to 2.1.0.0. Affected is an unknown function of the file owntracks/views.py of the component Amap API Call H | Apr 19, 2026 | 7.3 | 26 | NO | NO |
CVE-2025-11290HIGH A vulnerability was identified in CRMEB up to 5.6.1. This affects an unknown function of the component JWT HMAC Secret Handler. Such manipulation of the argument secret with the in | Oct 5, 2025 | 8.1 | 26 | NO | NO |
CVE-2016-2880HIGH IBM QRadar 7.2 stores the encryption key used to encrypt the service account password which can be obtained by a local user. IBM Reference #: 1997340. | Mar 1, 2017 | 7.8 | 26 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.