Vulnerabilities > Crypto JS Project > Crypto JS > 3.1.7

DATE CVE VULNERABILITY TITLE RISK
2023-10-25 CVE-2023-46233 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Crypto-Js Project Crypto-Js
crypto-js is a JavaScript library of crypto standards.
network
low complexity
crypto-js-project CWE-327
critical
9.1
2023-06-12 CVE-2020-36732 Use of Insufficiently Random Values vulnerability in Crypto-Js Project Crypto-Js
The crypto-js package before 3.2.1 for Node.js generates random numbers by concatenating the string "0." with an integer, which makes the output more predictable than necessary.
network
low complexity
crypto-js-project CWE-330
5.3