CWE-310
251 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-310page 5 of 6
- CVE-2019-9861HIGHCVSS 8.1EG 8.12019-05-14
Due to the use of an insecure RFID technology (MIFARE Classic), ABUS proximity chip keys (RFID tokens) of the ABUS Secvest FUAA50000 wireless alarm system can easily be cloned and used to deactivate the alarm system in an unauthorized way.
- CVE-2020-3389MEDIUMCVSS 4.4EG 4.42020-08-26
A vulnerability in the installation component of Cisco Hyperflex HX-Series Software could allow an authenticated, local attacker to retrieve the password that was configured at installation on an affected device. The vulnerability exists b…
- CVE-2020-8150MEDIUMCVSS 4.1EG 4.12020-11-09
A cryptographic issue in Nextcloud Server 19.0.1 allowed an attacker to downgrade the encryption scheme and break the integrity of encrypted files.
- CVE-2020-8173LOWCVSS 2.2EG 2.22020-11-02
A too small set of random characters being used for encryption in Nextcloud Server 18.0.4 allowed decryption in shorter time than intended.
- CVE-2020-8897MEDIUMCVSS 4.8EG 4.82020-11-16
A weak robustness vulnerability exists in the AWS Encryption SDKs for Java, Python, C and Javalcript prior to versions 2.0.0. Due to the non-committing property of AES-GCM (and other AEAD ciphers such as AES-GCM-SIV or (X)ChaCha20Poly1305)…
- CVE-2021-22947MEDIUMCVSS 5.9EG 5.92021-09-29
When curl >= 7.20.0 and <= 7.78.0 connects to an IMAP or POP3 server to retrieve data using STARTTLS to upgrade to TLS security, the server can respond and send back multiple responses at once that curl caches. curl would then upgrade to T…
- CVE-2021-41992HIGHCVSS 7.7EG 9.82022-04-30
A misconfiguration of RSA in PingID Windows Login prior to 2.7 is vulnerable to pre-computed dictionary attacks, leading to an offline MFA bypass.
- CVE-2021-41993MEDIUMCVSS 6.6EG 4.82022-04-30
A misconfiguration of RSA in PingID Android app prior to 1.19 is vulnerable to pre-computed dictionary attacks, leading to an offline MFA bypass when using PingID Windows Login.
- CVE-2021-41994MEDIUMCVSS 6.6EG 4.82022-04-30
A misconfiguration of RSA in PingID iOS app prior to 1.19 is vulnerable to pre-computed dictionary attacks, leading to an offline MFA bypass when using PingID Windows Login.
- CVE-2021-41995HIGHCVSS 7.7EG 7.52022-06-30
A misconfiguration of RSA in PingID Mac Login prior to 1.1 is vulnerable to pre-computed dictionary attacks, leading to an offline MFA bypass.
- CVE-2021-42001HIGHCVSS 8.0EG 9.82022-04-30
PingID Desktop prior to 1.7.3 has a misconfiguration in the encryption libraries which can lead to sensitive data exposure. An attacker capable of exploiting this vulnerability may be able to successfully complete an MFA challenge via OTP.
- CVE-2021-4258LOWCVSS 3.7EG 7.52022-12-19
A vulnerability was found in whohas. It has been rated as problematic. This issue affects some unknown processing of the component Package Information Handler. The manipulation leads to cleartext transmission of sensitive information. The …
- CVE-2022-22076HIGHCVSS 7.1EG 7.12023-06-06
information disclosure due to cryptographic issue in Core during RPMB read request.
- CVE-2022-23719HIGHCVSS 7.2EG 6.42022-06-30
PingID Windows Login prior to 2.8 does not authenticate communication with a local Java service used to capture security key requests. An attacker with the ability to execute code on the target machine maybe able to exploit and spoof the l…
- CVE-2022-23724MEDIUMCVSS 6.4EG 8.12022-05-04
Use of static encryption key material allows forging an authentication token to other users within a tenant organization. MFA may be bypassed by redirecting an authentication flow to a target user. To exploit the vulnerability, must have c…
- CVE-2022-32222MEDIUMCVSS 5.3EG 5.32022-07-14
A cryptographic vulnerability exists on Node.js on linux in versions of 18.x prior to 18.40.0 which allowed a default path for openssl.cnf that might be accessible under some circumstances to a non-admin user instead of /etc/ssl as was the…
- CVE-2022-40675MEDIUMCVSS 6.5EG 7.42023-02-16
Some cryptographic issues in Fortinet FortiNAC versions 9.4.0 through 9.4.1, 9.2.0 through 9.2.7, 9.1.0 through 9.1.8, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 8.6.0 through 8.6.5, 8.5.0 through 8.5.4, 8.3.7 may allow an attacker to decr…
- CVE-2022-45453HIGHCVSS 7.5EG 5.32023-05-18
TLS/SSL weak cipher suites enabled. The following products are affected: Acronis Cyber Protect 15 (Windows, Linux) before build 30984.
