The product does not implement a required step in a cryptographic algorithm, resulting in weaker encryption than advertised by the algorithm.
Volume of CVEs assigned to CWE-325 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
58 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-45445HIGH Issue summary: When an application drives an AES-OCB context through the
public EVP_Cipher() one-shot interface, the application-supplied
initialisation vector (IV) is silently dis | Jun 9, 2026 | 7.5 | 35 | NO | NO |
CVE-2026-59776MEDIUM Missing Cryptographic Step (CWE-325) vulnerability exists in certain FeliCa IC chips shipped in or before 2017. If the vulnerability is exploited, information stored in the IC chip | Jul 21, 2026 | 6.8 | 34 | NO | NO |
CVE-2026-42246HIGH Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.3.10, 0.4.24, 0.5.14, and 0.6.4, a man-in-the-middle attacker can cau | May 9, 2026 | 7.4 | 33 | NO | NO |
CVE-2026-4601CRITICAL Versions of the package jsrsasign before 11.1.1 are vulnerable to Missing Cryptographic Step via the KJUR.crypto.DSA.signWithMessageHash process in the DSA signing implementation. | Mar 23, 2026 | 9.1 | 33 | NO | NO |
CVE-2026-49440HIGH Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.8.1, node:crypto.checkPrime(candidate[, options][, callback]) and crypto.checkPrimeSync(candidate[, options]) | Jun 23, 2026 | 7.4 | 31 | NO | NO |
CVE-2022-24116CRITICAL Certain General Electric Renewable Energy products have inadequate encryption strength. This affects iNET and iNET II before 8.3.0. | Dec 26, 2022 | 9.8 | 31 | NO | NO |
CVE-2026-55144HIGH Missing cryptographic step in Windows CryptoAPI allows an authorized attacker to perform tampering locally. | Jul 14, 2026 | 7.1 | 30 | NO | NO |
CVE-2026-48480MEDIUM The netty incubator codec.bhttp is a java language binary http parser. Prior to version 0.0.22.FInal, the codec-ohttp implementation of draft-ietf-ohai-chunked-ohttp does not verif | Jun 4, 2026 | 6.6 | 29 | NO | NO |
CVE-2026-40542HIGH Missing critical step in authentication in Apache HttpClient 5.6 allows an attacker to cause the client to accept SCRAM-SHA-256 authentication without proper mutual authentication | Apr 22, 2026 | 7.3 | 29 | NO | NO |
CVE-2025-3938CRITICAL Missing Cryptographic Step vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Cryptanalysis. This | May 22, 2025 | 9.8 | 29 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.