CWE-325
42 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-325page 1 of 1
- CVE-2015-20112LOWCVSS 3.4EG 3.42025-06-29
RLPx 5 has two CTR streams based on the same key, IV, and nonce. This can facilitate decryption on a private network.
- CVE-2016-9574MEDIUMCVSS 5.9EG 5.92018-07-19
nss before version 3.30 is vulnerable to a remote denial of service during the session handshake when using SessionTicket extension and ECDHE-ECDSA.
- CVE-2017-2598MEDIUMCVSS 4.3EG 4.32018-05-23
Jenkins before versions 2.44, 2.32.2 uses AES ECB block cipher mode without IV for encrypting secrets which makes Jenkins and the stored secrets vulnerable to unnecessary risks (SECURITY-304).
- CVE-2017-2600MEDIUMCVSS 4.3EG 4.32018-05-15
In jenkins before versions 2.44, 2.32.2 node monitor data could be viewed by low privilege users via the remote API. These included system configuration and runtime information of these nodes (SECURITY-343).
- CVE-2017-2603LOWCVSS 2.6EG 2.62018-05-15
Jenkins before versions 2.44, 2.32.2 is vulnerable to a user data leak in disconnected agents' config.xml API. This could leak sensitive data such as API tokens (SECURITY-362).
- CVE-2018-5383MEDIUMCVSS 6.8EG 6.82018-08-07
Bluetooth firmware or operating system software drivers in macOS versions before 10.13, High Sierra and iOS versions before 11.4, and Android versions before the 2018-06-05 patch may not sufficiently validate elliptic curve parameters used…
- CVE-2019-3738MEDIUMCVSS 6.5EG 6.52019-09-18
RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to a Missing Required Cryptographic Step vulnerability. A malicious remote attacker could potentially exploit this vulnerability to coerce two parties into computing the same predic…
- CVE-2020-10702MEDIUMCVSS 5.5EG 5.52020-06-04
A flaw was found in QEMU in the implementation of the Pointer Authentication (PAuth) support for ARM introduced in version 4.0 and fixed in version 5.0.0. A general failure of the signature generation process caused every PAuth-enforced po…
- CVE-2020-15086CRITICALCVSS 9.8EG 9.82020-07-29
In TYPO3 installations with the "mediace" extension from version 7.6.2 and before version 7.6.5, it has been discovered that an internal verification mechanism can be used to generate arbitrary checksums. The allows to inject arbitrary dat…
- CVE-2020-15098HIGHCVSS 8.8EG 8.82020-07-29
In TYPO3 CMS greater than or equal to 9.0.0 and less than 9.5.20, and greater than or equal to 10.0.0 and less than 10.4.6, it has been discovered that an internal verification mechanism can be used to generate arbitrary checksums. This al…
- CVE-2020-26244MEDIUMCVSS 6.8EG 6.82020-12-02
Python oic is a Python OpenID Connect implementation. In Python oic before version 1.2.1, there are several related cryptographic issues affecting client implementations that use the library. The issues are: 1) The IdToken signature algori…
- CVE-2021-22946HIGHCVSS 7.5EG 7.52021-09-29
A user can tell curl >= 7.20.0 and <= 7.78.0 to require a successful upgrade to TLS when speaking to an IMAP, POP3 or FTP server (`--ssl-reqd` on the command line or`CURLOPT_USE_SSL` set to `CURLUSESSL_CONTROL` or `CURLUSESSL_ALL` withlibc…
- CVE-2021-31386MEDIUMCVSS 5.3EG 5.32021-10-19
