CWE-916 · 108 записей
Use of Password Hash With Insufficient Computational Effort
CVE этого класса
108 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
42В плане | CVE-2018-10618Proof of concept | Davolink DVW-3200N all version prior to Version 1.00.06.davolink · dvw-3200n firmware · CWE-916 | Критическая9,8 | — | 10,0 % | 1 авг. 2018 г. |
41В плане | CVE-2020-14516Эксплойта нет | In Rockwell Automation FactoryTalk Services Platform Versions 6.10.00 and 6.11.00, there is an issue with the implementation of the SHA-256 rockwellautomation · factorytalk services platform · CWE-916 | Критическая10,0 | — | 4,1 % | 18 мар. 2021 г. |
40В плане | CVE-2005-0408Proof of concept | CitrusDB 0.3.6 and earlier generates easily predictable MD5 hashes of the user name for the id_hash cookie, which allows remote attackers tocitrusdb · citrusdb · CWE-916 | Критическая9,8 | — | 4,7 % | 14 февр. 2005 г. |
39Наблюдать | CVE-2001-0967Эксплойта нет | Knox Arkeia server 4.2, and possibly other versions, uses a constant salt when encrypting passwords using the crypt() function, which makes arkeia · arkeia · CWE-916 | Критическая9,8 | — | 1,0 % | 31 авг. 2001 г. |
39Наблюдать | CVE-2018-15680Эксплойта нет | An issue was discovered in BTITeam XBTIT 2.5.4.btiteam · xbtit · CWE-916 | Критическая9,8 | — | 0,8 % | 5 сент. 2018 г. |
39Наблюдать | CVE-2019-17216Эксплойта нет | An issue was discovered on V-Zug Combi-Steam MSLQ devices before Ethernet R07 and before WLAN R05.vzug · combi-stream mslq firmware · CWE-916 | Критическая9,8 | — | 0,7 % | 6 окт. 2019 г. |
39Наблюдать | CVE-2021-36767Эксплойта нет | In Digi RealPort through 4.10.490, authentication relies on a challenge-response mechanism that gives access to the server password, making digi · realport · CWE-916 | Критическая9,8 | — | 0,7 % | 8 окт. 2021 г. |
39Наблюдать | CVE-2023-34433Эксплойта нет | PiiGAB M-Bus Use of Password Hash With Insufficient Computational Effortpiigab · m-bus 900s firmware · CWE-916 | Критическая9,8 | — | 0,4 % | 6 июл. 2023 г. |
39Наблюдать | CVE-2024-5743Эксплойта нет | Command Injection Vulnerabilityevehome · eve play · CWE-916 | Критическая9,8 | — | 0,4 % | 13 янв. 2025 г. |
39Наблюдать | CVE-2025-3937Эксплойта нет | Use of Password Hash with Insufficient Computational Efforttridium · niagara · CWE-916 | Критическая9,8 | — | 0,4 % | 22 мая 2025 г. |
39Наблюдать | CVE-2017-3962Эксплойта нет | McAfee Network Security Management (NSM) - Password recovery exploitation vulnerabilitymcafee · network security manager · CWE-916 | Критическая9,8 | — | 0,4 % | 12 июн. 2018 г. |
39Наблюдать | CVE-2023-5846Эксплойта нет | Use of Password Hash With Insufficient Computational Effort in Franklin Fueling System TS-550franklinfueling · ts-550 evo firmware · CWE-916 | Критическая9,8 | — | 0,3 % | 2 нояб. 2023 г. |
38Наблюдать | GHSA-3p7g-wrgg-wq45Эксплойта нет | GraphQL queries can expose password hashesPackagist · ibexa/graphql · CWE-916 | Критическая9,5 | — | — | 10 нояб. 2022 г. |
37Наблюдать | CVE-2026-85497Эксплойта нет | CareCam CM2507 Use of Password Hash With Insufficient Computational Effortcarecam · hmt.cm2507 firmware · CWE-916 | Критическая9,3 | — | 0,3 % | 18 сент. 2026 г. |
36Наблюдать | CVE-2019-19735Эксплойта нет | class.userpeer.php in MFScripts YetiShare 3.5.2 through 4.5.3 uses an insecure method of creating password reset hashes (based only on micromfscripts · yetishare · CWE-916 | Критическая9,1 | — | 0,8 % | 30 дек. 2019 г. |
