CWE-916 · 106 kayıt
Use of Password Hash With Insufficient Computational Effort
Bu sınıftaki CVE’ler
106 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
42Planlayın | CVE-2018-10618Kavram kanıtı | Davolink DVW-3200N all version prior to Version 1.00.06.davolink · dvw-3200n firmware · CWE-916 | Kritik9,8 | — | %10,1 | 1 Ağu 2018 |
41Planlayın | CVE-2020-14516İstismar yok | In Rockwell Automation FactoryTalk Services Platform Versions 6.10.00 and 6.11.00, there is an issue with the implementation of the SHA-256 rockwellautomation · factorytalk services platform · CWE-916 | Kritik10,0 | — | %4,1 | 18 Mar 2021 |
40Planlayın | CVE-2005-0408Kavram kanıtı | CitrusDB 0.3.6 and earlier generates easily predictable MD5 hashes of the user name for the id_hash cookie, which allows remote attackers tocitrusdb · citrusdb · CWE-916 | Kritik9,8 | — | %4,7 | 14 Şub 2005 |
39İzleyin | CVE-2001-0967İstismar yok | Knox Arkeia server 4.2, and possibly other versions, uses a constant salt when encrypting passwords using the crypt() function, which makes arkeia · arkeia · CWE-916 | Kritik9,8 | — | %1,0 | 31 Ağu 2001 |
39İzleyin | CVE-2018-15680İstismar yok | An issue was discovered in BTITeam XBTIT 2.5.4.btiteam · xbtit · CWE-916 | Kritik9,8 | — | %0,8 | 5 Eyl 2018 |
39İzleyin | CVE-2019-17216İstismar yok | An issue was discovered on V-Zug Combi-Steam MSLQ devices before Ethernet R07 and before WLAN R05.vzug · combi-stream mslq firmware · CWE-916 | Kritik9,8 | — | %0,7 | 6 Eki 2019 |
39İzleyin | CVE-2021-36767İstismar yok | In Digi RealPort through 4.10.490, authentication relies on a challenge-response mechanism that gives access to the server password, making digi · realport · CWE-916 | Kritik9,8 | — | %0,7 | 8 Eki 2021 |
39İzleyin | CVE-2023-34433İstismar yok | PiiGAB M-Bus Use of Password Hash With Insufficient Computational Effortpiigab · m-bus 900s firmware · CWE-916 | Kritik9,8 | — | %0,4 | 6 Tem 2023 |
39İzleyin | CVE-2024-5743İstismar yok | Command Injection Vulnerabilityevehome · eve play · CWE-916 | Kritik9,8 | — | %0,4 | 13 Oca 2025 |
39İzleyin | CVE-2025-3937İstismar yok | Use of Password Hash with Insufficient Computational Efforttridium · niagara · CWE-916 | Kritik9,8 | — | %0,4 | 22 May 2025 |
39İzleyin | CVE-2017-3962İstismar yok | McAfee Network Security Management (NSM) - Password recovery exploitation vulnerabilitymcafee · network security manager · CWE-916 | Kritik9,8 | — | %0,4 | 12 Haz 2018 |
39İzleyin | CVE-2023-5846İstismar yok | Use of Password Hash With Insufficient Computational Effort in Franklin Fueling System TS-550franklinfueling · ts-550 evo firmware · CWE-916 | Kritik9,8 | — | %0,3 | 2 Kas 2023 |
38İzleyin | GHSA-3p7g-wrgg-wq45İstismar yok | GraphQL queries can expose password hashesPackagist · ibexa/graphql · CWE-916 | Kritik9,5 | — | — | 10 Kas 2022 |
37İzleyin | CVE-2026-85497İstismar yok | CareCam CM2507 Use of Password Hash With Insufficient Computational Effortcarecam · hmt.cm2507 firmware · CWE-916 | Kritik9,3 | — | %0,3 | 18 Eyl 2026 |
36İzleyin | CVE-2019-19735İstismar yok | class.userpeer.php in MFScripts YetiShare 3.5.2 through 4.5.3 uses an insecure method of creating password reset hashes (based only on micromfscripts · yetishare · CWE-916 | Kritik9,1 | — | %0,8 | 30 Ara 2019 |
