CWE-327

CWE-327 · 7 records · 0 with a public proof-of-concept

Records the NVD classes under CWE-327, highest CVSS first.

  1. HIGH 7.5CVE-2026-82356

    Imprivata EAM <=26.2.6 lacks the ability to rotate its RSA key pair after deployment when generating an X.509 certificate. Using an RSA key pair indefinitely for certificate generation is against best practices.

    AI risk analysis on Exploit-DB.ai →

  2. MEDIUM 5.9CVE-2025-36084

    IBM Concert 1.0.0 through 3.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.

    AI risk analysis on Exploit-DB.ai →

  3. MEDIUM 5.4CVE-2026-18153

    IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to obtain sensitive information and forge authentication tags due to the use of hard-coded cryptographic keys and initialization vectors.

    AI risk analysis on Exploit-DB.ai →

  4. MEDIUM 4.4CVE-2025-36591

    Dell ECS versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.4.0.0, contains an Use of a Broken or Risky Cryptographic Algorithm vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, le…

    AI risk analysis on Exploit-DB.ai →

  5. LOW 3.7CVE-2026-81438

    Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains Use of a Broken or Risky Cryptographic Algorithm vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information discl…

    AI risk analysis on Exploit-DB.ai →

  6. LOW 3.3CVE-2026-18104

    IBM Db2 Mirror for i 7.6, 7.5, and 7.4 could allow a local attacker to obtain sensitive information due to the use of the AES Electronic Codebook (ECB) mode for encryption.

    AI risk analysis on Exploit-DB.ai →

  7. UNSCOREDCVE-2026-15638

    An unauthenticated user with access to Secret Server could leverage a padding oracle to decrypt or encrypt data using one of the server's cryptographic keys. The key itself is not exposed.

    AI risk analysis on Exploit-DB.ai →