İçeriğe atla
Noroxi

CWE-328 · 61 kayıt

Use of Weak Hash

Bu sınıftaki CVE’ler

61 kayıt

  • CVE-2026-51996
    39İzleyin

    An issue in geelen mcp-remote 0.1.16 through 0.1.38 allows a remote attacker to execute arbitrary code via the src/lib/utils.ts and the getS

    KritikCVSS 9,8İstismar yokEPSS %1

    6 gün önce

  • CVE-2025-27595
    39İzleyin

    Weak hashing alghrythm

    KritikCVSS 9,8İstismar yokEPSS %1

    sick ag · sick dl100-2xxxxxxx14 Mar 2025

  • CVE-2025-41652
    39İzleyin

    Weidmueller: Authentication Bypass Vulnerability in Industrial Ethernet Switches

    KritikCVSS 9,8İstismar yokEPSS %0

    weidmueller · ie-sw-vl05m-5tx27 May 2025

  • CVE-2022-45141
    39İzleyin

    Since the Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability was disclosed by Microsoft on Nov 8 2022 and per RFC8429 it is assu

    KritikCVSS 9,8İstismar yokEPSS %0

    samba · samba6 Mar 2023

  • CVE-2026-36182
    39İzleyin

    GNCC GP5 v7.1.76 was discovered to utilize a weak hashing algorithm to protect the root password, possibly allowing attackers to obtain root

    KritikCVSS 9,8İstismar yokEPSS %0

    4 Haz 2026

  • CVE-2024-54143
    38İzleyin

    openwrt/asu allows build artifact poisoning via truncated SHA-256 hash and command injection

    KritikCVSS 9,3İstismar yokEPSS %2

    openwrt · asu6 Ara 2024

  • CVE-2020-37168
    37İzleyin

    Ecommerce Systempay 1.0 Production Key Brute Force

    KritikCVSS 9,3İstismar yokEPSS %0

    paiement · ecommerce systempay13 May 2026

  • CVE-2023-46233
    36İzleyin

    crypto-js PBKDF2 1,000 times weaker than specified in 1993 and 1.3M times weaker than current standard

    KritikCVSS 9,1İstismar yokEPSS %1

    crypto-js project · crypto-js25 Eki 2023

  • CVE-2023-46133
    36İzleyin

    crypto-es PBKDF2 1,000 times weaker than specified in 1993 and 1.3M times weaker than current standard

    KritikCVSS 9,1İstismar yokEPSS %0

    entronad · cryptoes25 Eki 2023

  • CVE-2024-48847
    35İzleyin

    MD5 bypass operation

    YüksekCVSS 8,8İstismar yokEPSS %0

    abb · aspect-ent-2 firmware5 Ara 2024

  • CVE-2026-54266
    35İzleyin

    Angular: Weak 32-Bit Cache Key Hashing in `HttpTransferCache` Leading to Cross-Request Data Leakage and State Poisoning

    YüksekCVSS 8,8İstismar yokEPSS %0

    angular · angular22 Haz 2026

  • CVE-2023-43635
    35İzleyin

    Vault Key Sealed With SHA1 PCRs

    YüksekCVSS 8,8İstismar yokEPSS %0

    linuxfoundation · edge virtualization engine20 Eyl 2023

  • CVE-2023-43630
    35İzleyin

    Config Partition Not Measured From 2 Fronts

    YüksekCVSS 8,8İstismar yokEPSS %0

    linuxfoundation · edge virtualization engine20 Eyl 2023

  • Duplicate Advisory: EVE Doesn't Measure Config Partition From 2 Fronts

    YüksekCVSS 8,8İstismar yok

    Go · github.com/lf-edge/eve20 Eyl 2023

  • CVE-2024-48924
    34İzleyin

    MessagePack allows untrusted data to lead to DoS attack due to hash collisions and stack overflow

    YüksekCVSS 8,7İstismar yokEPSS %0

    messagepack-csharp · messagepack-csharp17 Eki 2024

  • CVE-2026-32129
    34İzleyin

    Poseidon V1 variable-length input collision via implicit zero-padding

    YüksekCVSS 8,7İstismar yokEPSS %0

    stellar · rs-soroban-poseidon12 Mar 2026

  • CVE-2026-41879
    32İzleyin

    Weak password hashing in R-SOFT DMS

    YüksekCVSS 8,2İstismar yokEPSS %0

    r-soft serwis · dms10 Tem 2026

  • CVE-2019-13539
    31İzleyin

    Medtronic Valleylab FT10 and FX8 Reversible One-way Hash

    YüksekCVSS 7,8İstismar yokEPSS %0

    medtronic · valleylab exchange client8 Kas 2019

  • CVE-2023-2900
    30İzleyin

    NFine Rapid Development Platform CheckLogin weak hash

    YüksekCVSS 7,5İstismar yokEPSS %1

    nfine rapid development platform project · nfine rapid development platform25 May 2023

  • CVE-2026-40164
    30İzleyin

    jq: Algorithmic complexity DoS via hardcoded MurmurHash3 seed

    YüksekCVSS 7,5İstismar yokEPSS %1

    jqlang · jq13 Nis 2026

  • CVE-2025-49197
    30İzleyin

    Deprecated TLS version supported

    YüksekCVSS 7,5İstismar yokEPSS %0

    sick · media server12 Haz 2025

  • CVE-2025-47276
    30İzleyin

    Actualizer Uses OpenSSL's "-passwd" Function Which Uses SHA512 Under The Hood Instead of Proper Password Hasher like Yescript/Argon2i

    YüksekCVSS 7,5İstismar yokEPSS %0

    chewkeanho · actualizer13 May 2025

  • CVE-2024-38341
    30İzleyin

    IBM Sterling Secure Proxy information disclosure

    YüksekCVSS 7,5İstismar yokEPSS %0

    ibm · sterling secure proxy28 May 2025

  • CVE-2024-47182
    30İzleyin

    Dozzle uses unsafe hash for passwords

    YüksekCVSS 7,5İstismar yokEPSS %0

    amirraminfar · dozzle27 Eyl 2024

  • CVE-2025-54535
    30İzleyin

    In JetBrains TeamCity before 2025.07 password reset and email verification tokens were using weak hashing algorithms

    YüksekCVSS 7,5İstismar yokEPSS %0

    jetbrains · teamcity28 Tem 2025

Tüm zafiyet sınıfları