Note Mark is an open-source note-taking application. Prior to 0.19.4, no minimum length or entropy is enforced on the JW
ELBA5 5.8.0 contains a remote code execution vulnerability that allows attackers to obtain database credentials and exec
openssl_encrypt versions before 1.4.0 use HKDF with no salt and static info parameter in key normalization functions, re
fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to 6.2.4, a critical authentication-bypass vulnerabili
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.9.5, deterministic
ruby-jwt is a Ruby implementation of the RFC 7519 OAuth JSON Web Token standard. Prior to 2.10.3 and 3.2.0, JWT.decode(t
HCL Aftermarket EPC is affected by Business Logic Vulnerability using which a non valid user of the application can obta
Inadequate Encryption Strength vulnerability in TP-Link Archer C7 v5 and v5.8 (uhttpd modules) allows Password Recovery
CWE-326 in BOSH allows a local attacker to steal Basic-auth credentials or redirect UAA token requests via MITM. HttpReq
IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute arbitrary code due to a cryptogra
Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, the salt is derived
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the API plugin exposes a `decryptStr
A vulnerability in Grafana Tempo exposes the S3 SSE-C encryption key in plaintext through the /status/config endpoint, p
In Meari IoT SDK image handling (libmrplayer.so) as observed in CloudEdge 5.5.0 (build 220), Arenti 1.8.1 (build 220), a
Version 3.0.7 of the Securly Chrome Extension exposes multiple publicly accessible endpoints that allow unauthenticated
Unauthorized use of Kyocera printers, allows all information stored in the Kyocera address book to be exported. The secu
openssl_encrypt versions before 1.4.9 use under-parameterized PBKDF2-HMAC-SHA256 with only 100,000 iterations to protect
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `createKeys()` function in the L
UltraVNC through 1.8.2.2 uses inadequate cryptography in the MS-Logon II authentication scheme (rfbUltraVNC_MsLogonIIAut
Pronetiqs IntraVUE versions 3.2.1a14 and prior have an inadequate encryption strength vulnerability which could allow an
HCL DFXServer is affected by an Unencrypted Communication vulnerability. The application permits users to establish conn
IBM Security QRadar EDR 3.12 through 3.12.23 IBM Security ReaQta uses weaker than expected cryptographic algorithms that
Encrypted values in Fortra's GoAnywhere MFT prior to version 7.10.0 and GoAnywhere Agents prior to version 2.2.0 utilize
The encryption algorithm used to protect the configuration of user accounts, stored in the built-in user directory of Pc
Inadequate encryption strength in Windows Active Directory allows an authorized attacker to bypass a security feature ov
The Newsletters WordPress plugin before 4.17 does not generate its API key using a sufficiently random source, deriving
Cryptographic Flaw in PDFium in Google Chrome prior to 147.0.7727.55 allowed an attacker to read potentially sensitive i
Inadequate encryption strength in Notifications in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote a
The User Management Engine (UME) in NetWeaver Application Server for Java (NW AS Java) utilizes an obsolete cryptographi
OrangeHRM is a comprehensive human resource management (HRM) system. From 5.0 to 5.8, OrangeHRM Open Source encrypts cer
joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standar
Use of an insecure cryptographic algorithm in the cashless payment system using NFC wristbands from CasfID Servicios Tec
In Bouncy Castle for Java before 1.85, BKS keystore accepts legacy version with 16-bit integrity MAC key. This issue als
Frequently Asked Questions
What is CWE-326?
CWE-326 (CWE-326) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-326?
There are 33 CVE records associated with CWE-326 in our database. Of these, 7 are critical severity, 12 are high severity, and 9 are medium severity.
How can I protect against CWE-326 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-326 using AI-powered security agents.
Detect CWE-326 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-326 vulnerabilities across your infrastructure.
Get Started