CWE-916— Use of Password Hash With Insufficient Computational Effort
114 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-916page 2 of 3
- CVE-2021-32997HIGHCVSS 8.2EG 7.52022-05-25
The affected Baker Hughes Bentley Nevada products (3500 System 1 6.x, Part No. 3060/00 versions 6.98 and prior, 3500 System 1, Part No. 3071/xx & 3072/xx versions 21.1 HF1 and prior, 3500 Rack Configuration, Part No. 129133-01 versions 6.4…
- CVE-2021-33003MEDIUMCVSS 5.5EG 5.52021-08-30
Delta Electronics DIAEnergie Version 1.7.5 and prior may allow an attacker to retrieve passwords in cleartext due to a weak hashing algorithm.
- CVE-2021-33563HIGHCVSS 7.5EG 7.52021-05-24
Koel before 5.1.4 lacks login throttling, lacks a password strength policy, and shows whether a failed login attempt had a valid username. This might make brute-force attacks easier.
- CVE-2021-36767CRITICALCVSS 9.8EG 9.82021-10-08
In Digi RealPort through 4.10.490, authentication relies on a challenge-response mechanism that gives access to the server password, making the protection ineffective. An attacker may send an unauthenticated request to the server. The serv…
- CVE-2021-37551MEDIUMCVSS 5.3EG 5.32021-08-06
In JetBrains YouTrack before 2021.2.16363, system user passwords were hashed with SHA-256.
- CVE-2021-38314MEDIUMCVSS 5.3EG 5.32021-09-02
The Gutenberg Template Library & Redux Framework plugin <= 4.2.11 for WordPress registered several AJAX actions available to unauthenticated users in the `includes` function in `redux-core/class-redux-core.php` that were unique to a given …
- CVE-2021-38400MEDIUMCVSS 6.9EG 6.92021-10-04
An attacker with physical access to Boston Scientific Zoom Latitude Model 3120 can remove the hard disk drive or create a specially crafted USB to extract the password hash for brute force reverse engineering of the system password.
- CVE-2021-38979HIGHCVSS 7.5EG 7.52021-11-15
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 uses a one-way cryptographic hash against an input that should not be reversible, such as a password, but the software does not also use a salt as part of the input. IBM X-Force ID:…
- CVE-2021-39182HIGHCVSS 7.5EG 7.52021-11-08
EnroCrypt is a Python module for encryption and hashing. Prior to version 1.1.4, EnroCrypt used the MD5 hashing algorithm in the hashing file. Beginners who are unfamiliar with hashes can face problems as MD5 is considered an insecure hash…
- CVE-2021-43989HIGHCVSS 7.5EG 7.52021-12-23
mySCADA myPRO Versions 8.20.0 and prior stores passwords using MD5, which may allow an attacker to crack the previously retrieved password hashes.
- CVE-2022-0022MEDIUMCVSS 4.1EG 4.42022-03-09
Usage of a weak cryptographic algorithm in Palo Alto Networks PAN-OS software where the password hashes of administrator and local user accounts are not created with a sufficient level of computational effort, which allows for password cra…
- CVE-2022-1235HIGHCVSS 8.2EG 8.22022-04-05
Weak secrethash can be brute-forced in GitHub repository livehelperchat/livehelperchat prior to 3.96.
- CVE-2022-23348MEDIUMCVSS 5.3EG 5.32022-03-21
BigAnt Software BigAnt Server v5.6.06 was discovered to utilize weak password hashes.
- CVE-2022-24041MEDIUMCVSS 6.5EG 6.52022-05-10
A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.142.5-22), Desigo PXC3 (All versions < V01.21.142.4-18), Desigo PXC4 (All versions < V02.20.142.10-10884), Desigo PXC5 (All versions < V02.20.142.10-10884). The web …
- CVE-2022-25156HIGHCVSS 8.1EG 8.12022-04-01
Use of Weak Hash vulnerability in Mitsubishi Electric MELSEC iQ-F series FX5U(C) CPU all versions, Mitsubishi Electric MELSEC iQ-F series FX5UJ CPU all versions, Mitsubishi Electric MELSEC iQ-R series R00/01/02CPU all versions, Mitsubishi …
- CVE-2022-25157CRITICALCVSS 9.1EG 9.12022-04-01
Use of Password Hash Instead of Password for Authentication vulnerability in Mitsubishi Electric MELSEC iQ-F series FX5U(C) CPU all versions, Mitsubishi Electric MELSEC iQ-F series FX5UJ CPU all versions, Mitsubishi Electric MELSEC iQ-R se…
- CVE-2022-26115MEDIUMCVSS 5.9EG 7.52023-02-16
A use of password hash with insufficient computational effort vulnerability [CWE-916] in FortiSandbox before 4.2.0 may allow an attacker with access to the password database to efficiently mount bulk guessing attacks to recover the passwo…
- CVE-2022-29731MEDIUMCVSS 4.3EG 4.32022-06-02
An access control issue in ICT Protege GX/WX 2.08 allows attackers to leak SHA1 password hashes of other users.