35İzleyin | CVE-2020-16231İstismar yok | All Bachmann M1 System Processor Modules - Use of Password Hash with Insufficient Computational Effortbachmann · mx207 firmware · CWE-916 | Yüksek8,8 | — | %0,9 | 19 May 2022 |
34İzleyin | CVE-2026-81689İstismar yok | openssl_encrypt before 1.4.9 Weak Pepper Key Derivationjahlives · openssl encrypt · CWE-916 | Yüksek8,7 | — | %0,3 | 27 Ağu 2026 |
34İzleyin | CVE-2026-81704İstismar yok | openssl_encrypt before 1.4.9 Weak Key Derivation via D-Busjahlives · openssl encrypt · CWE-916 | Yüksek8,7 | — | %0,3 | 27 Ağu 2026 |
34İzleyin | CVE-2026-55069İstismar yok | Kestra BasicAuth Password Stored as SHA-512 Enables Offline Brute-Force Attackkestra · kestra · CWE-916 | Yüksek8,7 | — | %0,2 | 26 Haz 2026 |
33İzleyin | CVE-2023-33243Kavram kanıtı | RedTeam Pentesting discovered that the web interface of STARFACE as well as its REST API allows authentication using the SHA512 hash of the starface · starface · CWE-916 | Yüksek8,1 | — | %4,4 | 15 Haz 2023 |
33İzleyin | CVE-2024-3183Kavram kanıtı | Freeipa: user can obtain a hash of the passwords of all domain users and perform offline brute forceredhat · enterprise linux · CWE-916 | Yüksek8,1 | — | %2,1 | 12 Haz 2024 |
32İzleyin | CVE-2018-1447İstismar yok | The GSKit (IBM Spectrum Protect 7.1 and 7.2) and (IBM Spectrum Protect Snapshot 4.1.3, 4.1.4, and 4.1.6) CMS KDB logic fails to salt the hasibm · spectrum protect for space management · CWE-916 | Yüksek8,1 | — | %0,9 | 4 Nis 2018 |
32İzleyin | CVE-2020-14389İstismar yok | It was found that Keycloak before version 12.0.0 would permit a user with only view-profile role to manage the resources in the new account redhat · keycloak · CWE-916 | Yüksek8,1 | — | %0,8 | 16 Kas 2020 |
32İzleyin | CVE-2022-1235İstismar yok | Weak secrethash can be brute-forced in livehelperchat/livehelperchatlivehelperchat · live helper chat · CWE-916 | Yüksek8,2 | — | %0,6 | 5 Nis 2022 |
32İzleyin | CVE-2026-80211İstismar yok | FrontAccounting through 2.4.20 Use of Unsalted MD5 for Password Storagefrontaccounting · frontaccounting · CWE-916 | Yüksek8,2 | — | %0,3 | 27 Ağu 2026 |
- CVE-2018-1061842Planlayın
Davolink DVW-3200N all version prior to Version 1.00.06.
KritikCVSS 9,8Kavram kanıtıEPSS %10davolink · dvw-3200n firmware1 Ağu 2018
- CVE-2020-1451641Planlayın
In Rockwell Automation FactoryTalk Services Platform Versions 6.10.00 and 6.11.00, there is an issue with the implementation of the SHA-256
KritikCVSS 10,0İstismar yokEPSS %4rockwellautomation · factorytalk services platform18 Mar 2021
- CVE-2005-040840Planlayın
CitrusDB 0.3.6 and earlier generates easily predictable MD5 hashes of the user name for the id_hash cookie, which allows remote attackers to
KritikCVSS 9,8Kavram kanıtıEPSS %5citrusdb · citrusdb14 Şub 2005
- CVE-2001-096739İzleyin
Knox Arkeia server 4.2, and possibly other versions, uses a constant salt when encrypting passwords using the crypt() function, which makes
KritikCVSS 9,8İstismar yokEPSS %1arkeia · arkeia31 Ağu 2001
- CVE-2018-1568039İzleyin
An issue was discovered in BTITeam XBTIT 2.5.4.
KritikCVSS 9,8İstismar yokEPSS %1btiteam · xbtit5 Eyl 2018
- CVE-2019-1721639İzleyin
An issue was discovered on V-Zug Combi-Steam MSLQ devices before Ethernet R07 and before WLAN R05.
