Перейти к содержимому
Noroxi

CWE-916 · 108 записей

Use of Password Hash With Insufficient Computational Effort

CVE этого класса

108 записей

  • CVE-2018-10618
    42В плане

    Davolink DVW-3200N all version prior to Version 1.00.06.

    КритическаяCVSS 9,8Proof of conceptEPSS 10 %

    davolink · dvw-3200n firmware1 авг. 2018 г.

  • CVE-2020-14516
    41В плане

    In Rockwell Automation FactoryTalk Services Platform Versions 6.10.00 and 6.11.00, there is an issue with the implementation of the SHA-256

    КритическаяCVSS 10,0Эксплойта нетEPSS 4 %

    rockwellautomation · factorytalk services platform18 мар. 2021 г.

  • CVE-2005-0408
    40В плане

    CitrusDB 0.3.6 and earlier generates easily predictable MD5 hashes of the user name for the id_hash cookie, which allows remote attackers to

    КритическаяCVSS 9,8Proof of conceptEPSS 5 %

    citrusdb · citrusdb14 февр. 2005 г.

  • CVE-2001-0967
    39Наблюдать

    Knox Arkeia server 4.2, and possibly other versions, uses a constant salt when encrypting passwords using the crypt() function, which makes

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    arkeia · arkeia31 авг. 2001 г.

  • CVE-2018-15680
    39Наблюдать

    An issue was discovered in BTITeam XBTIT 2.5.4.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    btiteam · xbtit5 сент. 2018 г.

  • CVE-2019-17216
    39Наблюдать

    An issue was discovered on V-Zug Combi-Steam MSLQ devices before Ethernet R07 and before WLAN R05.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    vzug · combi-stream mslq firmware6 окт. 2019 г.

  • CVE-2021-36767
    39Наблюдать

    In Digi RealPort through 4.10.490, authentication relies on a challenge-response mechanism that gives access to the server password, making

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    digi · realport8 окт. 2021 г.

  • CVE-2023-34433
    39Наблюдать

    PiiGAB M-Bus Use of Password Hash With Insufficient Computational Effort

    КритическаяCVSS 9,8Эксплойта нетEPSS 0 %

    piigab · m-bus 900s firmware6 июл. 2023 г.

  • CVE-2024-5743
    39Наблюдать

    Command Injection Vulnerability

    КритическаяCVSS 9,8Эксплойта нетEPSS 0 %

    evehome · eve play13 янв. 2025 г.

  • CVE-2025-3937
    39Наблюдать

    Use of Password Hash with Insufficient Computational Effort

    КритическаяCVSS 9,8Эксплойта нетEPSS 0 %

    tridium · niagara22 мая 2025 г.

  • CVE-2017-3962
    39Наблюдать

    McAfee Network Security Management (NSM) - Password recovery exploitation vulnerability

    КритическаяCVSS 9,8Эксплойта нетEPSS 0 %

    mcafee · network security manager12 июн. 2018 г.

  • CVE-2023-5846
    39Наблюдать

    Use of Password Hash With Insufficient Computational Effort in Franklin Fueling System TS-550

    КритическаяCVSS 9,8Эксплойта нетEPSS 0 %

    franklinfueling · ts-550 evo firmware2 нояб. 2023 г.

  • GHSA-3p7g-wrgg-wq45
    38Наблюдать

    GraphQL queries can expose password hashes

    КритическаяCVSS 9,5Эксплойта нет

    Packagist · ibexa/graphql10 нояб. 2022 г.

  • CVE-2026-85497
    37Наблюдать

    CareCam CM2507 Use of Password Hash With Insufficient Computational Effort

    КритическаяCVSS 9,3Эксплойта нетEPSS 0 %

    carecam · hmt.cm2507 firmware18 сент. 2026 г.

  • CVE-2019-19735
    36Наблюдать

    class.userpeer.php in MFScripts YetiShare 3.5.2 through 4.5.3 uses an insecure method of creating password reset hashes (based only on micro

    КритическаяCVSS 9,1Эксплойта нетEPSS 1 %

    mfscripts · yetishare30 дек. 2019 г.

  • CVE-2020-16231
    35Наблюдать

    All Bachmann M1 System Processor Modules - Use of Password Hash with Insufficient Computational Effort

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    bachmann · mx207 firmware19 мая 2022 г.

  • CVE-2026-81704
    34Наблюдать

    openssl_encrypt before 1.4.9 Weak Key Derivation via D-Bus

    ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %

    jahlives · openssl encrypt27 авг. 2026 г.

  • CVE-2026-81689
    34Наблюдать

    openssl_encrypt before 1.4.9 Weak Pepper Key Derivation

    ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %

    jahlives · openssl encrypt27 авг. 2026 г.

  • CVE-2026-55069
    34Наблюдать

    Kestra BasicAuth Password Stored as SHA-512 Enables Offline Brute-Force Attack

    ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %

    kestra · kestra26 июн. 2026 г.

  • CVE-2023-33243
    33Наблюдать

    RedTeam Pentesting discovered that the web interface of STARFACE as well as its REST API allows authentication using the SHA512 hash of the

    ВысокаяCVSS 8,1Proof of conceptEPSS 4 %

    starface · starface15 июн. 2023 г.

  • CVE-2024-3183
    33Наблюдать

    Freeipa: user can obtain a hash of the passwords of all domain users and perform offline brute force

    ВысокаяCVSS 8,1Proof of conceptEPSS 2 %

    redhat · enterprise linux12 июн. 2024 г.

  • CVE-2018-1447
    32Наблюдать

    The GSKit (IBM Spectrum Protect 7.1 and 7.2) and (IBM Spectrum Protect Snapshot 4.1.3, 4.1.4, and 4.1.6) CMS KDB logic fails to salt the has

    ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %

    ibm · spectrum protect for space management4 апр. 2018 г.

  • CVE-2020-14389
    32Наблюдать

    It was found that Keycloak before version 12.0.0 would permit a user with only view-profile role to manage the resources in the new account

    ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %

    redhat · keycloak16 нояб. 2020 г.

  • CVE-2022-1235
    32Наблюдать

    Weak secrethash can be brute-forced in livehelperchat/livehelperchat

    ВысокаяCVSS 8,2Эксплойта нетEPSS 1 %

    livehelperchat · live helper chat5 апр. 2022 г.

  • CVE-2026-80211
    32Наблюдать

    FrontAccounting through 2.4.20 Use of Unsalted MD5 for Password Storage

    ВысокаяCVSS 8,2Эксплойта нетEPSS 0 %

    frontaccounting · frontaccounting27 авг. 2026 г.

Все классы уязвимостей