35Наблюдать | CVE-2020-16231Эксплойта нет | All Bachmann M1 System Processor Modules - Use of Password Hash with Insufficient Computational Effortbachmann · mx207 firmware · CWE-916 | Высокая8,8 | — | 0,9 % | 19 мая 2022 г. |
34Наблюдать | CVE-2026-81704Эксплойта нет | openssl_encrypt before 1.4.9 Weak Key Derivation via D-Busjahlives · openssl encrypt · CWE-916 | Высокая8,7 | — | 0,3 % | 27 авг. 2026 г. |
34Наблюдать | CVE-2026-81689Эксплойта нет | openssl_encrypt before 1.4.9 Weak Pepper Key Derivationjahlives · openssl encrypt · CWE-916 | Высокая8,7 | — | 0,3 % | 27 авг. 2026 г. |
34Наблюдать | CVE-2026-55069Эксплойта нет | Kestra BasicAuth Password Stored as SHA-512 Enables Offline Brute-Force Attackkestra · kestra · CWE-916 | Высокая8,7 | — | 0,2 % | 26 июн. 2026 г. |
33Наблюдать | CVE-2023-33243Proof of concept | RedTeam Pentesting discovered that the web interface of STARFACE as well as its REST API allows authentication using the SHA512 hash of the starface · starface · CWE-916 | Высокая8,1 | — | 4,4 % | 15 июн. 2023 г. |
33Наблюдать | CVE-2024-3183Proof of concept | Freeipa: user can obtain a hash of the passwords of all domain users and perform offline brute forceredhat · enterprise linux · CWE-916 | Высокая8,1 | — | 2,1 % | 12 июн. 2024 г. |
32Наблюдать | CVE-2018-1447Эксплойта нет | The GSKit (IBM Spectrum Protect 7.1 and 7.2) and (IBM Spectrum Protect Snapshot 4.1.3, 4.1.4, and 4.1.6) CMS KDB logic fails to salt the hasibm · spectrum protect for space management · CWE-916 | Высокая8,1 | — | 0,9 % | 4 апр. 2018 г. |
32Наблюдать | CVE-2020-14389Эксплойта нет | It was found that Keycloak before version 12.0.0 would permit a user with only view-profile role to manage the resources in the new account redhat · keycloak · CWE-916 | Высокая8,1 | — | 0,8 % | 16 нояб. 2020 г. |
32Наблюдать | CVE-2022-1235Эксплойта нет | Weak secrethash can be brute-forced in livehelperchat/livehelperchatlivehelperchat · live helper chat · CWE-916 | Высокая8,2 | — | 0,6 % | 5 апр. 2022 г. |
32Наблюдать | CVE-2026-80211Эксплойта нет | FrontAccounting through 2.4.20 Use of Unsalted MD5 for Password Storagefrontaccounting · frontaccounting · CWE-916 | Высокая8,2 | — | 0,3 % | 27 авг. 2026 г. |
- CVE-2018-1061842В плане
Davolink DVW-3200N all version prior to Version 1.00.06.
КритическаяCVSS 9,8Proof of conceptEPSS 10 %davolink · dvw-3200n firmware1 авг. 2018 г.
- CVE-2020-1451641В плане
In Rockwell Automation FactoryTalk Services Platform Versions 6.10.00 and 6.11.00, there is an issue with the implementation of the SHA-256
КритическаяCVSS 10,0Эксплойта нетEPSS 4 %rockwellautomation · factorytalk services platform18 мар. 2021 г.
- CVE-2005-040840В плане
CitrusDB 0.3.6 and earlier generates easily predictable MD5 hashes of the user name for the id_hash cookie, which allows remote attackers to
КритическаяCVSS 9,8Proof of conceptEPSS 5 %citrusdb · citrusdb14 февр. 2005 г.
- CVE-2001-096739Наблюдать
Knox Arkeia server 4.2, and possibly other versions, uses a constant salt when encrypting passwords using the crypt() function, which makes
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %arkeia · arkeia31 авг. 2001 г.
- CVE-2018-1568039Наблюдать
An issue was discovered in BTITeam XBTIT 2.5.4.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %btiteam · xbtit5 сент. 2018 г.
