The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.
Volume of CVEs assigned to CWE-326 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
455 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-1000486CRITICAL Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution | Jan 3, 2018 | 9.8 | 99 | YES | YES |
CVE-2018-18325HIGH DNN (aka DotNetNuke) 9.2 through 9.2.2 uses a weak encryption algorithm to protect input parameters. NOTE: this issue exists because of an incomplete fix for CVE-2018-15811. | Jul 3, 2019 | 7.5 | 97 | YES | YES |
CVE-2018-15811HIGH DNN (aka DotNetNuke) 9.2 through 9.2.1 uses a weak encryption algorithm to protect input parameters. | Jul 3, 2019 | 7.5 | 97 | YES | YES |
CVE-2017-11317CRITICAL Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and R2 before R2 2017 SP2 uses weak RadAsyncUpload encryption, which allows remote attackers to perform arbitr | Aug 23, 2017 | 9.8 | 97 | YES | YES |
CVE-2014-0224HIGH OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to | Jun 5, 2014 | 7.4 | 83 | NO | YES |
CVE-2013-2566MEDIUM The RC4 algorithm, as used in the TLS protocol and SSL protocol, has many single-byte biases, which makes it easier for remote attackers to conduct plaintext-recovery attacks via s | Mar 15, 2013 | 5.9 | 80 | NO | YES |
CVE-2011-3389MEDIUM The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and other products, encrypts data b | Sep 6, 2011 | 4.3 | 71 | NO | YES |
CVE-2026-45363CRITICAL ruby-jwt is a Ruby implementation of the RFC 7519 OAuth JSON Web Token standard. Prior to 2.10.3 and 3.2.0, JWT.decode(token, '', true, algorithm: 'HS256') accepts an attacker-forg | Jul 14, 2026 | 9.1 | 39 | NO | NO |
CVE-2024-23564CRITICAL HCL Aftermarket EPC is affected by Business Logic Vulnerability using which a non valid user of the application can obtain passwords from the server and redirect them to their own | Jul 17, 2026 | 9.1 | 38 | NO | NO |
CVE-2002-1910HIGH Click2Learn Ingenium Learning Management System 5.1 and 6.1 uses weak encryption for passwords (reversible algorithm), which allows attackers to obtain passwords. | Dec 31, 2002 | 7.5 | 37 | NO | YES |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.