CWE-320: CWE-320

12
Total CVEs
0
Critical
2
High
4.8
Avg CVSS

Yearly Trend

2025
10
2023
1
2021
1

Top Affected Vendors

1 Fortinet 1
2 Phpgurukul 1
3 Qualcomm 1
4 Couchcms 1
5 Maxun 1
6 Actionsky 1
7 Amd 1

All CWE-320 CVEs (12)

CVE-2021-26322
7.5

This vulnerability in AMD platform security processors (PSP) allows potential recovery of encrypted private keys due to insufficient initialization ve...

Nov 16, 2021
CVE-2023-21626
7.1

This cryptographic vulnerability in Qualcomm's HLOS (High-Level Operating System) allows improper authentication during key velocity checks when multi...

Aug 8, 2023
CVE-2024-40593
6.0

This vulnerability allows authenticated administrators on affected Fortinet devices to retrieve certificate private keys via the admin shell. This aff...

Dec 11, 2025
CVE-2025-13948
5.6

This vulnerability in opsre go-ldap-admin allows attackers to manipulate JWT secret keys, potentially enabling authentication bypass or privilege esca...

Dec 3, 2025
CVE-2025-13877
5.6

This vulnerability in NocoBase involves the use of a hard-coded cryptographic key in the JWT Service component, allowing attackers to potentially forg...

Dec 2, 2025
CVE-2025-12615
5.0

PHPGurukul News Portal 1.0 contains a hard-coded cryptographic key in its settings.py file, allowing attackers to potentially decrypt sensitive data o...

Nov 3, 2025
CVE-2025-15108
3.7

This vulnerability involves the use of a hard-coded cryptographic key in PandaXGO PandaX's JWT Secret Handler, allowing attackers to potentially forge...

Dec 27, 2025
CVE-2025-15107
3.7

This vulnerability in ActionTech SQLE involves a hard-coded cryptographic key in the JWT Secret Handler component, allowing attackers to potentially f...

Dec 27, 2025
CVE-2025-15105
3.7

This vulnerability in getmaxun maxun up to version 0.0.28 involves the use of hard-coded cryptographic keys in the authentication API, allowing attack...

Dec 27, 2025
CVE-2025-15005
3.7

CVE-2025-15005 is a security vulnerability in CouchCMS up to version 2.4 where the reCAPTCHA handler uses hard-coded cryptographic keys in a configura...

Dec 22, 2025
CVE-2025-14651
3.7

This vulnerability in MartialBE one-hub involves the use of a hard-coded cryptographic key for session secrets in the docker-compose.yml file. Attacke...

Dec 14, 2025
CVE-2025-6666
2.0

This vulnerability in motogadget mo.lock Ignition Lock devices allows attackers to exploit a hard-coded cryptographic key in the NFC Handler component...

Nov 29, 2025

About CWE-320 (CWE-320)

Our database tracks 12 CVEs classified as CWE-320, with 0 rated critical and 2 rated high severity. The average CVSS score for CWE-320 vulnerabilities is 4.8.

External reference: View CWE-320 on MITRE CWE →

Monitor CWE-320 Vulnerabilities

Get alerted when new CWE-320 CVEs affect your infrastructure.

Start Monitoring Free