CWE-310
364 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-310page 7 of 8
- CVE-2019-1804CRITICALCVSS 9.8EG 9.82019-05-03
A vulnerability in the SSH key management for the Cisco Nexus 9000 Series Application Centric Infrastructure (ACI) Mode Switch Software could allow an unauthenticated, remote attacker to connect to the affected system with the privileges o…
- CVE-2019-1940MEDIUMCVSS 5.9EG 5.92019-07-17
A vulnerability in the Web Services Management Agent (WSMA) feature of Cisco Industrial Network Director (IND) could allow an unauthenticated, remote attacker to gain unauthorized read access to sensitive data using an invalid X.509 certif…
- CVE-2019-3731HIGHCVSS 7.5EG 7.52019-09-30
RSA BSAFE Crypto-C Micro Edition versions prior to 4.1.4 and RSA Micro Edition Suite versions prior to 4.4 are vulnerable to an Information Exposure Through Timing Discrepancy. A malicious remote user could potentially exploit this vulnera…
- CVE-2019-3739MEDIUMCVSS 6.5EG 6.52019-09-18
RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to Information Exposure Through Timing Discrepancy vulnerabilities during ECDSA key generation. A malicious remote attacker could potentially exploit those vulnerabilities to recove…
- CVE-2019-3740MEDIUMCVSS 6.5EG 6.52019-09-18
RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to an Information Exposure Through Timing Discrepancy vulnerabilities during DSA key generation. A malicious remote attacker could potentially exploit those vulnerabilities to recov…
- CVE-2019-6576HIGHCVSS 6.5EG 7.52019-05-14
A vulnerability has been identified in SIMATIC HMI Comfort Panels 4" - 22" (All versions < V15.1 Update 1), SIMATIC HMI Comfort Outdoor Panels 7" & 15" (All versions < V15.1 Update 1), SIMATIC HMI KTP Mobile Panels KTP400F, KTP700, KTP700F…
- CVE-2019-9191MEDIUMCVSS 5.9EG 5.92019-02-26
The ETSI Enterprise Transport Security (ETS, formerly known as eTLS) protocol does not provide per-session forward secrecy.
- CVE-2019-9506HIGHCVSS 8.1EG 8.12019-08-14
The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encryption key length and does not prevent an attacker from influencing the key length negotiation. This allows practical brute-force attacks (aka …
- CVE-2019-9861HIGHCVSS 8.1EG 8.12019-05-14
Due to the use of an insecure RFID technology (MIFARE Classic), ABUS proximity chip keys (RFID tokens) of the ABUS Secvest FUAA50000 wireless alarm system can easily be cloned and used to deactivate the alarm system in an unauthorized way.
- CVE-2020-3389MEDIUMCVSS 4.4EG 4.42020-08-26
A vulnerability in the installation component of Cisco Hyperflex HX-Series Software could allow an authenticated, local attacker to retrieve the password that was configured at installation on an affected device. The vulnerability exists b…
- CVE-2020-8150MEDIUMCVSS 4.1EG 4.12020-11-09
A cryptographic issue in Nextcloud Server 19.0.1 allowed an attacker to downgrade the encryption scheme and break the integrity of encrypted files.
- CVE-2020-8173LOWCVSS 2.2EG 2.22020-11-02
A too small set of random characters being used for encryption in Nextcloud Server 18.0.4 allowed decryption in shorter time than intended.
- CVE-2020-8897MEDIUMCVSS 4.8EG 4.82020-11-16
A weak robustness vulnerability exists in the AWS Encryption SDKs for Java, Python, C and Javalcript prior to versions 2.0.0. Due to the non-committing property of AES-GCM (and other AEAD ciphers such as AES-GCM-SIV or (X)ChaCha20Poly1305)…
- CVE-2021-22947MEDIUMCVSS 5.9EG 5.92021-09-29
When curl >= 7.20.0 and <= 7.78.0 connects to an IMAP or POP3 server to retrieve data using STARTTLS to upgrade to TLS security, the server can respond and send back multiple responses at once that curl caches. curl would then upgrade to T…
- CVE-2021-41992CRITICALCVSS 7.7EG 9.82022-04-30
A misconfiguration of RSA in PingID Windows Login prior to 2.7 is vulnerable to pre-computed dictionary attacks, leading to an offline MFA bypass.
- CVE-2021-41993MEDIUMCVSS 6.6EG 6.62022-04-30
A misconfiguration of RSA in PingID Android app prior to 1.19 is vulnerable to pre-computed dictionary attacks, leading to an offline MFA bypass when using PingID Windows Login.