- CVE-2022-4610LOWCVSS 1.9EG 5.52022-12-19
A vulnerability, which was classified as problematic, has been found in Click Studios Passwordstate and Passwordstate Browser Extension Chrome. Affected by this issue is some unknown functionality. The manipulation leads to risky cryptogra…
- CVE-2023-23919HIGHCVSS 7.5EG 7.52023-02-23
A cryptographic vulnerability exists in Node.js <19.2.0, <18.14.1, <16.19.1, <14.21.3 that in some cases did does not clear the OpenSSL error stack after operations that may set it. This may lead to false positive errors during subsequent …
- CVE-2023-33037HIGHCVSS 7.1EG 7.12024-01-02
Cryptographic issue in Automotive while unwrapping the key secs2d and verifying with RPMB data.
- CVE-2023-44303HIGHCVSS 7.5EG 7.52023-11-24
RVTools, Version 3.9.2 and above, contain a sensitive data exposure vulnerability in the password encryption utility (RVToolsPasswordEncryption.exe) and main application (RVTools.exe). A remote unauthenticated attacker with access to stor…
- CVE-2024-20690MEDIUMCVSS 6.5EG 6.52024-01-09
Windows Nearby Sharing Spoofing Vulnerability
- CVE-2024-26228HIGHCVSS 7.8EG 7.82024-04-09
Windows Cryptographic Services Security Feature Bypass Vulnerability
- CVE-2024-38408HIGHCVSS 8.2EG 8.22024-11-04
Cryptographic issue when a controller receives an LMP start encryption command under unexpected conditions.
- CVE-2025-0784LOWCVSS 3.7EG 3.72025-01-28
A vulnerability has been found in Intelbras InControl up to 2.21.58 and classified as problematic. This vulnerability affects unknown code of the file /v1/usuario/ of the component Registered User Handler. The manipulation leads to clearte…
- CVE-2025-10671LOWCVSS 3.7EG 3.72025-09-18
A vulnerability has been found in youth-is-as-pale-as-poetry e-learning 1.0. Impacted is the function encryptSecret of the file e-learning-master\exam-api\src\main\java\com\yf\exam\ability\shiro\jwt\JwtUtils.java of the component JWT Token…
- CVE-2025-10776LOWCVSS 3.7EG 3.72025-09-22
A vulnerability was detected in LionCoders SalePro POS up to 5.5.0. This issue affects some unknown processing of the component Login. Performing manipulation results in cleartext transmission of sensitive information. The attack can be in…
- CVE-2025-11640LOWCVSS 3.1EG 3.12025-10-12
A vulnerability was found in Tomofun Furbo 360 and Furbo Mini. This affects an unknown function of the component Bluetooth Low Energy. The manipulation results in cleartext transmission of sensitive information. Access to the local network…
- CVE-2025-1953LOWCVSS 2.6EG 2.62025-03-04
A vulnerability has been found in vLLM AIBrix 0.2.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file pkg/plugins/gateway/prefixcacheindexer/hash.go of the component Prefix Caching. The m…
- CVE-2025-21422HIGHCVSS 7.1EG 7.12025-07-08
Cryptographic issue while processing crypto API calls, missing checks may lead to corrupted key usage or IV reuses.
- CVE-2025-21482HIGHCVSS 7.1EG 7.12025-09-24
Cryptographic issue while performing RSA PKCS padding decoding.
- CVE-2025-2922LOWCVSS 2.0EG 2.02025-03-28
A vulnerability classified as problematic was found in Netis WF-2404 1.1.124EN. Affected by this vulnerability is an unknown functionality of the component BusyBox Shell. The manipulation leads to cleartext storage of sensitive information…
- CVE-2025-3329LOWCVSS 3.1EG 3.12025-04-07
A vulnerability classified as problematic has been found in Consumer Comanda Mobile up to 14.9.3.2/15.0.0.8. This affects an unknown part of the component Restaurant Order Handler. The manipulation of the argument Login/Password leads to c…
- CVE-2025-48823MEDIUMCVSS 5.9EG 5.92025-07-08
Cryptographic issues in Windows Cryptographic Services allows an unauthorized attacker to disclose information over a network.
