CWE-328 · 61 kayıt
Use of Weak Hash
Bu sınıftaki CVE’ler
61 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2026-51996İstismar yok | An issue in geelen mcp-remote 0.1.16 through 0.1.38 allows a remote attacker to execute arbitrary code via the src/lib/utils.ts and the getSCWE-328 | Kritik9,8 | — | %0,8 | 6 gün önce |
39İzleyin | CVE-2025-27595İstismar yok | Weak hashing alghrythmsick ag · sick dl100-2xxxxxxx · CWE-328 | Kritik9,8 | — | %0,5 | 14 Mar 2025 |
39İzleyin | CVE-2025-41652İstismar yok | Weidmueller: Authentication Bypass Vulnerability in Industrial Ethernet Switchesweidmueller · ie-sw-vl05m-5tx · CWE-328 | Kritik9,8 | — | %0,5 | 27 May 2025 |
39İzleyin | CVE-2022-45141İstismar yok | Since the Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability was disclosed by Microsoft on Nov 8 2022 and per RFC8429 it is assusamba · samba · CWE-328 | Kritik9,8 | — | %0,5 | 6 Mar 2023 |
39İzleyin | CVE-2026-36182İstismar yok | GNCC GP5 v7.1.76 was discovered to utilize a weak hashing algorithm to protect the root password, possibly allowing attackers to obtain rootCWE-328 | Kritik9,8 | — | %0,3 | 4 Haz 2026 |
38İzleyin | CVE-2024-54143İstismar yok | openwrt/asu allows build artifact poisoning via truncated SHA-256 hash and command injectionopenwrt · asu · CWE-328 | Kritik9,3 | — | %1,8 | 6 Ara 2024 |
37İzleyin | CVE-2020-37168İstismar yok | Ecommerce Systempay 1.0 Production Key Brute Forcepaiement · ecommerce systempay · CWE-328 | Kritik9,3 | — | %0,2 | 13 May 2026 |
36İzleyin | CVE-2023-46233İstismar yok | crypto-js PBKDF2 1,000 times weaker than specified in 1993 and 1.3M times weaker than current standardcrypto-js project · crypto-js · CWE-328 | Kritik9,1 | — | %0,6 | 25 Eki 2023 |
36İzleyin | CVE-2023-46133İstismar yok | crypto-es PBKDF2 1,000 times weaker than specified in 1993 and 1.3M times weaker than current standardentronad · cryptoes · CWE-328 | Kritik9,1 | — | %0,4 | 25 Eki 2023 |
35İzleyin | CVE-2024-48847İstismar yok | MD5 bypass operationabb · aspect-ent-2 firmware · CWE-328 | Yüksek8,8 | — | %0,3 | 5 Ara 2024 |
35İzleyin | CVE-2026-54266İstismar yok | Angular: Weak 32-Bit Cache Key Hashing in `HttpTransferCache` Leading to Cross-Request Data Leakage and State Poisoningangular · angular · CWE-328 | Yüksek8,8 | — | %0,1 | 22 Haz 2026 |
35İzleyin | CVE-2023-43635İstismar yok | Vault Key Sealed With SHA1 PCRslinuxfoundation · edge virtualization engine · CWE-328 | Yüksek8,8 | — | %0,1 | 20 Eyl 2023 |
35İzleyin | CVE-2023-43630İstismar yok | Config Partition Not Measured From 2 Frontslinuxfoundation · edge virtualization engine · CWE-328 | Yüksek8,8 | — | %0,1 | 20 Eyl 2023 |
35İzleyin | GHSA-5jvg-8j6f-vpmcİstismar yok | Duplicate Advisory: EVE Doesn't Measure Config Partition From 2 FrontsGo · github.com/lf-edge/eve · CWE-328 | Yüksek8,8 | — | — | 20 Eyl 2023 |
34İzleyin | CVE-2024-48924İstismar yok | MessagePack allows untrusted data to lead to DoS attack due to hash collisions and stack overflowmessagepack-csharp · messagepack-csharp · CWE-328 | Yüksek8,7 | — | %0,4 | 17 Eki 2024 |
