CVE Database

12+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS

12 results for "CWE-32"

CVE-2026-59776
6.8 MEDIUM

Missing Cryptographic Step (CWE-325) vulnerability exists in certain FeliCa IC chips shipped in or before 2017. If the vulnerability is exploited, information stored in the …

Jul 21, 2026
CVE-2026-50091
9.1 CRITICAL

Aqara Home Android (com.lumiunited.aqarahome) 6.0.0 (and white-label clients embedding the same liblumidevsdk.so) uses hard-coded cryptographic keys, which is an instance of "CWE-321: Use of Hard-coded …

Jun 12, 2026
CVE-2026-50086
10.0 CRITICAL

The Aqara IAM/SSO gateway (gw-builder.aqara.com) exposes bidirectional AES round-trups against the platform's signing key without authentication. This is an instance of "CWE-306: Missing Authentication for …

Jun 12, 2026
CVE-2026-41860
8.8 HIGH

CWE-326 in BOSH allows a local attacker to steal Basic-auth credentials or redirect UAA token requests via MITM. HttpRequestHelper#create_async_endpoint and #send_http_get_request_synchronous hard-code OpenSSL::SSL::VERIFY_NONE, enabling an …

Jun 4, 2026
CVE-2025-55053
6.5 MEDIUM

CWE-328: Use of Weak Hash

Sep 9, 2025
CVE-2025-56608
4.2 MEDIUM

The SourceCodester Android application "Corona Virus Tracker App India" 1.0 uses MD5 for digest authentication in `OkHttpClientWrapper.java`. The `handleDigest()` function employs `MessageDigest.getInstance("MD5")` to hash credentials. …

Sep 3, 2025
CVE-2024-54027
8.2 HIGH

A Use of Hard-coded Cryptographic Key vulnerability [CWE-321] in FortiSandbox version 4.4.6 and below, version 4.2.7 and below, version 4.0.5 and below, version 3.2.4 and …

Mar 17, 2025
CVE-2025-26340
8.8 HIGH

A CWE-321 "Use of Hard-coded Cryptographic Key" in the JWT signing in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote …

Feb 12, 2025
CVE-2024-33504
4.1 MEDIUM

A use of hard-coded cryptographic key to encrypt sensitive data vulnerability [CWE-321] in FortiManager 7.6.0 through 7.6.1, 7.4.0 through 7.4.5, 7.2.0 through 7.2.9, 7.0 all …

Feb 11, 2025
CVE-2024-47921
8.4 HIGH

Smadar SPS – CWE-327: Use of a Broken or Risky Cryptographic Algorithm

Dec 30, 2024
CVE-2024-5559
6.1 MEDIUM

CWE-327: Use of a Broken or Risky Cryptographic Algorithm vulnerability exists that could cause denial of service, device reboot, or an attacker gaining full control …

Jun 12, 2024
CVE-2024-36391
9.1 CRITICAL

MileSight DeviceHub - CWE-320: Key Management Errors may allow Authentication Bypass and Man-In-The-Middle Traffic

Jun 2, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.