Nonces should be used for the present occasion and only once.
Volume of CVEs assigned to CWE-323 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
42 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-49952CRITICAL Discuz! X5.0 releases 20260320 through 20260501 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to gain unauthorized access to database | Jun 15, 2026 | 9.1 | 45 | NO | YES |
CVE-2026-59099CRITICAL Apereo CAS 7.3.0 before 8.0.0-RC6 contains a cryptographic vulnerability that allows remote unauthenticated attackers to recover plaintext conversation state by exploiting AES-GCM | Jul 2, 2026 | 9.1 | 40 | NO | NO |
CVE-2026-13602HIGH We found a chain of combining multiple weaknesses in the product that could allow an attacker to become any user in the backend and access any data:
*
The payment inte | Jul 1, 2026 | 7.7 | 35 | NO | NO |
CVE-2026-12205CRITICAL Crypt::DSA versions before 1.21 for Perl reused the nonce across signatures, leading to private-key recovery.
Crypt::DSA::sign caches the per-signature nonce material in the Key o | Jun 15, 2026 | 9.1 | 35 | NO | NO |
CVE-2026-55967HIGH AES-GCM encryption/decryption with extremely large cumulative single message sizes (>64 GiB) were not properly rejected by the streaming APIs, allowing counter wrap, keystream reus | Jun 25, 2026 | 7.5 | 33 | NO | NO |
CVE-2025-59870CRITICAL HCL MyXalytics is affected by improper management of a static JWT signing secret in the web application, where the secret lacks rotation , introducing a security risk | Jan 16, 2026 | 9.8 | 33 | NO | NO |
CVE-2025-64767CRITICAL hpke-js is a Hybrid Public Key Encryption (HPKE) module built on top of Web Cryptography API. Prior to version 1.7.5, the public SenderContext Seal() API has a race condition which | Nov 21, 2025 | 9.1 | 32 | NO | NO |
CVE-2017-7902CRITICAL A "Reusing a Nonce, Key Pair in Encryption" issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1100 programmable-logic controllers 1763-L16AWA, Series A and B, Ve | Jun 30, 2017 | 9.8 | 32 | NO | NO |
CVE-2026-21383HIGH Cryptographic Issue when using a static initialization vector for AES-GCM key wrapping, which requires a unique value for each call to ensure security. | Jul 6, 2026 | 7.1 | 29 | NO | NO |
CVE-2026-3559HIGH Philips Hue Bridge HomeKit Accessory Protocol Static Nonce Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on aff | Mar 13, 2026 | 8.1 | 28 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.