- CVE-2021-41994MEDIUMCVSS 6.6EG 6.62022-04-30
A misconfiguration of RSA in PingID iOS app prior to 1.19 is vulnerable to pre-computed dictionary attacks, leading to an offline MFA bypass when using PingID Windows Login.
- CVE-2021-41995HIGHCVSS 7.7EG 7.72022-06-30
A misconfiguration of RSA in PingID Mac Login prior to 1.1 is vulnerable to pre-computed dictionary attacks, leading to an offline MFA bypass.
- CVE-2021-42001CRITICALCVSS 8.0EG 9.82022-04-30
PingID Desktop prior to 1.7.3 has a misconfiguration in the encryption libraries which can lead to sensitive data exposure. An attacker capable of exploiting this vulnerability may be able to successfully complete an MFA challenge via OTP.
- CVE-2021-4258HIGHCVSS 3.7EG 7.52022-12-19
A vulnerability was found in whohas. It has been rated as problematic. This issue affects some unknown processing of the component Package Information Handler. The manipulation leads to cleartext transmission of sensitive information. The …
- CVE-2022-22076HIGHCVSS 7.1EG 7.12023-06-06
information disclosure due to cryptographic issue in Core during RPMB read request.
- CVE-2022-23719HIGHCVSS 7.2EG 7.22022-06-30
PingID Windows Login prior to 2.8 does not authenticate communication with a local Java service used to capture security key requests. An attacker with the ability to execute code on the target machine maybe able to exploit and spoof the l…
- CVE-2022-23724HIGHCVSS 6.4EG 8.12022-05-04
Use of static encryption key material allows forging an authentication token to other users within a tenant organization. MFA may be bypassed by redirecting an authentication flow to a target user. To exploit the vulnerability, must have c…
- CVE-2022-32222MEDIUMCVSS 5.3EG 5.32022-07-14
A cryptographic vulnerability exists on Node.js on linux in versions of 18.x prior to 18.40.0 which allowed a default path for openssl.cnf that might be accessible under some circumstances to a non-admin user instead of /etc/ssl as was the…
- CVE-2022-40675HIGHCVSS 6.5EG 7.42023-02-16
Some cryptographic issues in Fortinet FortiNAC versions 9.4.0 through 9.4.1, 9.2.0 through 9.2.7, 9.1.0 through 9.1.8, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 8.6.0 through 8.6.5, 8.5.0 through 8.5.4, 8.3.7 may allow an attacker to decr…
- CVE-2022-45453HIGHCVSS 7.5EG 7.52023-05-18
TLS/SSL weak cipher suites enabled. The following products are affected: Acronis Cyber Protect 15 (Windows, Linux) before build 30984.
- CVE-2022-4610MEDIUMCVSS 1.9EG 5.52022-12-19
A vulnerability, which was classified as problematic, has been found in Click Studios Passwordstate and Passwordstate Browser Extension Chrome. Affected by this issue is some unknown functionality. The manipulation leads to risky cryptogra…
- CVE-2023-23919HIGHCVSS 7.5EG 7.52023-02-23
A cryptographic vulnerability exists in Node.js <19.2.0, <18.14.1, <16.19.1, <14.21.3 that in some cases did does not clear the OpenSSL error stack after operations that may set it. This may lead to false positive errors during subsequent …
- CVE-2023-33037HIGHCVSS 7.1EG 7.12024-01-02
Cryptographic issue in Automotive while unwrapping the key secs2d and verifying with RPMB data.
- CVE-2023-44303HIGHCVSS 7.5EG 7.52023-11-24
RVTools, Version 3.9.2 and above, contain a sensitive data exposure vulnerability in the password encryption utility (RVToolsPasswordEncryption.exe) and main application (RVTools.exe). A remote unauthenticated attacker with access to stor…
- CVE-2024-20690MEDIUMCVSS 6.5EG 6.52024-01-09
Windows Nearby Sharing Spoofing Vulnerability
- CVE-2024-26228HIGHCVSS 7.8EG 7.82024-04-09
Windows Cryptographic Services Security Feature Bypass Vulnerability
- CVE-2024-38408HIGHCVSS 8.2EG 8.22024-11-04
Cryptographic issue when a controller receives an LMP start encryption command under unexpected conditions.
