CWE-328

Use of Weak Hash

Parent: CWE-326 - Inadequate Encryption Strength

The product uses an algorithm that produces a digest (output value) that does not meet security expectations for a hash function that allows an adversary to reasonably determine the original input (preimage attack), find another input that can produce the same hash (2nd preimage attack), or find multiple inputs that evaluate to the same hash (birthday attack).

90 vulnerabilities with CWE-328
CVE-2026-10766 LOW
mlrun DataFrame Hash helpers.py mlrun.utils.helpers.calculate_dataframe_hash weak hash
CVSS 3.6
CVE-2026-45413 MEDIUM
MaxKB: Unsalted MD5 Password Hashing
CVE-2026-8803 LOW
opensourcepos Open Source Point of Sale Employee Login Employee.php login weak hash
CVSS 3.7
CVE-2026-44582 LOW
Next.js: Cache poisoning via collisions in React Server Component cache-busting
CVSS 3.7
CVE-2026-34527 MEDIUM
Sandboxie-Plus EditPassword hash entropy reduced from 160 bits to 80 bits due to incorrect nibble extraction
CVSS 5.3
CVE-2026-7845 LOW
chatchat-space Langchain-Chatchat Vision Chat Paste Image dialogue.py PIL.Image.tobytes weak hash
CVSS 2.6
CVE-2026-7103 LOW
code-projects Chat System MD5 Hash update_user.php weak hash
CVSS 3.7
CVE-2026-40164 HIGH
jq: Algorithmic complexity DoS via hardcoded MurmurHash3 seed
CVSS 7.5
CVE-2026-21717 MEDIUM
Node.js 20.x 22.x 24.x 25.x - Denial of Service via V8 String Hash Collision
CVSS 5.9
CVE-2026-32129 HIGH
soroban-poseidon < 25.0.1 - Hash Collision via Implicit Zero-Filling in PoseidonSponge
CVE-2026-27754 MEDIUM
SODOLA SL902-SWTGW124AS Firmware <200.1.20 - Auth Bypass
CVSS 6.5
CVE-2025-41762 MEDIUM
MBS Solutions Universal BACnet Router Firmware < 6.0.1.0 - Unauthenticated Sensitive Data Exposure via Weak Backup Hash
CVSS 6.2
CVE-2025-14636 LOW
Tenda AX9 22.03.01.46 - Use of Weak Hash in httpd image_check Function
CVSS 3.7
CVE-2025-11650 LOW
Furbo 360 Dog Camera Firmware < 036 and Furbo Mini Firmware < 074 - Use of Weak Hash in Password Handler
CVSS 1.8
CVE-2025-59354 MEDIUM
Dragonfly < 2.1.0 - Use of Weak Hash via MD5 Collision
CVSS 5.3
CVE-2025-9078 MEDIUM
Mattermost <10.8.4 - Info Disclosure
CVSS 4.3
CVE-2025-55053 MEDIUM
Baicells NOVA and NEUTRINO - Use of Weak Hash
CVSS 6.5
CVE-2025-9383 LOW
FNKvision Y215 CCTV Camera - Weak Hash
CVSS 2.5
CVE-2025-54535 MEDIUM
JetBrains TeamCity <2025.07 - Info Disclosure
CVSS 5.8
CVE-2025-8260 LOW
Vaelsys VaelsysV4 <= 5.1.0/5.4.0 - Use of Weak Hash via xajaxargs Parameter
CVSS 3.1
CVE-2025-41256 HIGH
Cyberduck <9.1.6 - Mountain Duck <4.17.5 - TLS Pinning Weakness
CVSS 7.4
CVE-2025-49197 MEDIUM
SICK media_server < 1.5 - Weak Password Hash for FTP User Account
CVSS 6.5
CVE-2025-48931 LOW
TeleMessage <2025-05-05 - Info Disclosure
CVSS 3.2
CVE-2025-41652 CRITICAL
Weidmueller IE-SW Series - Authentication Bypass via Weak MD5 Hash
CVSS 9.8
CVE-2025-47276 HIGH
Actualizer <1.2.0 - Info Disclosure
CVSS 7.5
Details
Vulnerabilities 90