CWE-326: CWE-326
Yearly Trend
Top Affected Vendors
All CWE-326 CVEs (59)
CVE-2024-37034 is an authentication bypass vulnerability in Couchbase Server where credentials may not be properly negotiated with SCRAM-SHA encryptio...
Jul 26, 2024This vulnerability affects Siemens SIPROTEC 5 protection devices and communication modules, allowing man-in-the-middle attackers to decrypt sensitive ...
Jul 9, 2024This vulnerability in Google Chrome's App-Bound Encryption implementation on Windows allows a local attacker to read potentially sensitive information...
Nov 10, 2025The Linux kernel's Bluetooth L2CAP implementation fails to validate encryption key size on incoming connections, allowing connections with insufficien...
Sep 24, 2025This vulnerability in Easy-RSA allows a local attacker to more easily brute-force the private CA key when it's created using OpenSSL 3. The weak encry...
Jan 20, 2025This vulnerability in Apache Answer uses weak MD5 hashing of user email addresses for Gravatar integration, potentially exposing email addresses throu...
Sep 25, 2024This vulnerability involves inadequate encryption strength in .NET, .NET Framework, and Visual Studio, allowing an authorized attacker to disclose sen...
Oct 14, 2025This vulnerability allows a local unprivileged attacker to extract data from update images in Sprecher Automation SPRECON-E products due to insufficie...
Dec 2, 2025CVE-2026-0510 is a cryptographic weakness in SAP NetWeaver Application Server for Java's User Management Engine where obsolete encryption algorithms p...
Jan 13, 2026About CWE-326 (CWE-326)
Our database tracks 59 CVEs classified as CWE-326, with 4 rated critical and 39 rated high severity. The average CVSS score for CWE-326 vulnerabilities is 7.2.
External reference: View CWE-326 on MITRE CWE →
Monitor CWE-326 Vulnerabilities
Get alerted when new CWE-326 CVEs affect your infrastructure.
Start Monitoring Free