34İzleyin | CVE-2026-32129İstismar yok | Poseidon V1 variable-length input collision via implicit zero-paddingstellar · rs-soroban-poseidon · CWE-328 | Yüksek8,7 | — | %0,3 | 12 Mar 2026 |
32İzleyin | CVE-2026-41879İstismar yok | Weak password hashing in R-SOFT DMSr-soft serwis · dms · CWE-328 | Yüksek8,2 | — | %0,3 | 10 Tem 2026 |
31İzleyin | CVE-2019-13539İstismar yok | Medtronic Valleylab FT10 and FX8 Reversible One-way Hashmedtronic · valleylab exchange client · CWE-328 | Yüksek7,8 | — | %0,3 | 8 Kas 2019 |
30İzleyin | CVE-2023-2900İstismar yok | NFine Rapid Development Platform CheckLogin weak hashnfine rapid development platform project · nfine rapid development platform · CWE-328 | Yüksek7,5 | — | %0,7 | 25 May 2023 |
30İzleyin | CVE-2026-40164İstismar yok | jq: Algorithmic complexity DoS via hardcoded MurmurHash3 seedjqlang · jq · CWE-328 | Yüksek7,5 | — | %0,6 | 13 Nis 2026 |
30İzleyin | CVE-2025-49197İstismar yok | Deprecated TLS version supportedsick · media server · CWE-328 | Yüksek7,5 | — | %0,3 | 12 Haz 2025 |
30İzleyin | CVE-2025-47276İstismar yok | Actualizer Uses OpenSSL's "-passwd" Function Which Uses SHA512 Under The Hood Instead of Proper Password Hasher like Yescript/Argon2ichewkeanho · actualizer · CWE-328 | Yüksek7,5 | — | %0,3 | 13 May 2025 |
30İzleyin | CVE-2024-38341İstismar yok | IBM Sterling Secure Proxy information disclosureibm · sterling secure proxy · CWE-328 | Yüksek7,5 | — | %0,2 | 28 May 2025 |
30İzleyin | CVE-2024-47182İstismar yok | Dozzle uses unsafe hash for passwordsamirraminfar · dozzle · CWE-328 | Yüksek7,5 | — | %0,2 | 27 Eyl 2024 |
30İzleyin | CVE-2025-54535İstismar yok | In JetBrains TeamCity before 2025.07 password reset and email verification tokens were using weak hashing algorithmsjetbrains · teamcity · CWE-328 | Yüksek7,5 | — | %0,2 | 28 Tem 2025 |
- CVE-2026-5199639İzleyin
An issue in geelen mcp-remote 0.1.16 through 0.1.38 allows a remote attacker to execute arbitrary code via the src/lib/utils.ts and the getS
KritikCVSS 9,8İstismar yokEPSS %16 gün önce
- CVE-2025-2759539İzleyin
Weak hashing alghrythm
KritikCVSS 9,8İstismar yokEPSS %1sick ag · sick dl100-2xxxxxxx14 Mar 2025
- CVE-2025-4165239İzleyin
Weidmueller: Authentication Bypass Vulnerability in Industrial Ethernet Switches
KritikCVSS 9,8İstismar yokEPSS %0weidmueller · ie-sw-vl05m-5tx27 May 2025
- CVE-2022-4514139İzleyin
Since the Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability was disclosed by Microsoft on Nov 8 2022 and per RFC8429 it is assu
KritikCVSS 9,8İstismar yokEPSS %0samba · samba6 Mar 2023
- CVE-2026-3618239İzleyin
GNCC GP5 v7.1.76 was discovered to utilize a weak hashing algorithm to protect the root password, possibly allowing attackers to obtain root
KritikCVSS 9,8İstismar yokEPSS %04 Haz 2026
- CVE-2024-5414338İzleyin
openwrt/asu allows build artifact poisoning via truncated SHA-256 hash and command injection
KritikCVSS 9,3İstismar yokEPSS %2openwrt · asu6 Ara 2024
- CVE-2020-3716837İzleyin
Ecommerce Systempay 1.0 Production Key Brute Force
KritikCVSS 9,3İstismar yokEPSS %0paiement · ecommerce systempay13 May 2026
