CWE-916
Use of Password Hash With Insufficient Computational Effort
Parent: CWE-328 - Use of Weak Hash
The product generates a hash for a password, but it uses a scheme that does not provide a sufficient level of computational effort that would make password cracking attacks infeasible or expensive.
115 vulnerabilities with CWE-916
CVE-2026-9641
MEDIUM
Crypt::PBKDF2 versions before 0.261630 for Perl have a weak default algorithm and number of iterations
CVSS 5.3
CVE-2026-25861
MEDIUM
QloApps 1.7.0 Weak Password Hashing via MD5 in Tools.php
CVSS 5.9
CVE-2026-44611
MEDIUM
MacGregor Voyage Data Recorder (VDR) G4e Use of Password Hash With Insufficient Computational Effort
CVSS 5.4
CVE-2026-45787
CRITICAL
electerm's encrypt method not safe enough
CVSS 9.1
CVE-2026-45027
MEDIUM
WeGIA: Use of Weak Password Hashing Algorithm (SHA-256, no salt) in html/login.php
CVSS 5.9
CVE-2026-30790
CRITICAL
RustDesk Server Pro/OSS - Auth Bypass
CVSS 9.8
CVE-2026-30789
CRITICAL
RustDesk Client <1.4.5 - Auth Bypass
CVSS 9.8
CVE-2026-30785
MEDIUM
rustdesk < 1.4.5 - Prototype Pollution and Insufficient Password Hash Effort
CVSS 5.5
CVE-2025-67168
MEDIUM
RiteCMS 3.1.0 - Use of Password Hash With Insufficient Computational Effort
CVSS 5.3
CVE-2025-13532
MEDIUM
Fortra's Core Privileged Access Manager - Info Disclosure
CVSS 6.2
CVE-2025-41692
MEDIUM
Phoenixcontact FL NAT/SWITCH Firmware <= 3.50 - Weak Password Generation
CVSS 6.8
CVE-2025-46413
MEDIUM
BUFFALO WSR-1800AX4 - Info Disclosure
CVSS 4.3
CVE-2025-7789
LOW
Xuxueli xxl-job <3.1.1 - Password Hashing
CVSS 3.7
CVE-2025-3937
HIGH
Tridium Niagara <4.14.2-4.15.1-4.10.11 - Cryptanalysis
CVSS 7.7
CVE-2025-24340
MEDIUM
Bosch Rexroth ctrlX OS 1.12.0-1.12.8, 1.20.0-1.20.6, 2.6.0-2.6.7 Authenticated Password Recovery via Weak Hash
CVSS 6.5
CVE-2025-27552
MEDIUM
DBIx::Class::EncodedColumn <0.00032 - Info Disclosure
CVSS 4.0
CVE-2025-27551
MEDIUM
DBIx::Class::EncodedColumn <0.00032 - Info Disclosure
CVSS 4.0
CVE-2025-26486
MEDIUM
Beta80 Life 1st Identity Mgr <1.5.2.142 - Info Disclosure
CVSS 6.0
CVE-2025-2349
LOW
IROAD Dash Cam FX2 <20250308 - Info Disclosure
CVSS 3.1
CVE-2025-2265
HIGH
Sante PACS Server.exe - Info Disclosure
CVSS 7.8
CVE-2024-5743
CRITICAL
Eve Play <= 1.1.42 - Remote Code Execution via Weak Password Hash
CVSS 9.8
CVE-2024-55057
MEDIUM
Phpgurukul Online Birth Certificate System 1.0 - Info Disclosure
CVSS 5.4
CVE-2024-7701
HIGH
Percona Toolkit <3.6.0 - Info Disclosure
CVSS 7.5
CVE-2024-23091
HIGH
HotelDruid < 1.3.2 - Weak Password Hashing via MD5 in funzioni.php
CVSS 7.5
CVE-2024-24553
HIGH
Bludit 3.14.0-3.14.9 - Weak Password Hashing via SHA-1 and Insecure Salt Generation
CVSS 7.5
Details
Vulnerabilities
115