CWE-328— Use of Weak Hash
62 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-328page 1 of 2
- CVE-2004-2761CRITICALCVSS 9.8EG 9.82009-01-05
The MD5 Message-Digest Algorithm is not collision resistant, which makes it easier for context-dependent attackers to conduct spoofing attacks, as demonstrated by attacks on the use of MD5 in the signature algorithm of an X.509 certificate.
- CVE-2019-13539HIGHCVSS 7.0EG 7.82019-11-08
Medtronic Valleylab Exchange Client version 3.4 and below, Valleylab FT10 Energy Platform (VLFT10GEN) software version 4.0.0 and below, and Valleylab FX8 Energy Platform (VLFX8GEN) software version 1.1.0 and below use the descrypt algorith…
- CVE-2020-37168CRITICALCVSS 9.8EG 9.82026-05-13
Ecommerce Systempay 1.0 contains a weak cryptographic implementation vulnerability that allows attackers to brute force the 16-character production secret key used for payment signature generation. Attackers can extract payment form data a…
- CVE-2021-39182HIGHCVSS 7.5EG 7.52021-11-08
EnroCrypt is a Python module for encryption and hashing. Prior to version 1.1.4, EnroCrypt used the MD5 hashing algorithm in the hashing file. Beginners who are unfamiliar with hashes can face problems as MD5 is considered an insecure hash…
- CVE-2022-29249HIGHCVSS 7.5EG 7.52022-05-24
JavaEZ is a library that adds new functions to make Java easier. A weakness in JavaEZ 1.6 allows force decryption of locked text by unauthorized actors. The issue is NOT critical for non-secure applications, however may be critical in a si…
- CVE-2022-29835MEDIUMCVSS 5.3EG 5.32022-09-19
WD Discovery software executable files were signed with an unsafe SHA-1 hashing algorithm. An attacker could use this weakness to create forged certificate signatures due to the use of a hashing algorithm that is not collision-free. This c…
- CVE-2022-3433MEDIUMCVSS 6.5EG 6.52022-10-10
The aeson library is not safe to use to consume untrusted JSON input. A remote user could abuse this flaw to produce a hash collision in the underlying unordered-containers library by sending specially crafted JSON data, resulting in a den…
- CVE-2022-43922MEDIUMCVSS 5.3EG 6.52023-02-01
IBM App Connect Enterprise Certified Container 4.1, 4.2, 5.0, 5.1, 5.2, 6.0, 6.1, and 6.2 could disclose sensitive information to an attacker due to a weak hash of an API Key in the configuration. IBM X-Force ID: 241583.
- CVE-2022-45141CRITICALCVSS 9.8EG 9.82023-03-06
Since the Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability was disclosed by Microsoft on Nov 8 2022 and per RFC8429 it is assumed that rc4-hmac is weak, Vulnerable Samba Active Directory DCs will issue rc4-hmac encrypted tick…
- CVE-2023-0452CRITICALCVSS 9.8EG 5.32023-01-26
Econolite EOS versions prior to 3.2.23 use a weak hash algorithm for encrypting privileged user credentials. A configuration file that is accessible without authentication uses MD5 hashes for encrypting credentials, including those of admi…
- CVE-2023-2900LOWCVSS 3.7EG 3.72023-05-25
A vulnerability was found in NFine Rapid Development Platform 20230511. It has been classified as problematic. Affected is an unknown function of the file /Login/CheckLogin. The manipulation leads to use of weak hash. It is possible to lau…
- CVE-2023-43630HIGHCVSS 8.8EG 8.82023-09-20
PCR14 is not in the list of PCRs that seal/unseal the “vault” key, but due to the change that was implemented in commit “7638364bc0acf8b5c481b5ce5fea11ad44ad7fd4”, fixing this issue alone would not solve the problem of the config p…
- CVE-2023-43635HIGHCVSS 8.8EG 8.82023-09-20
Vault Key Sealed With SHA1 PCRs The measured boot solution implemented in EVE OS leans on a PCR locking mechanism. Different parts of the system update different PCR values in the TPM, resulting in a unique value for each PCR entry…
- CVE-2023-44319MEDIUMCVSS 4.9EG 4.92023-11-14
A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.0), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2) (All versions < V8.0), SCALANCE M804PB (6GK5804-0AP00-2AA2) (All versions < V8…
- CVE-2023-46133CRITICALCVSS 9.1EG 9.12023-10-25
CryptoES is a cryptography algorithms library compatible with ES6 and TypeScript. Prior to version 2.1.0, CryptoES PBKDF2 is 1,000 times weaker than originally specified in 1993, and at least 1,300,000 times weaker than current industry st…
- CVE-2023-46233CRITICALCVSS 9.1EG 9.12023-10-25
crypto-js is a JavaScript library of crypto standards. Prior to version 4.2.0, crypto-js PBKDF2 is 1,000 times weaker than originally specified in 1993, and at least 1,300,000 times weaker than current industry standard. This is because it…
- CVE-2023-5962MEDIUMCVSS 6.5EG 6.52023-12-23
A weak cryptographic algorithm vulnerability has been identified in ioLogik E1200 Series firmware versions v3.3 and prior. This vulnerability can help an attacker compromise the confidentiality of sensitive data. This vulnerability may lea…
- CVE-2024-10026MEDIUMCVSS 5.3EG 5.32025-01-30
A weak hashing algorithm and small sizes of seeds/secrets in Google's gVisor allowed for a remote attacker to calculate a local IP address and a per-boot identifier that could aid in tracking of a device in certain circumstances.