A Protection Mechanism Failure vulnerability in the J-Web HTTP service of Juniper Networks Junos OS allows a remote unauthenticated attacker to perform Person-in-the-Middle (PitM) attacks against the device. This issue affects: Juniper Net…
- CVE-2021-33560HIGHCVSS 7.5EG 7.52021-06-08
Libgcrypt before 1.8.8 and 1.9.x before 1.9.3 mishandles ElGamal encryption because it lacks exponent blinding to address a side-channel attack against mpi_powm, and the window size is not chosen appropriately. This, for example, affects u…
- CVE-2021-3680MEDIUMCVSS 4.9EG 4.92021-08-04
showdoc is vulnerable to Missing Cryptographic Step
- CVE-2022-1279MEDIUMCVSS 6.5EG 7.52022-04-14
A vulnerability in the encryption implementation of EBICS messages in the open source librairy ebics-java/ebics-java-client allows an attacker sniffing network traffic to decrypt EBICS payloads. This issue affects: ebics-java/ebics-java-cl…
- CVE-2022-20742HIGHCVSS 7.4EG 7.42022-05-03
A vulnerability in an IPsec VPN library of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to read or modify data within an IPsec IKEv2 VPN …
- CVE-2022-20793MEDIUMCVSS 6.8EG 6.82024-11-15
A vulnerability in pairing process of Cisco TelePresence CE Software and RoomOS Software for Cisco Touch 10 Devices could allow an unauthenticated, remote attacker to impersonate a legitimate device and pair with an affected devi…
- CVE-2022-24116CRITICALCVSS 9.8EG 9.82022-12-26
Certain General Electric Renewable Energy products have inadequate encryption strength. This affects iNET and iNET II before 8.3.0.
- CVE-2022-29229MEDIUMCVSS 6.3EG 6.32022-05-18
CaSS is a Competency and Skills System. CaSS Library, (npm:cassproject) has a missing cryptographic step when storing cryptographic keys that can allow a server administrator access to an account’s cryptographic keys. This affects CaSS s…
- CVE-2022-30115MEDIUMCVSS 4.3EG 4.32022-06-02
Using its HSTS support, curl can be instructed to use HTTPS directly insteadof using an insecure clear-text HTTP step even when HTTP is provided in theURL. This mechanism could be bypassed if the host name in the given URL used atrailing d…
- CVE-2023-28998MEDIUMCVSS 6.7EG 6.72023-04-04
The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server. Starting with version 3.0.0 and prior to version 3.6.5, a malicious server administrator can gain full access to an end-to-end encrypted folder. They can de…
- CVE-2023-28999MEDIUMCVSS 6.9EG 6.92023-04-04
Nextcloud is an open-source productivity platform. In Nextcloud Desktop client 3.0.0 until 3.8.0, Nextcloud Android app 3.13.0 until 3.25.0, and Nextcloud iOS app 3.0.5 until 4.8.0, a malicious server administrator can gain full access to …
- CVE-2023-34471MEDIUMCVSS 6.3EG 6.32023-07-05
AMI SPx contains a vulnerability in the BMC where a user may cause a missing cryptographic step by generating a hash-based message authentication code (HMAC). A successful exploit of this vulnerability may lead to the loss confidentialit…
- CVE-2023-36539MEDIUMCVSS 5.3EG 5.32023-06-30
Exposure of information intended to be encrypted by some Zoom clients may lead to disclosure of sensitive information.
- CVE-2023-39199MEDIUMCVSS 4.9EG 4.92023-11-14
Cryptographic issues with In-Meeting Chat for some Zoom clients may allow a privileged user to conduct an information disclosure via network access.
