A04:2025 Cryptographic Failures
Sensitive data exposed in transit or at rest due to absent, weak, or misused cryptography.
Member CWEs (32)
- CWE-261 Weak Encoding for Password
- CWE-296 Improper Following of a Certificate's Chain of Trust
- CWE-319 Cleartext Transmission of Sensitive Information
- CWE-320
- CWE-321 Use of Hard-coded Cryptographic Key
- CWE-322 Key Exchange without Entity Authentication
- CWE-323 Reusing a Nonce, Key Pair in Encryption
- CWE-324 Use of a Key Past its Expiration Date
- CWE-325 Missing Cryptographic Step
- CWE-326 Inadequate Encryption Strength
- CWE-327 Use of a Broken or Risky Cryptographic Algorithm
- CWE-328 Use of Weak Hash
- CWE-329 Generation of Predictable IV with CBC Mode
- CWE-330 Use of Insufficiently Random Values
- CWE-331 Insufficient Entropy
- CWE-332 Insufficient Entropy in PRNG
- CWE-334 Small Space of Random Values
- CWE-335 Incorrect Usage of Seeds in Pseudo-Random Number Generator (PRNG)
- CWE-336 Same Seed in Pseudo-Random Number Generator (PRNG)
- CWE-337 Predictable Seed in Pseudo-Random Number Generator (PRNG)
- CWE-338 Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
- CWE-340 Generation of Predictable Numbers or Identifiers
- CWE-342 Predictable Exact Value from Previous Values
- CWE-347 Improper Verification of Cryptographic Signature
- CWE-523 Unprotected Transport of Credentials
- CWE-757 Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade')
- CWE-759 Use of a One-Way Hash without a Salt
- CWE-760 Use of a One-Way Hash with a Predictable Salt
- CWE-780 Use of RSA Algorithm without OAEP
- CWE-916 Use of Password Hash With Insufficient Computational Effort
- CWE-1240 Use of a Cryptographic Primitive with a Risky Implementation
- CWE-1241 Use of Predictable Algorithm in Random Number Generator
Mapped NIST 800-53 r5 controls (3)
Our two-way, human-QA’d reading of how this category and each NIST 800-53 control relate. No external body publishes an OWASP→800-53 mapping, so these are our assessment.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Tagged CVEs (showing 50 most recent of 4,397)
- CVE-2026-77151
- CVE-2026-76258
- CVE-2026-76244
- CVE-2026-76234
- CVE-2026-75946
- CVE-2026-75112
- CVE-2026-75106
- CVE-2026-74901
- CVE-2026-74889
- CVE-2026-74888
- CVE-2026-74887
- CVE-2026-74876
- CVE-2026-74874
- CVE-2026-74871
- CVE-2026-74244
- CVE-2026-73576
- CVE-2026-73567
- CVE-2026-73542
- CVE-2026-72889
- CVE-2026-72887
- CVE-2026-72861
- CVE-2026-71851
- CVE-2026-71225
- CVE-2026-68759
- CVE-2026-68757
- CVE-2026-68745
- CVE-2026-67596
- CVE-2026-67336
- CVE-2026-66776
- CVE-2026-66763
- CVE-2026-66407
- CVE-2026-66391
- CVE-2026-65777
- CVE-2026-65616
- CVE-2026-65309
- CVE-2026-64964
- CVE-2026-64887
- CVE-2026-64798
- CVE-2026-64742
- CVE-2026-64623
- CVE-2026-63761
- CVE-2026-63424
- CVE-2026-63423
- CVE-2026-63237
- CVE-2026-63089
- CVE-2026-62918
- CVE-2026-62873
- CVE-2026-62834
- CVE-2026-62757
- CVE-2026-62241
Data: OWASP Top 10:2025 (CC BY-SA 4.0) · CWE memberships from cwe-api.mitre.org (meta-category CWE-1439).