- CVE-2024-1040MEDIUMCVSS 4.4EG 4.42024-02-01
Gessler GmbH WEB-MASTER user account is stored using a weak hashing algorithm. The attacker can restore the passwords by breaking the hashes stored on the device.
- CVE-2024-23589MEDIUMCVSS 6.8EG 6.82025-05-30
Due to outdated Hash algorithm, HCL Glovius Cloud could allow attackers to guess the input data using brute-force or dictionary attacks efficiently using modern hardware such as GPUs or ASICs
- CVE-2024-32211MEDIUMCVSS 5.5EG 5.52024-05-01
An issue in LOGINT LoMag Inventory Management v1.0.20.120 and before allows a local attacker to obtain sensitive information via the UserClass.cs and Settings.cs components.
- CVE-2024-34914MEDIUMCVSS 5.3EG 5.32024-05-14
php-censor v2.1.4 and fixed in v.2.1.5 was discovered to utilize a weak hashing algorithm for its remember_key value. This allows attackers to bruteforce to bruteforce the remember_key value to gain access to accounts that have checked "re…
- CVE-2024-38341MEDIUMCVSS 5.9EG 5.92025-05-28
IBM Sterling Secure Proxy 6.0.0.0 through 6.0.3.1, 6.1.0.0 through 6.1.0.0, and 6.2.0.0 through 6.2.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
- CVE-2024-40465HIGHCVSS 8.8EG 8.82024-07-31
An issue in beego v.2.2.0 and before allows a remote attacker to escalate privileges via the getCacheFileName function in file.go file
- CVE-2024-47182MEDIUMCVSS 4.8EG 4.82024-09-27
Dozzle is a realtime log viewer for docker containers. Before version 8.5.3, the app uses sha-256 as the hash for passwords, which leaves users susceptible to rainbow table attacks. The app switches to bcrypt, a more appropriate hash for p…
- CVE-2024-47829MEDIUMCVSS 6.5EG 6.52025-04-23
pnpm is a package manager. Prior to version 10.0.0, the path shortening function uses the md5 function as a path shortening compression function, and if a collision occurs, it will result in the same storage path for two different librarie…
- CVE-2024-48847HIGHCVSS 8.2EG 8.22024-12-05
MD5 Checksum Bypass vulnerabilities where found exploiting a weakness in the way an application dependency calculates or validates MD5 checksum hashes. Affected products: ABB ASPECT - Enterprise v3.08.01; NEXUS Series v3.08.01; MATRI…
- CVE-2024-48924HIGHCVSS 8.7EG 0.02024-10-17
### Impact When this library is used to deserialize messagepack data from an untrusted source, there is a risk of a denial of service attack by an attacker that sends data contrived to produce hash collisions, leading to large CPU consump…
- CVE-2024-52521LOWCVSS 2.6EG 2.62024-11-15
Nextcloud Server is a self hosted personal cloud system. MD5 hashes were used to check background jobs for their uniqueness. This increased the chances of a background job with arguments falsely being identified as already existing and not…
- CVE-2024-54143CRITICALCVSS 9.3EG 0.02024-12-06
openwrt/asu is an image on demand server for OpenWrt based distributions. The request hashing mechanism truncates SHA-256 hashes to only 12 characters. This significantly reduces entropy, making it feasible for an attacker to generate coll…
- CVE-2024-55885HIGHCVSS 7.5EG 7.52024-12-12
beego is an open-source web framework for the Go programming language. Versions of beego prior to 2.3.4 use MD5 as a hashing algorithm. MD5 is no longer considered secure against well-funded opponents due to its vulnerability to collision …
- CVE-2024-56414MEDIUMCVSS 5.5EG 5.52025-01-02
Web installer integrity check used weak hash algorithm. The following products are affected: Acronis Cyber Protect 16 (Windows) before build 39169.
- CVE-2024-56516MEDIUMCVSS 6.9EG 0.02024-12-30
free-one-api allows users to access large language model reverse engineering libraries through the standard OpenAI API format. In versions up to and including 1.0.1, MD5 is used to hash passwords before sending them to the backend. MD5 is …
- CVE-2024-8452HIGHCVSS 7.5EG 7.52024-09-30
Certain switch models from PLANET Technology only support obsolete algorithms for authentication protocol and encryption protocol in the SNMPv3 service, allowing attackers to obtain plaintext SNMPv3 credentials potentially.
