CWE-916

Use of Password Hash With Insufficient Computational Effort

Parent: CWE-328 - Use of Weak Hash

The product generates a hash for a password, but it uses a scheme that does not provide a sufficient level of computational effort that would make password cracking attacks infeasible or expensive.

115 vulnerabilities with CWE-916
CVE-2026-9641 MEDIUM
Crypt::PBKDF2 versions before 0.261630 for Perl have a weak default algorithm and number of iterations
CVSS 5.3
CVE-2026-25861 MEDIUM
QloApps 1.7.0 Weak Password Hashing via MD5 in Tools.php
CVSS 5.9
CVE-2026-44611 MEDIUM
MacGregor Voyage Data Recorder (VDR) G4e Use of Password Hash With Insufficient Computational Effort
CVSS 5.4
CVE-2026-45787 CRITICAL
electerm's encrypt method not safe enough
CVSS 9.1
CVE-2026-45027 MEDIUM
WeGIA: Use of Weak Password Hashing Algorithm (SHA-256, no salt) in html/login.php
CVSS 5.9
CVE-2026-30790 CRITICAL
RustDesk Server Pro/OSS - Auth Bypass
CVSS 9.8
CVE-2026-30789 CRITICAL
RustDesk Client <1.4.5 - Auth Bypass
CVSS 9.8
CVE-2026-30785 MEDIUM
rustdesk < 1.4.5 - Prototype Pollution and Insufficient Password Hash Effort
CVSS 5.5
CVE-2025-67168 MEDIUM
RiteCMS 3.1.0 - Use of Password Hash With Insufficient Computational Effort
CVSS 5.3
CVE-2025-13532 MEDIUM
Fortra's Core Privileged Access Manager - Info Disclosure
CVSS 6.2
CVE-2025-41692 MEDIUM
Phoenixcontact FL NAT/SWITCH Firmware <= 3.50 - Weak Password Generation
CVSS 6.8
CVE-2025-46413 MEDIUM
BUFFALO WSR-1800AX4 - Info Disclosure
CVSS 4.3
CVE-2025-7789 LOW
Xuxueli xxl-job <3.1.1 - Password Hashing
CVSS 3.7
CVE-2025-3937 HIGH
Tridium Niagara <4.14.2-4.15.1-4.10.11 - Cryptanalysis
CVSS 7.7
CVE-2025-24340 MEDIUM
Bosch Rexroth ctrlX OS 1.12.0-1.12.8, 1.20.0-1.20.6, 2.6.0-2.6.7 Authenticated Password Recovery via Weak Hash
CVSS 6.5
CVE-2025-27552 MEDIUM
DBIx::Class::EncodedColumn <0.00032 - Info Disclosure
CVSS 4.0
CVE-2025-27551 MEDIUM
DBIx::Class::EncodedColumn <0.00032 - Info Disclosure
CVSS 4.0
CVE-2025-26486 MEDIUM
Beta80 Life 1st Identity Mgr <1.5.2.142 - Info Disclosure
CVSS 6.0
CVE-2025-2349 LOW
IROAD Dash Cam FX2 <20250308 - Info Disclosure
CVSS 3.1
CVE-2025-2265 HIGH
Sante PACS Server.exe - Info Disclosure
CVSS 7.8
CVE-2024-5743 CRITICAL
Eve Play <= 1.1.42 - Remote Code Execution via Weak Password Hash
CVSS 9.8
CVE-2024-55057 MEDIUM
Phpgurukul Online Birth Certificate System 1.0 - Info Disclosure
CVSS 5.4
CVE-2024-7701 HIGH
Percona Toolkit <3.6.0 - Info Disclosure
CVSS 7.5
CVE-2024-23091 HIGH
HotelDruid < 1.3.2 - Weak Password Hashing via MD5 in funzioni.php
CVSS 7.5
CVE-2024-24553 HIGH
Bludit 3.14.0-3.14.9 - Weak Password Hashing via SHA-1 and Insecure Salt Generation
CVSS 7.5
Details
Vulnerabilities 115