Skip to main content

CWE archive

CWE-759 CVEs

Programmatic archive

16 CVEs tagged with CWE-7590 Critical, 3 High, 12 Medium, 1 Low, 0 Unrated.

CVE-2026-45027

Published May 27, 2026

WeGIA is a web manager for charitable institutions. In versions prior to 3.7.3, when a user logs in, html/login.php hashes the submitted password using PHP's hash() function with…

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-9370

Published May 24, 2026

A weakness has been identified in ulisesbocchio jasypt-spring-boot up to 3.0.5/4.0.4. Affected by this vulnerability is the function getSecretKeySaltGenerator of the file jasypt-s…

CVSS 2.9 · Low
evidence mentions
6
Buzz score
26.0

CVE-2025-36253

Published Feb 2, 2026

IBM Concert 1.0.0 through 2.1.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-10205

Published Sep 17, 2025

Use of a One-Way Hash with a Predictable Salt vulnerability in ABB FLXEON.This issue affects FLXEON: through 9.3.5. and newer versions

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-53884

Published Sep 17, 2025

NeuVector stores user passwords and API keys using a simple, unsalted hash. This method is vulnerable to rainbow table attack (offline attack where hashes of known passwords are p…

CVSS 5.3 · Medium

CVE-2025-5922

Published Jul 29, 2025

Access to TSplus Remote Access Admin Tool is restricted to administrators (unless "Disable UAC" option is enabled) and requires a PIN code. In versions below v18.40.6.17 the PIN's…

CVSS 4.8 · Medium

CVE-2025-27408

Published Feb 28, 2025

Manifest offers users a one-file micro back end. Prior to version 4.9.2, Manifest employs a weak password hashing implementation that uses SHA3 without a salt. This exposes user p…

CVSS 4.8 · Medium

CVE-2023-33838

Published Jan 29, 2025

IBM Security Verify Governance 10.0.2 Identity Manager uses a one-way cryptographic hash against an input that should not be reversible, such as a password, but the product does…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-36440

Published Aug 22, 2024

An issue was discovered on Swissphone DiCal-RED 4009 devices. An attacker with access to the file /etc/deviceconfig may recover the administrative device password via password-cra…

CVSS 6.8 · Medium

CVE-2023-1430

Published Jun 9, 2023

The FluentCRM - Marketing Automation For WordPress plugin for WordPress is vulnerable to unauthorized modification of data in versions up to, and including, 2.8.01 due to the use…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-16244

Published Sep 23, 2020

GE Digital APM Classic, Versions 4.4 and prior. Salt is not used for hash calculation of passwords, making it possible to decrypt passwords. This design flaw, along with the IDOR…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort
Showing 1-16 of 16 CVEsPage 1 of 1