Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-327 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 55 | 54 | 0 |
▁▁▁▁▁▁▁▂█▃▃
2025-10 1 · 2025-11 0 · 2025-12 0 · 2026-01 1 · 2026-02 0 · 2026-03 0 · 2026-04 2 · 2026-05 4 · 2026-06 29 · 2026-07 9 · 2026-08 9
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-48386 | 7.5 | 50.2 | — | ColdFusion | Use of a Broken or Risky Cryptographic Algorithm (CWE-327) |
| CVE-2026-5588 | 6.3 | 47.9 | — | PKIX draft CompositeVerifier accepts empty signature sequence as valid. |
| CVE-2026-20833 | 5.5 | 40.8 | — | Windows Kerberos Information Disclosure Vulnerability |
| CVE-2026-66407 | 7.7 | 25.9 | — | — |
| CVE-2025-14813 | 9.3 | 24.1 | — | GOSTCTR implementation unable to process more than 255 blocks correctly |
| CVE-2026-44053 | 7.4 | 22.8 | — | Weak cryptography in DHCAST128 UAM |
| CVE-2026-46395 | 9.3 | 22.1 | — | HAX CMS Vulnerable to Private Key Disclosure via Broken HMAC Implementation |
| CVE-2026-50086 | 9.8 | 21.6 | — | Aqara unauthenticated AES oracle |
| CVE-2026-27871 | 2.9 | 19.2 | — | TL280 |
| CVE-2026-13510 | 2.9 | 12.3 | — | SimStudioAI sim Password Protection deployment.ts weak hash |
| CVE-2026-14738 | 2.9 | 12.3 | — | exo-explore exo Vision Feature Cache vision.py _image_cache_key weak hash |
| CVE-2026-45701 | 6.9 | 9.4 | — | Sulu: Weak Cryptographical usage for API Key generation and Reset Tokens |
| CVE-2026-13482 | 2.9 | 8.9 | — | skypilot-org skypilot User ID server.py username.encode weak hash |
| CVE-2026-9261 | 7.6 | 8.3 | — | — |
| CVE-2026-74888 | 8.7 | 6.4 | — | openssl_encrypt before 1.4.0 Non-Standard PBKDF2 Key Derivation |
| CVE-2026-36609 | 7.3 | 6.3 | — | — |
| CVE-2026-47775 | 6.8 | 6.0 | — | Envoy OAuth2 Filter: Padding Oracle via AES-256-CBC Cookie Decryption |
| CVE-2026-63761 | 5.3 | 6.0 | — | SurrealDB before 3.1.0 Algorithm Downgrade via ES512 |
| CVE-2026-9221 | 8.7 | 5.7 | — | Setracker2 Children's Smartwatch Ecosystem Use of a Broken or Risky Cryptographic Algor… |
| CVE-2026-11479 | 1.3 | 5.7 | — | yoanbernabeu grepai Qdrant Backend chunker.go weak hash |
| Vendor | CVEs |
|---|---|
| dell | 2 |
| hcl software | 2 |
| indian motorcycle | 2 |
| legion of the bouncy castle | 2 |
| oberon microsystems | 2 |
| wolfssl | 2 |
| yoanbernabeu | 2 |
| adobe | 1 |
| andritz | 1 |
| aqara | 1 |
| better-auth | 1 |
| canon | 1 |
| corewcf | 1 |
| ecovacs robotics | 1 |
| envoyproxy | 1 |