- CVE-2025-4894LOWCVSS 3.7EG 3.72025-05-18
A vulnerability classified as problematic was found in calmkart Django-sso-server up to 057247929a94ffc358788a37ab99e391379a4d15. This vulnerability affects the function gen_rsa_keys of the file common/crypto.py. The manipulation leads to …
- CVE-2025-5136LOWCVSS 3.7EG 3.72025-05-25
A vulnerability, which was classified as problematic, was found in Tmall Demo up to 20250505. This affects an unknown part of the file /tmall/order/pay/ of the component Payment Identifier Handler. The manipulation leads to insufficiently …
- CVE-2025-7214LOWCVSS 1.6EG 1.62025-07-09
A vulnerability classified as problematic was found in FNKvision FNK-GU2 up to 40.1.7. Affected by this vulnerability is an unknown functionality of the file /etc/shadow of the component MD5. The manipulation leads to risky cryptographic a…
- CVE-2025-7215LOWCVSS 1.6EG 1.62025-07-09
A vulnerability, which was classified as problematic, has been found in FNKvision FNK-GU2 up to 40.1.7. Affected by this issue is some unknown functionality of the file /rom/wpa_supplicant.conf. The manipulation leads to cleartext storage …
- CVE-2025-8205LOWCVSS 3.7EG 3.72025-07-26
A vulnerability, which was classified as problematic, has been found in Comodo Dragon up to 134.0.6998.179. Affected by this issue is some unknown functionality of the component IP DNS Leakage Detector. The manipulation leads to cleartext …
- CVE-2025-8741LOWCVSS 3.7EG 3.72025-08-08
A vulnerability was found in macrozheng mall up to 1.0.3. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/login. The manipulation leads to cleartext transmission of sensiti…
- CVE-2025-8763LOWCVSS 3.7EG 3.72025-08-09
A vulnerability was found in Ruijie EG306MG 3.0(1)B11P309. It has been rated as problematic. This issue affects some unknown processing of the file /etc/strongswan.conf of the component strongSwan. The manipulation of the argument i_dont_c…
- CVE-2025-9146MEDIUMCVSS 6.6EG 6.62025-08-19
A flaw has been found in Linksys E5600 1.1.0.26. The affected element is the function verify_gemtek_header of the file checkFw.sh of the component Firmware Handler. Executing manipulation can lead to risky cryptographic algorithm. The atta…
- CVE-2025-9239LOWCVSS 3.7EG 3.72025-08-20
A vulnerability was identified in elunez eladmin up to 2.7. Affected by this vulnerability is the function EncryptUtils of the file eladmin-common/src/main/java/me/zhengjie/utils/EncryptUtils.java of the component DES Key Handler. The mani…
- CVE-2025-9513LOWCVSS 3.7EG 3.72025-08-27
A flaw has been found in editso fuso up to 1.0.4-beta.7. This affects the function PenetrateRsaAndAesHandshake of the file src/net/penetrate/handshake/mod.rs. This manipulation of the argument priv_key causes inadequate encryption strength…
- CVE-2025-9828LOWCVSS 3.7EG 5.92025-09-02
A vulnerability was determined in Tenda CP6 11.10.00.243. The affected element is the function sub_2B7D04 of the component uhttp. Executing manipulation can lead to risky cryptographic algorithm. The attack may be launched remotely. This a…
- CVE-2026-2618LOWCVSS 3.7EG 3.72026-02-17
A vulnerability was determined in Beetel 777VR1 up to 01.00.09. This impacts an unknown function of the component SSH Service. This manipulation causes risky cryptographic algorithm. The attack is possible to be carried out remotely. The a…
- CVE-2026-49000HIGHCVSS 7.0EG 5.32026-05-27
An insecure password scheme refers to vulnerabilities arising from improper selection of encryption algorithms, inadequate key management, or flawed code implementation, which may lead to data leakage or tampering, such as hard-coded keys …
- CVE-2026-5682LOWCVSS 3.7EG 3.72026-04-06
A vulnerability has been found in Meesho Online Shopping App up to 27.3 on Android. Affected is an unknown function of the file /api/endpoint of the component com.meesho.supply. Such manipulation leads to risky cryptographic algorithm. The…
- CVE-2026-7610LOWCVSS 3.7EG 3.72026-05-02
A vulnerability has been found in TRENDnet TEW-821DAP 1.12B01. This affects an unknown function of the file /www/cgi/ssi of the component Firmware Update. Such manipulation leads to cleartext transmission of sensitive information. The atta…
Map vulnerabilities like CWE-310 to your infrastructure
EchelonGraph correlates every CVE — across CWE-310 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →