CWE-836 · 13 records
Use of Password Hash Instead of Password for Authentication
CVEs in this class
13 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
41Plan | CVE-2023-34132Weaponized | Use of password hash instead of password for authentication vulnerability in SonicWall GMS and Analytics allows Pass-the-Hash attacks.sonicwall · analytics · CWE-836 | Critical9.8 | — | 7.7% | Jul 12, 2023 |
40Plan | CVE-2017-7927No exploit | A Use of Password Hash Instead of Password for Authentication issue was discovered in Dahua DH-IPC-HDBW23A0RN-ZS, DH-IPC-HDBW13A0SN, DH-IPC-dahuasecurity · dh-ipc-hdbw23a0rn-zs firmware · CWE-836 | High7.3 | — | 36.7% | May 5, 2017 |
39Monitor | CVE-2021-23857No exploit | Login with hash: The login routine allows the client to log in to the system not by using the password, but by using the hash of the passworbosch · rexroth indramotion mlc l20 firmware · CWE-836 | Critical9.8 | — | 1.2% | Oct 4, 2021 |
39Monitor | CVE-2023-23450No exploit | Use of Password Hash Instead of Password for Authentication in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114sick · ftmg-esd20axx firmware · CWE-836 | Critical9.8 | — | 0.7% | May 15, 2023 |
36Monitor | CVE-2022-32282No exploit | An improper password check exists in the login functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364.wwbn · avideo · CWE-836 | High8.8 | — | 1.8% | Aug 22, 2022 |
36Monitor | CVE-2026-9222No exploit | Setracker2 Children's Smartwatch Ecosystem Use of password hash instead of password for authenticationshenzhen i365-tech co. ltd. · setracker2 parental control app (android) package com.tgelec.setracker · CWE-836 | Critical9.2 | — | 0.4% | Jun 25, 2026 |
35Monitor | CVE-2023-39546No exploit | CLUSTERPRO X Ver5.1 and earlier and EXPRESSCLUSTER X 5.1 and earlier, CLUSTERPRO X SingleServerSafe 5.1 and earlier, EXPRESSCLUSTER X Singlenec · expresscluster x · CWE-836 | High8.8 | — | 0.6% | Nov 17, 2023 |
34Monitor | CVE-2019-25552No exploit | CEWE PHOTO SHOW 6.4.3 Denial of Service via Password Fieldcewe · photo show · CWE-836 | High8.7 | — | 0.4% | Mar 21, 2026 |
32Monitor | CVE-2023-4299No exploit | Digi RealPort Protocol Use of Password Hash Instead of Password for Authenticationdigi · realport · CWE-836 | High8.1 | — | 0.7% | Aug 31, 2023 |
30Monitor | CVE-2025-64471No exploit | A use of password hash instead of password for authentication vulnerability [CWE-836] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1fortinet · fortiweb · CWE-836 | High7.5 | — | 0.3% | Dec 9, 2025 |
30Monitor | CVE-2025-48925No exploit | The TeleMessage service through 2025-05-05 relies on the client side (e.g., the TM SGNL app) to do MD5 hashing, and then accepts the hash assmarsh · telemessage · CWE-836 | High7.5 | — | 0.3% | May 28, 2025 |
21Monitor | CVE-2026-40103No exploit | Vikunja's Scoped API tokens with projects.background permission can delete project backgroundsvikunja · vikunja · CWE-836 | Medium5.4 | — | 0.3% | Apr 10, 2026 |
21Monitor | CVE-2025-52543No exploit | Login to the application services using only the password hashcopeland · e3 supervisory controller firmware · CWE-836 | Medium5.3 | — | 0.3% | Sep 2, 2025 |
- CVE-2023-3413241Plan
Use of password hash instead of password for authentication vulnerability in SonicWall GMS and Analytics allows Pass-the-Hash attacks.
CriticalCVSS 9.8WeaponizedEPSS 8%sonicwall · analyticsJul 12, 2023
- CVE-2017-792740Plan
A Use of Password Hash Instead of Password for Authentication issue was discovered in Dahua DH-IPC-HDBW23A0RN-ZS, DH-IPC-HDBW13A0SN, DH-IPC-
HighCVSS 7.3No exploitEPSS 37%dahuasecurity · dh-ipc-hdbw23a0rn-zs firmwareMay 5, 2017
- CVE-2021-2385739Monitor
Login with hash: The login routine allows the client to log in to the system not by using the password, but by using the hash of the passwor
CriticalCVSS 9.8No exploitEPSS 1%bosch · rexroth indramotion mlc l20 firmwareOct 4, 2021
- CVE-2023-2345039Monitor
Use of Password Hash Instead of Password for Authentication in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114
CriticalCVSS 9.8No exploitEPSS 1%sick · ftmg-esd20axx firmwareMay 15, 2023
- CVE-2022-3228236Monitor
An improper password check exists in the login functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364.
HighCVSS 8.8No exploitEPSS 2%wwbn · avideoAug 22, 2022
- CVE-2026-922236Monitor
Setracker2 Children's Smartwatch Ecosystem Use of password hash instead of password for authentication
CriticalCVSS 9.2No exploitEPSS 0%shenzhen i365-tech co. ltd. · setracker2 parental control app (android) package com.tgelec.setrackerJun 25, 2026
- CVE-2023-3954635Monitor
CLUSTERPRO X Ver5.1 and earlier and EXPRESSCLUSTER X 5.1 and earlier, CLUSTERPRO X SingleServerSafe 5.1 and earlier, EXPRESSCLUSTER X Single
HighCVSS 8.8No exploitEPSS 1%nec · expresscluster xNov 17, 2023
- CVE-2019-2555234Monitor
CEWE PHOTO SHOW 6.4.3 Denial of Service via Password Field
HighCVSS 8.7No exploitEPSS 0%cewe · photo showMar 21, 2026
- CVE-2023-429932Monitor
Digi RealPort Protocol Use of Password Hash Instead of Password for Authentication
HighCVSS 8.1No exploitEPSS 1%digi · realportAug 31, 2023
- CVE-2025-6447130Monitor
A use of password hash instead of password for authentication vulnerability [CWE-836] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1
HighCVSS 7.5No exploitEPSS 0%fortinet · fortiwebDec 9, 2025
- CVE-2025-4892530Monitor
The TeleMessage service through 2025-05-05 relies on the client side (e.g., the TM SGNL app) to do MD5 hashing, and then accepts the hash as
HighCVSS 7.5No exploitEPSS 0%smarsh · telemessageMay 28, 2025
- CVE-2026-4010321Monitor
Vikunja's Scoped API tokens with projects.background permission can delete project backgrounds
MediumCVSS 5.4No exploitEPSS 0%vikunja · vikunjaApr 10, 2026
- CVE-2025-5254321Monitor
Login to the application services using only the password hash
MediumCVSS 5.3No exploitEPSS 0%copeland · e3 supervisory controller firmwareSep 2, 2025