The product uses an algorithm that produces a digest (output value) that does not meet security expectations for a hash function that allows an adversary to reasonably determine the original input (preimage attack), find another input that can produce the same hash (2nd preimage attack), or find multiple inputs that evaluate to the same hash (birthday attack).
90 vulnerabilities with CWE-328
CVE-2025-3576
MEDIUM
Red Hat Enterprise Linux - Message Spoofing via RC4-HMAC-MD5 Weakness in MIT Kerberos GSSAPI
CVSS 5.9
CVE-2025-31130
MEDIUM
gitoxide <0.42.0 - Info Disclosure
CVSS 6.8
CVE-2025-2920
LOW
Netis WF-2404 1.1.124EN - Weak Hash
CVSS 2.0
CVE-2025-0508
MEDIUM
SageMaker Workflow - Info Disclosure
CVSS 5.9
CVE-2025-26486
MEDIUM
Beta80 Life 1st Identity Mgr <1.5.2.142 - Info Disclosure
CVSS 6.0
CVE-2025-27595
CRITICAL
SICK DL100-2xxxxxxx - Use of Weak Hash for Password Storage
CVSS 9.8
CVE-2025-21604
MEDIUM
LangChain4j-AIDeepin <3.5.0 - Info Disclosure
CVE-2024-23589
MEDIUM
HCL Glovius Cloud - Info Disclosure
CVSS 6.8
CVE-2024-38341
MEDIUM
IBM Sterling Secure Proxy <6.2.0.1 - Info Disclosure
CVSS 5.9
CVE-2024-47829
MEDIUM
pnpm < 10.0.0 - Use of Weak Hash via MD5 Path Shortening
CVSS 6.5
CVE-2024-10026
MEDIUM
gVisor < 20231030.0 - Weak Hashing and Small Seed/Secret Sizes
CVSS 5.3
CVE-2024-56414
MEDIUM
Acronis Cyber Protect <39169 - Info Disclosure
CVSS 5.5
CVE-2024-56516
MEDIUM
free-one-api <1.0.1 - Info Disclosure
CVE-2024-55885
HIGH
beego < 2.3.4 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 7.5
CVE-2024-54143
CRITICAL
openwrt/asu - Hash Collision via Truncated SHA-256
CVE-2024-48847
HIGH
ABB ASPECT/MATRIX/NEXUS Firmware < 3.08.03 - MD5 Checksum Bypass via Weak Hash Validation
CVSS 8.2
CVE-2024-52521
LOW
Nextcloud Server <28.0.10-30.0.0 - Info Disclosure
CVSS 2.6
CVE-2024-48924
HIGH
MessagePack < 2.5.187 and 2.6.95-alpha-3.0.214-rc.1 - Denial of Service via Hash Collision
CVE-2024-8453
MEDIUM
PLANET Technology - Info Disclosure
CVSS 4.9
CVE-2024-8452
HIGH
PLANET Technology - Info Disclosure
CVSS 7.5
CVE-2024-47182
MEDIUM
Dozzle < 8.5.3 - Inadequate Encryption Strength for Password Hashing
CVSS 4.8
CVE-2024-40465
HIGH
beego <2.2.0 - Privilege Escalation
CVSS 8.8
CVE-2024-34914
MEDIUM
php-censor <2.1.4 - Info Disclosure
CVSS 5.3
CVE-2023-5962
MEDIUM
Moxa ioLogik E1200 Series Firmware < 3.3 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 6.5
CVE-2023-44319
MEDIUM
RUGGEDCOM RM1224 LTE(4G) EU/NAM, SCALANCE M804PB/M812-1/M816-1 - In...
CVSS 4.9
Details
Vulnerabilities
90