The product uses an algorithm that produces a digest (output value) that does not meet security expectations for a hash function that allows an adversary to reasonably determine the original input (preimage attack), find another input that can produce the same hash (2nd preimage attack), or find multiple inputs that evaluate to the same hash (birthday attack).
90 vulnerabilities with CWE-328
CVE-2026-10766
LOW
mlrun DataFrame Hash helpers.py mlrun.utils.helpers.calculate_dataframe_hash weak hash
CVSS 3.6
CVE-2026-45413
MEDIUM
MaxKB: Unsalted MD5 Password Hashing
CVE-2026-8803
LOW
opensourcepos Open Source Point of Sale Employee Login Employee.php login weak hash
CVSS 3.7
CVE-2026-44582
LOW
Next.js: Cache poisoning via collisions in React Server Component cache-busting
CVSS 3.7
CVE-2026-34527
MEDIUM
Sandboxie-Plus EditPassword hash entropy reduced from 160 bits to 80 bits due to incorrect nibble extraction
CVSS 5.3
CVE-2026-7845
LOW
chatchat-space Langchain-Chatchat Vision Chat Paste Image dialogue.py PIL.Image.tobytes weak hash
CVSS 2.6
CVE-2026-7103
LOW
code-projects Chat System MD5 Hash update_user.php weak hash
CVSS 3.7
CVE-2026-40164
HIGH
jq: Algorithmic complexity DoS via hardcoded MurmurHash3 seed
CVSS 7.5
CVE-2026-21717
MEDIUM
Node.js 20.x 22.x 24.x 25.x - Denial of Service via V8 String Hash Collision
CVSS 5.9
CVE-2026-32129
HIGH
soroban-poseidon < 25.0.1 - Hash Collision via Implicit Zero-Filling in PoseidonSponge
CVE-2026-27754
MEDIUM
SODOLA SL902-SWTGW124AS Firmware <200.1.20 - Auth Bypass
CVSS 6.5
CVE-2025-41762
MEDIUM
MBS Solutions Universal BACnet Router Firmware < 6.0.1.0 - Unauthenticated Sensitive Data Exposure via Weak Backup Hash
CVSS 6.2
CVE-2025-14636
LOW
Tenda AX9 22.03.01.46 - Use of Weak Hash in httpd image_check Function
CVSS 3.7
CVE-2025-11650
LOW
Furbo 360 Dog Camera Firmware < 036 and Furbo Mini Firmware < 074 - Use of Weak Hash in Password Handler
CVSS 1.8
CVE-2025-59354
MEDIUM
Dragonfly < 2.1.0 - Use of Weak Hash via MD5 Collision
CVSS 5.3
CVE-2025-9078
MEDIUM
Mattermost <10.8.4 - Info Disclosure
CVSS 4.3
CVE-2025-55053
MEDIUM
Baicells NOVA and NEUTRINO - Use of Weak Hash
CVSS 6.5
CVE-2025-9383
LOW
FNKvision Y215 CCTV Camera - Weak Hash
CVSS 2.5
CVE-2025-54535
MEDIUM
JetBrains TeamCity <2025.07 - Info Disclosure
CVSS 5.8
CVE-2025-8260
LOW
Vaelsys VaelsysV4 <= 5.1.0/5.4.0 - Use of Weak Hash via xajaxargs Parameter
CVSS 3.1
CVE-2025-41256
HIGH
Cyberduck <9.1.6 - Mountain Duck <4.17.5 - TLS Pinning Weakness
CVSS 7.4
CVE-2025-49197
MEDIUM
SICK media_server < 1.5 - Weak Password Hash for FTP User Account
CVSS 6.5
CVE-2025-48931
LOW
TeleMessage <2025-05-05 - Info Disclosure
CVSS 3.2
CVE-2025-41652
CRITICAL
Weidmueller IE-SW Series - Authentication Bypass via Weak MD5 Hash
CVSS 9.8
CVE-2025-47276
HIGH
Actualizer <1.2.0 - Info Disclosure
CVSS 7.5
Details
Vulnerabilities
90