- CVE-2022-3010HIGHCVSS 7.5EG 7.52024-01-02
The Priva TopControl Suite contains predictable credentials for the SSH service, based on the Serial number. Which makes it possible for an attacker to calculate the login credentials for the Priva TopControll suite.
- CVE-2022-36071HIGHCVSS 8.3EG 8.32022-09-02
SFTPGo is configurable SFTP server with optional HTTP/S, FTP/S and WebDAV support. SFTPGo WebAdmin and WebClient support login using TOTP (Time-based One Time Passwords) as a secondary authentication factor. Because TOTPs are often configu…
- CVE-2022-37163CRITICALCVSS 9.8EG 9.82022-09-08
Bminusl IHateToBudget v1.5.7 employs a weak password policy which allows attackers to potentially gain unauthorized access to the application via brute-force attacks. Additionally, user passwords are hashed without a salt or pepper making …
- CVE-2022-37164CRITICALCVSS 9.8EG 9.82022-09-08
Inoda OnTrack v3.4 employs a weak password policy which allows attackers to potentially gain unauthorized access to the application via brute-force attacks. Additionally, user passwords are hashed without a salt or pepper making it much ea…
- CVE-2022-40258MEDIUMCVSS 5.3EG 5.32023-01-31
AMI Megarac Weak password hashes for Redfish & API
- CVE-2022-40295MEDIUMCVSS 4.9EG 4.92022-10-31
The application was vulnerable to an authenticated information disclosure, allowing administrators to view unsalted user passwords, which could lead to the compromise of plaintext passwords via offline attacks.
- CVE-2022-47557MEDIUMCVSS 6.1EG 6.12023-09-19
Vulnerability in ekorCCP and ekorRCI that could allow an attacker with access to the network where the device is located to decrypt the credentials of privileged users, and subsequently gain access to the system to perform malicious action…
- CVE-2022-47732HIGHCVSS 7.5EG 7.52023-01-20
In Yeastar N412 and N824 Configuration Panel 42.x and 45.x, an unauthenticated attacker can create backup file and download it, revealing admin hash, allowing, once cracked, to login inside the Configuration Panel, otherwise, replacing the…
- CVE-2023-0567HIGHCVSS 7.7EG 7.72023-03-01
In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, password_verify() function may accept some invalid Blowfish hashes as valid. If such invalid hash ever ends up in the password database, it may lead to an application …
- CVE-2023-27580HIGHCVSS 7.5EG 7.52023-03-13
CodeIgniter Shield provides authentication and authorization for the CodeIgniter 4 PHP framework. An improper implementation was found in the password storage process. All hashed passwords stored in Shield v1.0.0-beta.3 or earlier are easi…
- CVE-2023-31412HIGHCVSS 7.5EG 7.52023-08-24
The LMS5xx uses weak hash generation methods, resulting in the creation of insecure hashs. If an attacker manages to retrieve the hash, it could lead to collision attacks and the potential retrieval of the password.
- CVE-2023-33243HIGHCVSS 8.1EG 8.12023-06-15
RedTeam Pentesting discovered that the web interface of STARFACE as well as its REST API allows authentication using the SHA512 hash of the password instead of the cleartext password. While storing password hashes instead of cleartext pass…
- CVE-2023-33838MEDIUMCVSS 4.4EG 4.42025-01-29
IBM Security Verify Governance 10.0.2 Identity Manager uses a one-way cryptographic hash against an input that should not be reversible, such as a password, but the product does not also use a salt as part of the input.
- CVE-2023-34433HIGHCVSS 7.5EG 7.52023-07-07
PiiGAB M-Bus stores passwords using a weak hash algorithm.
