İçeriğe atla
Noroxi

CWE-916 · 106 kayıt

Use of Password Hash With Insufficient Computational Effort

Bu sınıftaki CVE’ler

106 kayıt

  • CVE-2018-10618
    42Planlayın

    Davolink DVW-3200N all version prior to Version 1.00.06.

    KritikCVSS 9,8Kavram kanıtıEPSS %10

    davolink · dvw-3200n firmware1 Ağu 2018

  • CVE-2020-14516
    41Planlayın

    In Rockwell Automation FactoryTalk Services Platform Versions 6.10.00 and 6.11.00, there is an issue with the implementation of the SHA-256

    KritikCVSS 10,0İstismar yokEPSS %4

    rockwellautomation · factorytalk services platform18 Mar 2021

  • CVE-2005-0408
    40Planlayın

    CitrusDB 0.3.6 and earlier generates easily predictable MD5 hashes of the user name for the id_hash cookie, which allows remote attackers to

    KritikCVSS 9,8Kavram kanıtıEPSS %5

    citrusdb · citrusdb14 Şub 2005

  • CVE-2001-0967
    39İzleyin

    Knox Arkeia server 4.2, and possibly other versions, uses a constant salt when encrypting passwords using the crypt() function, which makes

    KritikCVSS 9,8İstismar yokEPSS %1

    arkeia · arkeia31 Ağu 2001

  • CVE-2018-15680
    39İzleyin

    An issue was discovered in BTITeam XBTIT 2.5.4.

    KritikCVSS 9,8İstismar yokEPSS %1

    btiteam · xbtit5 Eyl 2018

  • CVE-2019-17216
    39İzleyin

    An issue was discovered on V-Zug Combi-Steam MSLQ devices before Ethernet R07 and before WLAN R05.

    KritikCVSS 9,8İstismar yokEPSS %1

    vzug · combi-stream mslq firmware6 Eki 2019

  • CVE-2021-36767
    39İzleyin

    In Digi RealPort through 4.10.490, authentication relies on a challenge-response mechanism that gives access to the server password, making

    KritikCVSS 9,8İstismar yokEPSS %1

    digi · realport8 Eki 2021

  • CVE-2023-34433
    39İzleyin

    PiiGAB M-Bus Use of Password Hash With Insufficient Computational Effort

    KritikCVSS 9,8İstismar yokEPSS %0

    piigab · m-bus 900s firmware6 Tem 2023

  • CVE-2024-5743
    39İzleyin

    Command Injection Vulnerability

    KritikCVSS 9,8İstismar yokEPSS %0

    evehome · eve play13 Oca 2025

  • CVE-2025-3937
    39İzleyin

    Use of Password Hash with Insufficient Computational Effort

    KritikCVSS 9,8İstismar yokEPSS %0

    tridium · niagara22 May 2025

  • CVE-2017-3962
    39İzleyin

    McAfee Network Security Management (NSM) - Password recovery exploitation vulnerability

    KritikCVSS 9,8İstismar yokEPSS %0

    mcafee · network security manager12 Haz 2018

  • CVE-2023-5846
    39İzleyin

    Use of Password Hash With Insufficient Computational Effort in Franklin Fueling System TS-550

    KritikCVSS 9,8İstismar yokEPSS %0

    franklinfueling · ts-550 evo firmware2 Kas 2023

  • GraphQL queries can expose password hashes

    KritikCVSS 9,5İstismar yok

    Packagist · ibexa/graphql10 Kas 2022

  • CVE-2026-85497
    37İzleyin

    CareCam CM2507 Use of Password Hash With Insufficient Computational Effort

    KritikCVSS 9,3İstismar yokEPSS %0

    carecam · hmt.cm2507 firmware18 Eyl 2026

  • CVE-2019-19735
    36İzleyin

    class.userpeer.php in MFScripts YetiShare 3.5.2 through 4.5.3 uses an insecure method of creating password reset hashes (based only on micro

    KritikCVSS 9,1İstismar yokEPSS %1

    mfscripts · yetishare30 Ara 2019

  • CVE-2020-16231
    35İzleyin

    All Bachmann M1 System Processor Modules - Use of Password Hash with Insufficient Computational Effort

    YüksekCVSS 8,8İstismar yokEPSS %1

    bachmann · mx207 firmware19 May 2022

  • CVE-2026-81689
    34İzleyin

    openssl_encrypt before 1.4.9 Weak Pepper Key Derivation

    YüksekCVSS 8,7İstismar yokEPSS %0

    jahlives · openssl encrypt27 Ağu 2026

  • CVE-2026-81704
    34İzleyin

    openssl_encrypt before 1.4.9 Weak Key Derivation via D-Bus

    YüksekCVSS 8,7İstismar yokEPSS %0

    jahlives · openssl encrypt27 Ağu 2026

  • CVE-2026-55069
    34İzleyin

    Kestra BasicAuth Password Stored as SHA-512 Enables Offline Brute-Force Attack

    YüksekCVSS 8,7İstismar yokEPSS %0

    kestra · kestra26 Haz 2026

  • CVE-2023-33243
    33İzleyin

    RedTeam Pentesting discovered that the web interface of STARFACE as well as its REST API allows authentication using the SHA512 hash of the

    YüksekCVSS 8,1Kavram kanıtıEPSS %4

    starface · starface15 Haz 2023

  • CVE-2024-3183
    33İzleyin

    Freeipa: user can obtain a hash of the passwords of all domain users and perform offline brute force

    YüksekCVSS 8,1Kavram kanıtıEPSS %2

    redhat · enterprise linux12 Haz 2024

  • CVE-2018-1447
    32İzleyin

    The GSKit (IBM Spectrum Protect 7.1 and 7.2) and (IBM Spectrum Protect Snapshot 4.1.3, 4.1.4, and 4.1.6) CMS KDB logic fails to salt the has

    YüksekCVSS 8,1İstismar yokEPSS %1

    ibm · spectrum protect for space management4 Nis 2018

  • CVE-2020-14389
    32İzleyin

    It was found that Keycloak before version 12.0.0 would permit a user with only view-profile role to manage the resources in the new account

    YüksekCVSS 8,1İstismar yokEPSS %1

    redhat · keycloak16 Kas 2020

  • CVE-2022-1235
    32İzleyin

    Weak secrethash can be brute-forced in livehelperchat/livehelperchat

    YüksekCVSS 8,2İstismar yokEPSS %1

    livehelperchat · live helper chat5 Nis 2022

  • CVE-2026-80211
    32İzleyin

    FrontAccounting through 2.4.20 Use of Unsalted MD5 for Password Storage

    YüksekCVSS 8,2İstismar yokEPSS %0

    frontaccounting · frontaccounting27 Ağu 2026

Tüm zafiyet sınıfları