- CVE-2024-8453MEDIUMCVSS 4.9EG 4.92024-09-30
Certain switch models from PLANET Technology use an insecure hashing function to hash user passwords without being salted. Remote attackers with administrator privileges can read configuration files to obtain the hash values, and potential…
- CVE-2025-0508MEDIUMCVSS 5.9EG 5.92025-03-20
A vulnerability in the SageMaker Workflow component of aws/sagemaker-python-sdk allows for the possibility of MD5 hash collisions in all versions. This can lead to workflows being inadvertently replaced due to the reuse of results from dif…
- CVE-2025-11650LOWCVSS 1.8EG 1.82025-10-12
A vulnerability was determined in Tomofun Furbo 360 and Furbo Mini. The impacted element is an unknown function of the file /etc/shadow of the component Password Handler. Executing manipulation can lead to use of weak hash. The physical de…
- CVE-2025-14636LOWCVSS 3.7EG 3.72025-12-13
A security flaw has been discovered in Tenda AX9 22.03.01.46. This affects the function image_check of the component httpd. The manipulation results in use of weak hash. It is possible to launch the attack remotely. A high complexity level…
- CVE-2025-21604MEDIUMCVSS 6.9EG 0.02025-01-06
LangChain4j-AIDeepin is a Retrieval enhancement generation (RAG) project. Prior to 3.5.0, LangChain4j-AIDeepin uses MD5 to hash files, which may cause file upload conflicts. This issue is fixed in 3.5.0.
- CVE-2025-26486MEDIUMCVSS 6.0EG 6.02025-03-19
Broken or Risky Cryptographic Algorithm, Use of Password Hash With Insufficient Computational Effort, Use of Weak Hash, Use of a One-Way Hash with a Predictable Salt vulnerabilities in Beta80 "Life 1st Identity Manager" enable an attacke…
- CVE-2025-27595CRITICALCVSS 9.8EG 9.82025-03-14
The device uses a weak hashing alghorithm to create the password hash. Hence, a matching password can be easily calculated by an attacker. This impacts the security and the integrity of the device.
- CVE-2025-2920LOWCVSS 2.0EG 2.02025-03-28
A vulnerability was found in Netis WF-2404 1.1.124EN. It has been rated as problematic. This issue affects some unknown processing of the file /еtc/passwd. The manipulation leads to use of weak hash. It is possible to launch the attack on…
- CVE-2025-31130MEDIUMCVSS 6.8EG 6.82025-04-04
gitoxide is an implementation of git written in Rust. Before 0.42.0, gitoxide uses SHA-1 hash implementations without any collision detection, leaving it vulnerable to hash collision attacks. gitoxide uses the sha1_smol or sha1 crate, both…
- CVE-2025-3576MEDIUMCVSS 5.9EG 5.92025-04-15
A vulnerability in the MIT Kerberos implementation allows GSSAPI-protected messages using RC4-HMAC-MD5 to be spoofed due to weaknesses in the MD5 checksum design. If RC4 is preferred over stronger encryption types, an attacker could exploi…
- CVE-2025-41256HIGHCVSS 7.4EG 7.42025-06-25
Cyberduck and Mountain Duck improper handle TLS certificate pinning for untrusted certificates (e.g., self-signed), since the certificate fingerprint is stored as SHA-1, although SHA-1 is considered weak. This issue affects Cyberduc…
- CVE-2025-41652CRITICALCVSS 9.8EG 9.82025-05-27
The devices are vulnerable to an authentication bypass due to flaws in the authorization mechanism. An unauthenticated remote attacker could exploit this weakness by performing brute-force attacks to guess valid credentials or by using MD5…
- CVE-2025-47276HIGHCVSS 7.5EG 7.52025-05-13
Actualizer is a single shell script solution to allow developers and embedded engineers to create Debian operating systems (OS). Prior to version 1.2.0, Actualizer uses OpenSSL's "-passwd" function, which uses SHA512 instead of a more sui…
- CVE-2025-48931LOWCVSS 3.2EG 3.22025-05-28
The TeleMessage service through 2025-05-05 relies on MD5 for password hashing, which opens up various attack possibilities (including rainbow tables) with low computational effort.
- CVE-2025-49197MEDIUMCVSS 6.5EG 6.52025-06-12
The application uses a weak password hash function, allowing an attacker to crack the weak password hash to gain access to an FTP user account.
- CVE-2025-54535MEDIUMCVSS 5.8EG 5.82025-07-28
In JetBrains TeamCity before 2025.07 password reset and email verification tokens were using weak hashing algorithms
Map vulnerabilities like CWE-328 to your infrastructure
EchelonGraph correlates every CVE — across CWE-328 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →