CWE-916

Use of Password Hash With Insufficient Computational Effort

Parent: CWE-328 - Use of Weak Hash

The product generates a hash for a password, but it uses a scheme that does not provide a sufficient level of computational effort that would make password cracking attacks infeasible or expensive.

110 vulnerabilities with CWE-916
CVE-2024-25607 HIGH
Liferay Portal/DXP - Info Disclosure
CVSS 8.1
CVE-2023-33838 MEDIUM
IBM Security Verify Governance 10.0.2 - Info Disclosure
CVSS 4.4
CVE-2023-5846 HIGH
Franklin Fueling System TS-550 <1.9.23.8960 - Info Disclosure
CVSS 8.3
CVE-2023-46233 CRITICAL
crypto-js <4.2.0 - Info Disclosure
CVSS 9.1
CVE-2023-46133 CRITICAL
CryptoES <2.1.0 - Info Disclosure
CVSS 9.1
CVE-2023-4986 LOW
Supcon InPlant SCADA <20230901 - Info Disclosure
CVSS 2.5
CVE-2023-41646 MEDIUM
Buttercup v2.20.3 - Info Disclosure
CVSS 5.3
CVE-2023-31412 HIGH
LMS5xx - Info Disclosure
CVSS 7.5
CVE-2023-34433 HIGH
PiiGAB M-Bus - Password Weak Hash
CVSS 7.5
CVE-2023-33243 HIGH
STARFACE - Auth Bypass
CVSS 8.1
CVE-2023-27580 HIGH
CodeIgniter Shield <v1.0.0-beta.3 - Info Disclosure
CVSS 7.5
CVE-2023-0567 HIGH
PHP <8.0.28-8.1.16-8.2.3 - Info Disclosure
CVSS 7.7
CVE-2022-3010 HIGH
Priva TopControl Suite - Info Disclosure
CVSS 7.5
CVE-2022-47557 MEDIUM
EkorCCP/EkorRCI - Privilege Escalation
CVSS 6.1
CVE-2022-26115 MEDIUM
FortiSandbox <4.2.0 - Info Disclosure
CVSS 5.9
CVE-2022-40258 MEDIUM
AMI Megarac - Info Disclosure
CVSS 5.3
CVE-2022-47732 HIGH
Yeastar N412/N824 Config Pnl 42.x/45.x - Info Disclosure
CVSS 7.5
CVE-2022-40295 MEDIUM
Phppointofsale Php Point OF Sale - Information Disclosure
CVSS 4.9
CVE-2022-37164 CRITICAL
Inoda OnTrack <3.4 - Privilege Escalation
CVSS 9.8
CVE-2022-37163 CRITICAL
Bminusl IHateToBudget v1.5.7 - Info Disclosure
CVSS 9.8
CVE-2022-36071 HIGH
SFTPGo <2.3.3 - Info Disclosure
CVSS 8.3
CVE-2022-29731 MEDIUM
ICT Protege GX/WX <2.08 - Info Disclosure
CVSS 4.3
CVE-2022-24041 MEDIUM
Desigo DXR2, PXC3, PXC4, PXC5 < V01.21.142.5-22, V02.20.142.10-1088...
CVSS 6.5
CVE-2022-1235 HIGH
GitHub livehelperchat/livehelperchat <3.96 - Info Disclosure
CVSS 8.2
CVE-2022-23348 MEDIUM
BigAnt Server <5.6.06 - Info Disclosure
CVSS 5.3
Details
Vulnerabilities 110