- CVE-2025-0784LOWCVSS 3.7EG 3.72025-01-28
A vulnerability has been found in Intelbras InControl up to 2.21.58 and classified as problematic. This vulnerability affects unknown code of the file /v1/usuario/ of the component Registered User Handler. The manipulation leads to clearte…
- CVE-2025-10671LOWCVSS 3.7EG 3.72025-09-18
A vulnerability has been found in youth-is-as-pale-as-poetry e-learning 1.0. Impacted is the function encryptSecret of the file e-learning-master\exam-api\src\main\java\com\yf\exam\ability\shiro\jwt\JwtUtils.java of the component JWT Token…
- CVE-2025-10776LOWCVSS 3.7EG 3.72025-09-22
A vulnerability was detected in LionCoders SalePro POS up to 5.5.0. This issue affects some unknown processing of the component Login. Performing manipulation results in cleartext transmission of sensitive information. The attack can be in…
- CVE-2025-11640LOWCVSS 3.1EG 3.12025-10-12
A vulnerability was found in Tomofun Furbo 360 and Furbo Mini. This affects an unknown function of the component Bluetooth Low Energy. The manipulation results in cleartext transmission of sensitive information. Access to the local network…
- CVE-2025-1953LOWCVSS 2.6EG 2.62025-03-04
A vulnerability has been found in vLLM AIBrix 0.2.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file pkg/plugins/gateway/prefixcacheindexer/hash.go of the component Prefix Caching. The m…
- CVE-2025-21422HIGHCVSS 7.1EG 7.12025-07-08
Cryptographic issue while processing crypto API calls, missing checks may lead to corrupted key usage or IV reuses.
- CVE-2025-21482HIGHCVSS 7.1EG 7.12025-09-24
Cryptographic issue while performing RSA PKCS padding decoding.
- CVE-2025-2922LOWCVSS 2.0EG 2.02025-03-28
A vulnerability classified as problematic was found in Netis WF-2404 1.1.124EN. Affected by this vulnerability is an unknown functionality of the component BusyBox Shell. The manipulation leads to cleartext storage of sensitive information…
- CVE-2025-3329LOWCVSS 3.1EG 3.12025-04-07
A vulnerability classified as problematic has been found in Consumer Comanda Mobile up to 14.9.3.2/15.0.0.8. This affects an unknown part of the component Restaurant Order Handler. The manipulation of the argument Login/Password leads to c…
- CVE-2025-48823MEDIUMCVSS 5.9EG 5.92025-07-08
Cryptographic issues in Windows Cryptographic Services allows an unauthorized attacker to disclose information over a network.
- CVE-2025-4894LOWCVSS 3.7EG 3.72025-05-18
A vulnerability classified as problematic was found in calmkart Django-sso-server up to 057247929a94ffc358788a37ab99e391379a4d15. This vulnerability affects the function gen_rsa_keys of the file common/crypto.py. The manipulation leads to …
- CVE-2025-5136LOWCVSS 3.7EG 3.72025-05-25
A vulnerability, which was classified as problematic, was found in Tmall Demo up to 20250505. This affects an unknown part of the file /tmall/order/pay/ of the component Payment Identifier Handler. The manipulation leads to insufficiently …
- CVE-2025-7214LOWCVSS 1.6EG 1.62025-07-09
A vulnerability classified as problematic was found in FNKvision FNK-GU2 up to 40.1.7. Affected by this vulnerability is an unknown functionality of the file /etc/shadow of the component MD5. The manipulation leads to risky cryptographic a…
- CVE-2025-7215LOWCVSS 1.6EG 1.62025-07-09
A vulnerability, which was classified as problematic, has been found in FNKvision FNK-GU2 up to 40.1.7. Affected by this issue is some unknown functionality of the file /rom/wpa_supplicant.conf. The manipulation leads to cleartext storage …
- CVE-2025-8205LOWCVSS 3.7EG 3.72025-07-26
A vulnerability, which was classified as problematic, has been found in Comodo Dragon up to 134.0.6998.179. Affected by this issue is some unknown functionality of the component IP DNS Leakage Detector. The manipulation leads to cleartext …
- CVE-2025-8741MEDIUMCVSS 5.9EG 5.92025-08-08
A vulnerability was found in macrozheng mall up to 1.0.3. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/login. The manipulation leads to cleartext transmission of sensiti…
- CVE-2025-8763LOWCVSS 3.7EG 3.72025-08-09
A vulnerability was found in Ruijie EG306MG 3.0(1)B11P309. It has been rated as problematic. This issue affects some unknown processing of the file /etc/strongswan.conf of the component strongSwan. The manipulation of the argument i_dont_c…
Map vulnerabilities like CWE-310 to your infrastructure
EchelonGraph correlates every CVE — across CWE-310 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →