4+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.
4 results for "CWE-32"
CWE-326 in BOSH allows a local attacker to steal Basic-auth credentials or redirect UAA token requests via MITM. HttpRequestHelper#create_async_endpoint and #send_http_get_request_synchronous hard-code OpenSSL::SSL::VERIFY_NONE, enabling an …
A Use of Hard-coded Cryptographic Key vulnerability [CWE-321] in FortiSandbox version 4.4.6 and below, version 4.2.7 and below, version 4.0.5 and below, version 3.2.4 and …
A CWE-321 "Use of Hard-coded Cryptographic Key" in the JWT signing in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote …
Smadar SPS – CWE-327: Use of a Broken or Risky Cryptographic Algorithm
Free website and port scanning — find vulnerabilities before attackers do.