- CVE-2019-1721639Наблюдать
An issue was discovered on V-Zug Combi-Steam MSLQ devices before Ethernet R07 and before WLAN R05.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %vzug · combi-stream mslq firmware6 окт. 2019 г.
- CVE-2021-3676739Наблюдать
In Digi RealPort through 4.10.490, authentication relies on a challenge-response mechanism that gives access to the server password, making
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %digi · realport8 окт. 2021 г.
- CVE-2023-3443339Наблюдать
PiiGAB M-Bus Use of Password Hash With Insufficient Computational Effort
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %piigab · m-bus 900s firmware6 июл. 2023 г.
- CVE-2024-574339Наблюдать
Command Injection Vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %evehome · eve play13 янв. 2025 г.
- CVE-2025-393739Наблюдать
Use of Password Hash with Insufficient Computational Effort
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %tridium · niagara22 мая 2025 г.
- CVE-2017-396239Наблюдать
McAfee Network Security Management (NSM) - Password recovery exploitation vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %mcafee · network security manager12 июн. 2018 г.
- CVE-2023-584639Наблюдать
Use of Password Hash With Insufficient Computational Effort in Franklin Fueling System TS-550
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %franklinfueling · ts-550 evo firmware2 нояб. 2023 г.
- GHSA-3p7g-wrgg-wq4538Наблюдать
GraphQL queries can expose password hashes
КритическаяCVSS 9,5Эксплойта нетPackagist · ibexa/graphql10 нояб. 2022 г.
- CVE-2026-8549737Наблюдать
CareCam CM2507 Use of Password Hash With Insufficient Computational Effort
КритическаяCVSS 9,3Эксплойта нетEPSS 0 %carecam · hmt.cm2507 firmware18 сент. 2026 г.
- CVE-2019-1973536Наблюдать
class.userpeer.php in MFScripts YetiShare 3.5.2 through 4.5.3 uses an insecure method of creating password reset hashes (based only on micro
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %mfscripts · yetishare30 дек. 2019 г.
- CVE-2020-1623135Наблюдать
All Bachmann M1 System Processor Modules - Use of Password Hash with Insufficient Computational Effort
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %bachmann · mx207 firmware19 мая 2022 г.
- CVE-2026-8170434Наблюдать
openssl_encrypt before 1.4.9 Weak Key Derivation via D-Bus
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %jahlives · openssl encrypt27 авг. 2026 г.
- CVE-2026-8168934Наблюдать
openssl_encrypt before 1.4.9 Weak Pepper Key Derivation
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %jahlives · openssl encrypt27 авг. 2026 г.
- CVE-2026-5506934Наблюдать
Kestra BasicAuth Password Stored as SHA-512 Enables Offline Brute-Force Attack
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %kestra · kestra26 июн. 2026 г.
- CVE-2023-3324333Наблюдать
RedTeam Pentesting discovered that the web interface of STARFACE as well as its REST API allows authentication using the SHA512 hash of the
ВысокаяCVSS 8,1Proof of conceptEPSS 4 %starface · starface15 июн. 2023 г.
- CVE-2024-318333Наблюдать
Freeipa: user can obtain a hash of the passwords of all domain users and perform offline brute force
ВысокаяCVSS 8,1Proof of conceptEPSS 2 %redhat · enterprise linux12 июн. 2024 г.
- CVE-2018-144732Наблюдать
The GSKit (IBM Spectrum Protect 7.1 and 7.2) and (IBM Spectrum Protect Snapshot 4.1.3, 4.1.4, and 4.1.6) CMS KDB logic fails to salt the has
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %ibm · spectrum protect for space management4 апр. 2018 г.
- CVE-2020-1438932Наблюдать
It was found that Keycloak before version 12.0.0 would permit a user with only view-profile role to manage the resources in the new account
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %redhat · keycloak16 нояб. 2020 г.
- CVE-2022-123532Наблюдать
Weak secrethash can be brute-forced in livehelperchat/livehelperchat
ВысокаяCVSS 8,2Эксплойта нетEPSS 1 %livehelperchat · live helper chat5 апр. 2022 г.
- CVE-2026-8021132Наблюдать
FrontAccounting through 2.4.20 Use of Unsalted MD5 for Password Storage
ВысокаяCVSS 8,2Эксплойта нетEPSS 0 %frontaccounting · frontaccounting27 авг. 2026 г.