- CVE-2023-40012MEDIUMCVSS 5.9EG 5.92023-08-09
uthenticode is a small cross-platform library for partially verifying Authenticode digital signatures. Versions of uthenticode prior to the 2.x series did not check Extended Key Usages in certificates, in violation of the Authenticode X.50…
- CVE-2023-46129HIGHCVSS 7.5EG 7.52023-10-31
NATS.io is a high performance open source pub-sub distributed communication technology, built for the cloud, on-premise, IoT, and edge computing. The cryptographic key handling library, nkeys, recently gained support for encryption, not ju…
- CVE-2024-43547MEDIUMCVSS 6.5EG 6.52024-10-08
Windows Kerberos Information Disclosure Vulnerability
- CVE-2024-55655LOWCVSS 2.7EG 0.02024-12-10
sigstore-python is a Python tool for generating and verifying Sigstore signatures. Versions of sigstore-python newer than 2.0.0 but prior to 3.6.0 perform insufficient validation of the "integration time" present in "v2" and "v3" bundles d…
- CVE-2025-30147HIGHCVSS 8.7EG 0.02025-05-07
Besu Native contains scripts and tooling that is used to build and package the native libraries used by the Ethereum client Hyperledger Besu. Besu 24.7.1 through 25.2.2, corresponding to besu-native versions 0.9.0 through 1.2.1, have a pot…
- CVE-2025-3938MEDIUMCVSS 6.8EG 6.82025-05-22
Missing Cryptographic Step vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Cryptanalysis. This issue affects Niagara Framework: before 4.14.2, before 4.15…
- CVE-2025-49600MEDIUMCVSS 4.9EG 4.92025-07-04
In MbedTLS 3.3.0 before 3.6.4, mbedtls_lms_verify may accept invalid signatures if hash computation fails and internal errors go unchecked, enabling LMS (Leighton-Micali Signature) forgery in a fault scenario. Specifically, unchecked retur…
- CVE-2025-5323LOWCVSS 3.7EG 3.72025-05-29
A vulnerability, which was classified as problematic, has been found in fossasia open-event-server 1.19.1. This issue affects the function send_email_change_user_email of the file /fossasia/open-event-server/blob/development/app/api/helper…
- CVE-2025-58359MEDIUMCVSS 6.0EG 0.02025-09-05
ZF FROST is a Rust implementation of FROST (Flexible Round-Optimised Schnorr Threshold signatures). In versions 2.0.0 through 2.1.0, refresh shares with smaller min_signers will reduce security of group. The inability to change min_signers…
- CVE-2025-59339MEDIUMCVSS 4.4EG 4.42025-09-17
The Bastion provides authentication, authorization, traceability and auditability for SSH accesses. Session-recording ttyrec files, may be handled by the provided osh-encrypt-rsync script that is a helper to rotate, encrypt, sign, copy, an…
- CVE-2025-60704HIGHCVSS 7.5EG 7.52025-11-11
Missing cryptographic step in Windows Kerberos allows an unauthorized attacker to elevate privileges over a network.
- CVE-2025-69418MEDIUMCVSS 4.0EG 4.02026-01-27
Issue summary: When using the low-level OCB API directly with AES-NI or<br>other hardware-accelerated code paths, inputs whose length is not a multiple<br>of 16 bytes can leave the final partial block unencrypted and unauthenticated.<br><b…
- CVE-2026-22863HIGHCVSS 7.5EG 7.52026-01-15
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Before 2.6.0, node:crypto doesn't finalize cipher. The vulnerability allows an attacker to have infinite encryptions. This can lead to naive attempts at brute forcing, as well as m…
- CVE-2026-29142MEDIUMCVSS 5.3EG 5.32026-04-02
SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to forge a GINA-encrypted email.
- CVE-2026-41395HIGHCVSS 7.5EG 7.52026-04-28
OpenClaw before 2026.3.28 contains a webhook replay vulnerability in Plivo V3 signature verification that canonicalizes query ordering for signatures but hashes raw URLs for replay detection. Attackers can reorder query parameters to bypas…
- CVE-2026-4258HIGHCVSS 7.5EG 7.52026-03-17
All versions of the package sjcl are vulnerable to Improper Verification of Cryptographic Signature due to missing point-on-curve validation in sjcl.ecc.basicKey.publicKey(). An attacker can recover a victim's ECDH private key by sending c…
Map vulnerabilities like CWE-325 to your infrastructure
EchelonGraph correlates every CVE — across CWE-325 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →