Browse and filter security vulnerabilities across ecosystems
Browse and filter security vulnerabilities across ecosystems
Inadequate Encryption Strength in Panduit IntraVUE by Pronetiqs
joserfc: HS256/HS384/HS512 verify accepts empty/nil HMAC key (cross-language sibling of CVE-2026-45363)
HCL Aftermarket EPC is affected by Business Logic Vulnerability using which a non valid user of the application can obtain passwords from the serve...
HCL DFXServer is affected by an Unencrypted Communication vulnerability.
`jwt` (Ruby gem) - empty-key HMAC bypass
Weak encryption mechanism for User directory
UltraVNC MS-Logon II uses 64-bit Diffie-Hellman and seeded libc rand() enabling credential interception
CWE-326 in BOSH allows a local attacker to steal Basic-auth credentials or redirect UAA token requests via MITM
electerm's encrypt method not safe enough
Note Mark: JWT Secret Weakness allows Full Account Takeover via token forgery
fast-jwt: Empty HMAC secret accepted via async key resolver - JWT auth bypass
Meari weak XOR obfuscation
ELBA5 5.8.0 Remote Code Execution via Database Access
Encryption vulnerable to brute-force decryption in GoAnywhere MFT
Use of weak cryptographic key in TP-Link Archer C7
OrangeHRM Uses AES-ECB for Sensitive Data Encryption Enables Pattern Disclosure
AVideo has an unauthenticated decrypt oracle leaking any ciphertext
AVideo has a PGP 2FA Bypass via Cryptographically Broken 512-bit RSA Key Generation in LoginControl Plugin
IBM Security QRadar EDR Software has multiple vulnerabilities
Jervis has a Salt for PBKDF2 derived from password
Showing 1 - 20 of 1,000+ results