The product uses an algorithm that produces a digest (output value) that does not meet security expectations for a hash function that allows an adversary to reasonably determine the original input (preimage attack), find another input that can produce the same hash (2nd preimage attack), or find multiple inputs that evaluate to the same hash (birthday attack).
56 vulnerabilities with CWE-328
CVE-2026-7103
LOW
code-projects Chat System MD5 Hash update_user.php weak hash
CVSS 3.7
CVE-2026-40164
HIGH
jq: Algorithmic complexity DoS via hardcoded MurmurHash3 seed
CVSS 7.5
CVE-2026-32129
HIGH
soroban-poseidon - Hash Collision
CVE-2026-27754
MEDIUM
SODOLA SL902-SWTGW124AS Firmware <200.1.20 - Auth Bypass
CVSS 6.5
CVE-2025-41762
MEDIUM
wwwdnload.cgi - Info Disclosure
CVSS 6.2
CVE-2025-14636
LOW
Tenda AX9 22.03.01.46 - Weak Hash
CVSS 3.7
CVE-2025-11650
LOW
Furbo Mini Firmware < 074 - Broken Cryptographic Algorithm
CVSS 1.8
CVE-2025-59354
MEDIUM
Dragonfly <2.1.0 - Info Disclosure
CVSS 5.3
CVE-2025-9078
MEDIUM
Mattermost <10.8.4 - Info Disclosure
CVSS 4.3
CVE-2025-55053
MEDIUM
Weak Hash - Info Disclosure
CVSS 6.5
CVE-2025-9383
LOW
FNKvision Y215 CCTV Camera - Weak Hash
CVSS 2.5
CVE-2025-54535
MEDIUM
JetBrains TeamCity <2025.07 - Info Disclosure
CVSS 5.8
CVE-2025-8260
LOW
Vaelsys - Broken Cryptographic Algorithm
CVSS 3.1
CVE-2025-41256
HIGH
Cyberduck <9.1.6 - Mountain Duck <4.17.5 - TLS Pinning Weakness
CVSS 7.4
CVE-2025-49197
MEDIUM
FTP App - Info Disclosure
CVSS 6.5
CVE-2025-48931
LOW
TeleMessage <2025-05-05 - Info Disclosure
CVSS 3.2
CVE-2025-41652
CRITICAL
Devices - Auth Bypass
CVSS 9.8
CVE-2025-47276
HIGH
Actualizer <1.2.0 - Info Disclosure
CVSS 7.5
CVE-2025-3576
MEDIUM
MIT Kerberos - Info Disclosure
CVSS 5.9
CVE-2025-31130
MEDIUM
gitoxide <0.42.0 - Info Disclosure
CVSS 6.8
CVE-2025-2920
LOW
Netis WF-2404 1.1.124EN - Weak Hash
CVSS 2.0
CVE-2025-0508
MEDIUM
SageMaker Workflow - Info Disclosure
CVSS 5.9
CVE-2025-26486
MEDIUM
Beta80 Life 1st Identity Mgr <1.5.2.142 - Info Disclosure
CVSS 6.0
CVE-2025-27595
CRITICAL
Device - Info Disclosure
CVSS 9.8
CVE-2025-21604
MEDIUM
LangChain4j-AIDeepin <3.5.0 - Info Disclosure
Details
Vulnerabilities
56