KritikCVSS 9,8İstismar yokEPSS %1vzug · combi-stream mslq firmware6 Eki 2019
- CVE-2021-3676739İzleyin
In Digi RealPort through 4.10.490, authentication relies on a challenge-response mechanism that gives access to the server password, making
KritikCVSS 9,8İstismar yokEPSS %1digi · realport8 Eki 2021
- CVE-2023-3443339İzleyin
PiiGAB M-Bus Use of Password Hash With Insufficient Computational Effort
KritikCVSS 9,8İstismar yokEPSS %0piigab · m-bus 900s firmware6 Tem 2023
- CVE-2024-574339İzleyin
Command Injection Vulnerability
KritikCVSS 9,8İstismar yokEPSS %0evehome · eve play13 Oca 2025
- CVE-2025-393739İzleyin
Use of Password Hash with Insufficient Computational Effort
KritikCVSS 9,8İstismar yokEPSS %0tridium · niagara22 May 2025
- CVE-2017-396239İzleyin
McAfee Network Security Management (NSM) - Password recovery exploitation vulnerability
KritikCVSS 9,8İstismar yokEPSS %0mcafee · network security manager12 Haz 2018
- CVE-2023-584639İzleyin
Use of Password Hash With Insufficient Computational Effort in Franklin Fueling System TS-550
KritikCVSS 9,8İstismar yokEPSS %0franklinfueling · ts-550 evo firmware2 Kas 2023
- GHSA-3p7g-wrgg-wq4538İzleyin
GraphQL queries can expose password hashes
KritikCVSS 9,5İstismar yokPackagist · ibexa/graphql10 Kas 2022
- CVE-2026-8549737İzleyin
CareCam CM2507 Use of Password Hash With Insufficient Computational Effort
KritikCVSS 9,3İstismar yokEPSS %0carecam · hmt.cm2507 firmware18 Eyl 2026
- CVE-2019-1973536İzleyin
class.userpeer.php in MFScripts YetiShare 3.5.2 through 4.5.3 uses an insecure method of creating password reset hashes (based only on micro
KritikCVSS 9,1İstismar yokEPSS %1mfscripts · yetishare30 Ara 2019
- CVE-2020-1623135İzleyin
All Bachmann M1 System Processor Modules - Use of Password Hash with Insufficient Computational Effort
YüksekCVSS 8,8İstismar yokEPSS %1bachmann · mx207 firmware19 May 2022
- CVE-2026-8168934İzleyin
openssl_encrypt before 1.4.9 Weak Pepper Key Derivation
YüksekCVSS 8,7İstismar yokEPSS %0jahlives · openssl encrypt27 Ağu 2026
- CVE-2026-8170434İzleyin
openssl_encrypt before 1.4.9 Weak Key Derivation via D-Bus
YüksekCVSS 8,7İstismar yokEPSS %0jahlives · openssl encrypt27 Ağu 2026
- CVE-2026-5506934İzleyin
Kestra BasicAuth Password Stored as SHA-512 Enables Offline Brute-Force Attack
YüksekCVSS 8,7İstismar yokEPSS %0kestra · kestra26 Haz 2026
- CVE-2023-3324333İzleyin
RedTeam Pentesting discovered that the web interface of STARFACE as well as its REST API allows authentication using the SHA512 hash of the
YüksekCVSS 8,1Kavram kanıtıEPSS %4starface · starface15 Haz 2023
- CVE-2024-318333İzleyin
Freeipa: user can obtain a hash of the passwords of all domain users and perform offline brute force
YüksekCVSS 8,1Kavram kanıtıEPSS %2redhat · enterprise linux12 Haz 2024
- CVE-2018-144732İzleyin
The GSKit (IBM Spectrum Protect 7.1 and 7.2) and (IBM Spectrum Protect Snapshot 4.1.3, 4.1.4, and 4.1.6) CMS KDB logic fails to salt the has
YüksekCVSS 8,1İstismar yokEPSS %1ibm · spectrum protect for space management4 Nis 2018
- CVE-2020-1438932İzleyin
It was found that Keycloak before version 12.0.0 would permit a user with only view-profile role to manage the resources in the new account
YüksekCVSS 8,1İstismar yokEPSS %1redhat · keycloak16 Kas 2020
- CVE-2022-123532İzleyin
Weak secrethash can be brute-forced in livehelperchat/livehelperchat
YüksekCVSS 8,2İstismar yokEPSS %1livehelperchat · live helper chat5 Nis 2022
- CVE-2026-8021132İzleyin
FrontAccounting through 2.4.20 Use of Unsalted MD5 for Password Storage
YüksekCVSS 8,2İstismar yokEPSS %0frontaccounting · frontaccounting27 Ağu 2026