A protocol or its implementation supports interaction between multiple actors and allows those actors to negotiate which algorithm should be used as a protection mechanism such as encryption or authentication, but it does not select the strongest algorithm that is available to both parties.
Volume of CVEs assigned to CWE-757 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
30 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-53712HIGH SCRAM (Salted Challenge Response Authentication Mechanism) is part of the family of Simple Authentication and Security Layer (SASL, RFC 4422) authentication mechanisms. Prior to 3. | Jul 17, 2026 | 8.2 | 35 | NO | NO |
CVE-2026-54291MEDIUM pgjdbc is an open source postgresql JDBC Driver. In releases 42.7.4 through 42.7.11, channelBinding=require connections can be silently downgraded from SCRAM-SHA-256-PLUS with chan | Jul 6, 2026 | 5.9 | 31 | NO | NO |
CVE-2024-38883CRITICAL An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform a Drop Encryption Level attack | Aug 2, 2024 | 9.1 | 30 | NO | NO |
CVE-2017-9269CRITICAL In libzypp before August 2018 GPG keys attached to YUM repositories were not correctly pinned, allowing malicious repository mirrors to silently downgrade to unsigned repositories | Mar 1, 2018 | 9.8 | 29 | NO | NO |
CVE-2026-4942MEDIUM IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to send a specifically crafted message and downgrade the Transport Layer Security (TLS) protocol to a version disabled in | Jul 17, 2026 | 5.9 | 28 | NO | NO |
CVE-2026-2673MEDIUM Issue summary: An OpenSSL TLS 1.3 server may fail to negotiate the expected
preferred key exchange group when its key exchange group configuration includes
the default by using the | Mar 13, 2026 | 6.5 | 28 | NO | NO |
CVE-2019-14887CRITICAL A flaw was found when an OpenSSL security provider is used with Wildfly, the 'enabled-protocols' value in the Wildfly configuration isn't honored. An attacker could target the traf | Mar 16, 2020 | 9.1 | 28 | NO | NO |
CVE-2024-4995CRITICAL Wapro ERP Desktop is vulnerable to MS SQL protocol downgrade request from a server side, what could lead to an unencrypted communication vulnerable to data interception and modific | Dec 18, 2024 | 9.8 | 27 | NO | NO |
CVE-2026-48747MEDIUM Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 7.4.13 and 8.0.13, MailomatRequestParser::validateSignature() parsed X-MO | Jul 14, 2026 | 5.3 | 26 | NO | NO |
CVE-2026-6092MEDIUM When HAVE_ENCRYPT_THEN_MAC is configured, the implementation could fall back to MAC-then-Encrypt rather than enforcing Encrypt-then-MAC. | Jun 25, 2026 | 5.3 | 26 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.