| CVE-2026-74893 | 8.8 | — | — | — | jahlives / openssl encrypt | openssl_encrypt versions before 1.4.0 contain hardcoded default JWT signing secrets in config.py that pass validat | 19d ago |
| CVE-2026-74883 | 8.8 | — | — | — | jahlives / openssl encrypt | openssl_encrypt versions before 1.4.0 contain a sandbox bypass vulnerability where the plugin sandbox fails to res | 19d ago |
| CVE-2026-74877 | 8.8 | — | — | — | jahlives / openssl encrypt | openssl_encrypt versions before 1.4.0 contain a missing ownership verification vulnerability in the revoke_key met | 19d ago |
| CVE-2026-81683 | 8.4 | — | — | — | jahlives / openssl encrypt | openssl_encrypt (pip package openssl-encrypt) versions 1.4.8 and earlier store an mTLS client private key in clear | 9d ago |
| CVE-2026-81719 | 7.8 | — | — | — | jahlives / openssl encrypt | openssl_encrypt before 1.4.9 executes untrusted third-party plugins with insufficient controls: the plugin signatu | 9d ago |
| CVE-2026-81721 | 7.5 | — | — | — | jahlives / openssl encrypt | openssl_encrypt before 1.4.9 fails to validate KDF cost parameters in encrypted file metadata and keystore headers | 9d ago |
| CVE-2026-81705 | 7.5 | — | — | — | jahlives / openssl encrypt | openssl-encrypt before 1.4.9 fails to redact the file password in its --debug argv dump when the password is suppl | 9d ago |
| CVE-2026-81704 | 7.5 | — | — | — | jahlives / openssl encrypt | openssl_encrypt versions before 1.4.9 contain a weak key derivation vulnerability in the D-Bus CryptoService.Encry | 9d ago |
| CVE-2026-81699 | 7.5 | — | — | — | jahlives / openssl encrypt | openssl_encrypt versions before 1.4.9 fail to properly validate key derivation function costs in crafted files, al | 9d ago |
| CVE-2026-81698 | 7.5 | — | — | — | jahlives / openssl encrypt | openssl_encrypt versions before 1.4.9 contain a shell injection vulnerability in the info command's reconstructed | 9d ago |
| CVE-2026-81693 | 7.5 | — | — | — | jahlives / openssl encrypt | openssl_encrypt before 1.4.9 fails to validate the total field from QR JSON payloads before materializing ranges. | 9d ago |
| CVE-2026-81691 | 7.5 | — | — | — | jahlives / openssl encrypt | openssl_encrypt versions before 1.4.9 fail to validate server URLs in login and register_with_email functions, acc | 9d ago |
| CVE-2026-81689 | 7.5 | — | — | — | jahlives / openssl encrypt | openssl_encrypt versions before 1.4.9 derive the remote-pepper wrap key using unsalted HKDF-SHA256 or bare SHA-256 | 9d ago |
| CVE-2026-81688 | 7.5 | — | — | — | jahlives / openssl encrypt | openssl_encrypt versions before 1.4.9 store an unkeyed SHA-256 hash of the plaintext in the cleartext file header | 9d ago |
| CVE-2026-74892 | 7.5 | — | — | — | jahlives / openssl encrypt | openssl_encrypt versions before 1.4.0 contain a hardcoded default secret key in the standalone telemetry server co | 19d ago |
| CVE-2026-74888 | 7.5 | — | — | — | jahlives / openssl encrypt | openssl_encrypt versions before 1.4.0 use a non-standard PBKDF2 key derivation construction with iterations=1 per | 19d ago |
| CVE-2026-74884 | 7.5 | — | — | — | jahlives / openssl encrypt | openssl_encrypt versions before 1.4.0 contain a path traversal vulnerability in the _is_safe_path method where the | 19d ago |
| CVE-2026-74882 | 7.5 | — | — | — | jahlives / openssl encrypt | openssl_encrypt versions before 1.4.0 contain an insecure default configuration that trusts the entire RFC 1918 pr | 19d ago |
| CVE-2026-74879 | 7.5 | — | — | — | jahlives / openssl encrypt | openssl_encrypt versions before 1.4.0 contain an information disclosure vulnerability in the /ready endpoint that | 19d ago |
| CVE-2026-74874 | 7.5 | — | — | — | jahlives / openssl encrypt | openssl_encrypt versions before 1.4.0 use Python's non-cryptographic random module for steganographic pixel select | 19d ago |
| CVE-2026-81690 | 7.3 | — | — | — | jahlives / openssl encrypt | openssl-encrypt (pip package) before 1.4.9 contains a symlink-following flaw in its verify-usb v2 added-file allow | 9d ago |
| CVE-2026-81714 | 7 | — | — | — | jahlives / openssl encrypt | openssl_encrypt (pip: openssl-encrypt) versions <= 1.4.8 use suffix-tolerant fingerprint matching in enroll_trust_ | 9d ago |