- CVE-2023-4623336İzleyin
crypto-js PBKDF2 1,000 times weaker than specified in 1993 and 1.3M times weaker than current standard
KritikCVSS 9,1İstismar yokEPSS %1crypto-js project · crypto-js25 Eki 2023
- CVE-2023-4613336İzleyin
crypto-es PBKDF2 1,000 times weaker than specified in 1993 and 1.3M times weaker than current standard
KritikCVSS 9,1İstismar yokEPSS %0entronad · cryptoes25 Eki 2023
- CVE-2024-4884735İzleyin
MD5 bypass operation
YüksekCVSS 8,8İstismar yokEPSS %0abb · aspect-ent-2 firmware5 Ara 2024
- CVE-2026-5426635İzleyin
Angular: Weak 32-Bit Cache Key Hashing in `HttpTransferCache` Leading to Cross-Request Data Leakage and State Poisoning
YüksekCVSS 8,8İstismar yokEPSS %0angular · angular22 Haz 2026
- CVE-2023-4363535İzleyin
Vault Key Sealed With SHA1 PCRs
YüksekCVSS 8,8İstismar yokEPSS %0linuxfoundation · edge virtualization engine20 Eyl 2023
- CVE-2023-4363035İzleyin
Config Partition Not Measured From 2 Fronts
YüksekCVSS 8,8İstismar yokEPSS %0linuxfoundation · edge virtualization engine20 Eyl 2023
- GHSA-5jvg-8j6f-vpmc35İzleyin
Duplicate Advisory: EVE Doesn't Measure Config Partition From 2 Fronts
YüksekCVSS 8,8İstismar yokGo · github.com/lf-edge/eve20 Eyl 2023
- CVE-2024-4892434İzleyin
MessagePack allows untrusted data to lead to DoS attack due to hash collisions and stack overflow
YüksekCVSS 8,7İstismar yokEPSS %0messagepack-csharp · messagepack-csharp17 Eki 2024
- CVE-2026-3212934İzleyin
Poseidon V1 variable-length input collision via implicit zero-padding
YüksekCVSS 8,7İstismar yokEPSS %0stellar · rs-soroban-poseidon12 Mar 2026
- CVE-2026-4187932İzleyin
Weak password hashing in R-SOFT DMS
YüksekCVSS 8,2İstismar yokEPSS %0r-soft serwis · dms10 Tem 2026
- CVE-2019-1353931İzleyin
Medtronic Valleylab FT10 and FX8 Reversible One-way Hash
YüksekCVSS 7,8İstismar yokEPSS %0medtronic · valleylab exchange client8 Kas 2019
- CVE-2023-290030İzleyin
NFine Rapid Development Platform CheckLogin weak hash
YüksekCVSS 7,5İstismar yokEPSS %1nfine rapid development platform project · nfine rapid development platform25 May 2023
- CVE-2026-4016430İzleyin
jq: Algorithmic complexity DoS via hardcoded MurmurHash3 seed
YüksekCVSS 7,5İstismar yokEPSS %1jqlang · jq13 Nis 2026
- CVE-2025-4919730İzleyin
Deprecated TLS version supported
YüksekCVSS 7,5İstismar yokEPSS %0sick · media server12 Haz 2025
- CVE-2025-4727630İzleyin
Actualizer Uses OpenSSL's "-passwd" Function Which Uses SHA512 Under The Hood Instead of Proper Password Hasher like Yescript/Argon2i
YüksekCVSS 7,5İstismar yokEPSS %0chewkeanho · actualizer13 May 2025
- CVE-2024-3834130İzleyin
IBM Sterling Secure Proxy information disclosure
YüksekCVSS 7,5İstismar yokEPSS %0ibm · sterling secure proxy28 May 2025
- CVE-2024-4718230İzleyin
Dozzle uses unsafe hash for passwords
YüksekCVSS 7,5İstismar yokEPSS %0amirraminfar · dozzle27 Eyl 2024
- CVE-2025-5453530İzleyin
In JetBrains TeamCity before 2025.07 password reset and email verification tokens were using weak hashing algorithms
YüksekCVSS 7,5İstismar yokEPSS %0jetbrains · teamcity28 Tem 2025