CWE-328

Use of Weak Hash

Parent: CWE-326 - Inadequate Encryption Strength

The product uses an algorithm that produces a digest (output value) that does not meet security expectations for a hash function that allows an adversary to reasonably determine the original input (preimage attack), find another input that can produce the same hash (2nd preimage attack), or find multiple inputs that evaluate to the same hash (birthday attack).

90 vulnerabilities with CWE-328
CVE-2025-3576 MEDIUM
Red Hat Enterprise Linux - Message Spoofing via RC4-HMAC-MD5 Weakness in MIT Kerberos GSSAPI
CVSS 5.9
CVE-2025-31130 MEDIUM
gitoxide <0.42.0 - Info Disclosure
CVSS 6.8
CVE-2025-2920 LOW
Netis WF-2404 1.1.124EN - Weak Hash
CVSS 2.0
CVE-2025-0508 MEDIUM
SageMaker Workflow - Info Disclosure
CVSS 5.9
CVE-2025-26486 MEDIUM
Beta80 Life 1st Identity Mgr <1.5.2.142 - Info Disclosure
CVSS 6.0
CVE-2025-27595 CRITICAL
SICK DL100-2xxxxxxx - Use of Weak Hash for Password Storage
CVSS 9.8
CVE-2025-21604 MEDIUM
LangChain4j-AIDeepin <3.5.0 - Info Disclosure
CVE-2024-23589 MEDIUM
HCL Glovius Cloud - Info Disclosure
CVSS 6.8
CVE-2024-38341 MEDIUM
IBM Sterling Secure Proxy <6.2.0.1 - Info Disclosure
CVSS 5.9
CVE-2024-47829 MEDIUM
pnpm < 10.0.0 - Use of Weak Hash via MD5 Path Shortening
CVSS 6.5
CVE-2024-10026 MEDIUM
gVisor < 20231030.0 - Weak Hashing and Small Seed/Secret Sizes
CVSS 5.3
CVE-2024-56414 MEDIUM
Acronis Cyber Protect <39169 - Info Disclosure
CVSS 5.5
CVE-2024-56516 MEDIUM
free-one-api <1.0.1 - Info Disclosure
CVE-2024-55885 HIGH
beego < 2.3.4 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 7.5
CVE-2024-54143 CRITICAL
openwrt/asu - Hash Collision via Truncated SHA-256
CVE-2024-48847 HIGH
ABB ASPECT/MATRIX/NEXUS Firmware < 3.08.03 - MD5 Checksum Bypass via Weak Hash Validation
CVSS 8.2
CVE-2024-52521 LOW
Nextcloud Server <28.0.10-30.0.0 - Info Disclosure
CVSS 2.6
CVE-2024-48924 HIGH
MessagePack < 2.5.187 and 2.6.95-alpha-3.0.214-rc.1 - Denial of Service via Hash Collision
CVE-2024-8453 MEDIUM
PLANET Technology - Info Disclosure
CVSS 4.9
CVE-2024-8452 HIGH
PLANET Technology - Info Disclosure
CVSS 7.5
CVE-2024-47182 MEDIUM
Dozzle < 8.5.3 - Inadequate Encryption Strength for Password Hashing
CVSS 4.8
CVE-2024-40465 HIGH
beego <2.2.0 - Privilege Escalation
CVSS 8.8
CVE-2024-34914 MEDIUM
php-censor <2.1.4 - Info Disclosure
CVSS 5.3
CVE-2023-5962 MEDIUM
Moxa ioLogik E1200 Series Firmware < 3.3 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 6.5
CVE-2023-44319 MEDIUM
RUGGEDCOM RM1224 LTE(4G) EU/NAM, SCALANCE M804PB/M812-1/M816-1 - In...
CVSS 4.9
Details
Vulnerabilities 90