Aescrypt Project maintains a narrowly scoped encryption utility focused on AES-based file encryption, representing a modest security footprint within the broader cryptographic software landscape. The observed vulnerability pattern centers on cryptographic-random-number generation, a foundational concern for any encryption tool where weaknesses in randomness undermine the integrity of derived keys and initialization vectors. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Aescrypt Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-7463HIGH The aescrypt gem 1.0.0 for Ruby does not randomize the CBC IV for use with the AESCrypt.encrypt and AESCrypt.decrypt functions, which allows attackers to defeat cryptographic prote | Apr 19, 2017 | 7.5 | 25 | NO | NO |
CVE-2022-35928MEDIUM AES Crypt is a file encryption software for multiple platforms. AES Crypt for Linux built using the source on GitHub and having the version number 3.11 has a vulnerability with res | Aug 3, 2022 | 5.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Aescrypt Project.
Media articles that mention a CVE ID that affects a product developed by Aescrypt Project — matched by CVE ID, not by vendor name.