- CVE-2023-41646MEDIUMCVSS 5.3EG 5.32023-09-07
Buttercup v2.20.3 allows attackers to obtain the hash of the master password for the password manager via accessing the file /vaults.json/
- CVE-2023-46133CRITICALCVSS 9.1EG 9.12023-10-25
CryptoES is a cryptography algorithms library compatible with ES6 and TypeScript. Prior to version 2.1.0, CryptoES PBKDF2 is 1,000 times weaker than originally specified in 1993, and at least 1,300,000 times weaker than current industry st…
- CVE-2023-46233CRITICALCVSS 9.1EG 9.12023-10-25
crypto-js is a JavaScript library of crypto standards. Prior to version 4.2.0, crypto-js PBKDF2 is 1,000 times weaker than originally specified in 1993, and at least 1,300,000 times weaker than current industry standard. This is because it…
- CVE-2023-4986LOWCVSS 2.5EG 2.52023-09-15
A vulnerability classified as problematic was found in Supcon InPlant SCADA up to 20230901. Affected by this vulnerability is an unknown functionality of the file Project.xml. The manipulation leads to password hash with insufficient compu…
- CVE-2023-5846HIGHCVSS 8.3EG 8.32023-11-02
Franklin Fueling System TS-550 versions prior to 1.9.23.8960 are vulnerable to attackers decoding admin credentials, resulting in unauthenticated access to the device.
- CVE-2024-21754LOWCVSS 1.8EG 1.82024-06-11
A use of password hash with insufficient computational effort vulnerability [CWE-916] affecting FortiOS version 7.4.3 and below, 7.2 all versions, 7.0 all versions, 6.4 all versions and FortiProxy version 7.4.2 and below, 7.2 all versions,…
- CVE-2024-23091HIGHCVSS 7.5EG 7.52024-07-30
Weak password hashing using MD5 in funzioni.php in HotelDruid before 1.32 allows an attacker to obtain plaintext passwords from hash values.
- CVE-2024-2365LOWCVSS 1.6EG 1.62024-03-11
A vulnerability classified as problematic was found in Musicshelf 1.0/1.1 on Android. Affected by this vulnerability is an unknown functionality of the file io\fabric\sdk\android\services\network\PinningTrustManager.java of the component S…
- CVE-2024-24553HIGHCVSS 7.5EG 7.52024-06-24
Bludit uses the SHA-1 hashing algorithm to compute password hashes. Thus, attackers could determine cleartext passwords with brute-force attacks due to the inherent speed of SHA-1. In addition, the salt that is computed by Bludit is genera…
- CVE-2024-25607HIGHCVSS 8.1EG 8.12024-02-20
The default password hashing algorithm (PBKDF2-HMAC-SHA1) in Liferay Portal 7.2.0 through 7.4.3.15, and older unsupported versions, and Liferay DXP 7.4 before update 16, 7.3 before update 4, 7.2 before fix pack 17, and older unsupported ve…
- CVE-2024-29886MEDIUMCVSS 5.3EG 5.32024-03-27
Serverpod is an app and web server, built for the Flutter and Dart ecosystem. An issue was identified with the old password hash algorithm that made it susceptible to rainbow attacks if the database was compromised. This vulnerability is f…
- CVE-2024-31464MEDIUMCVSS 6.8EG 6.82024-04-10
XWiki Platform is a generic wiki platform. Starting in version 5.0-rc-1 and prior to versions 14.10.19, 15.5.4, and 15.9-rc-1, it is possible to access the hash of a password by using the diff feature of the history whenever the object sto…
- CVE-2024-3183HIGHCVSS 8.1EG 8.12024-06-12
A vulnerability was found in FreeIPA in a way when a Kerberos TGS-REQ is encrypted using the client’s session key. This key is different for each new session, which protects it from brute force attacks. However, the ticket it contains is…
- CVE-2024-55057MEDIUMCVSS 5.4EG 5.42024-12-17
Phpgurukul Online Birth Certificate System 1.0 suffers from insufficient password requirements which can lead to unauthorized access to user accounts.
- CVE-2024-5743CRITICALCVSS 9.8EG 9.82025-01-13
An attacker could exploit the 'Use of Password Hash With Insufficient Computational Effort' vulnerability in EveHome Eve Play to execute arbitrary code. This issue affects Eve Play: through 1.1.42.
- CVE-2024-7701HIGHCVSS 7.5EG 7.52024-12-15
Use of Password Hash With Insufficient Computational Effort vulnerability in percona percona-toolkit allows Encryption Brute Forcing.This issue affects percona-toolkit: 3.6.0.
- CVE-2025-13532MEDIUMCVSS 6.2EG 6.22025-12-16
Insecure defaults in the Server Agent component of Fortra's Core Privileged Access Manager (BoKS) can result in the selection of weak password hash algorithms. This issue affects BoKS Server Agent 9.0 instances that support yescrypt and …
- CVE-2025-2265HIGHCVSS 7.8EG 7.82025-03-13
The password of a web user in "Sante PACS Server.exe" is zero-padded to 0x2000 bytes, SHA1-hashed, base64-encoded, and stored in the USER table in the SQLite database HTTP.db. However, the number of hash bytes encoded and stored is truncat…
Map vulnerabilities like CWE-916 to your infrastructure
EchelonGraph correlates every CVE — across CWE-916 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →