Skip to main content

CWE archive

CWE-916 CVEs

Programmatic archive

119 CVEs tagged with CWE-91616 Critical, 46 High, 52 Medium, 5 Low, 0 Unrated.

CVE-2026-57310

Published Jul 20, 2026

Windu CMS uses hashing algorithm based on MD5 and SHA1 with static salt to store user passwords. This allows an attacker who obtain password hash to decode user credentials. Beca…

CVSS 6.3 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-5040

Published Jul 14, 2026

TP-Link Deco M5 v1 uses a weak password hashing mechanism to store user credentials. An attacker who obtains the password hash through system compromise or privileged access coul…

CVSS 7.1 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-40522

Published Jun 29, 2026

FrontAccounting before 2.4.20 contains a SQL injection vulnerability in the Bank Statement report handler that allows authenticated attackers to extract arbitrary database data by…

CVSS 7.1 · High
evidence mentions
4
Buzz score
29.1

CVE-2026-55069

Published Jun 26, 2026

Kestra is an open-source, event-driven orchestration platform. Prior to 1.3.24, this vulnerability exists in the BasicAuth authentication component of the Kestra OSS workflow orch…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-56272

Published Jun 24, 2026

Flowise before 3.0.13 uses bcrypt with default salt rounds of 5, providing only 32 iterations instead of the OWASP-recommended minimum of 10 rounds. Attackers can crack password h…

CVSS 5.6 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-9641

Published Jun 12, 2026

Crypt::PBKDF2 versions before 0.261630 for Perl have a weak default algorithm and number of iterations. The default algorithm is HMAC-SHA1, which should only be used for legacy s…

CVSS 5.3 · Medium
evidence mentions
7
Buzz score
35.8

CVE-2026-25861

Published Jun 2, 2026

QloApps through 1.7.0, fixed in commit 64e9722, contains a weak cryptographic algorithm vulnerability that allows attackers to compromise user credentials by exploiting the use of…

CVSS 8.2 · High
evidence mentions
3
Buzz score
20.4

CVE-2026-45027

Published May 27, 2026

WeGIA is a web manager for charitable institutions. In versions prior to 3.7.3, when a user logs in, html/login.php hashes the submitted password using PHP's hash() function with…

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-67168

Published Dec 17, 2025

RiteCMS v3.1.0 was discovered to use insecure encryption to store passwords.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-13532

Published Dec 16, 2025

Insecure defaults in the Server Agent component of Fortra's Core Privileged Access Manager (BoKS) can result in the selection of weak password hash algorithms.  This issue affects…

CVSS 6.2 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-46413

Published Nov 7, 2025

Use of password hash with insufficient computational effort issue exists in BUFFALO Wi-Fi router 'WSR-1800AX4 series'. When WPS is enabled, PIN code and/or Wi-Fi password may be o…

CVSS 5.3 · Medium

CVE-2025-7789

Published Jul 18, 2025

A vulnerability was found in Xuxueli xxl-job up to 3.1.1 and classified as problematic. Affected by this issue is the function makeToken of the file src/main/java/com/xxl/job/admi…

CVSS 2.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-24340

Published Apr 30, 2025

A vulnerability in the users configuration file of ctrlX OS may allow a remote authenticated (low-privileged) attacker to recover the plaintext passwords of other users.

CVSS 6.5 · Medium

CVE-2025-27552

Published Mar 26, 2025

DBIx::Class::EncodedColumn use the rand() function, which is not cryptographically secure to salt password hashes. This vulnerability is associated with program files Crypt/Eksbl…

CVSS 4.0 · Medium

CVE-2025-27551

Published Mar 26, 2025

DBIx::Class::EncodedColumn use the rand() function, which is not cryptographically secure to salt password hashes. This vulnerability is associated with program files lib/DBIx/Cl…

CVSS 4.0 · Medium

CVE-2025-26486

Published Mar 19, 2025

Broken or Risky Cryptographic Algorithm, Use of Password Hash With Insufficient Computational Effort, Use of Weak Hash, Use of a One-Way Hash with a Predictable Salt vulnerabili…

CVSS 6.0 · Medium

CVE-2025-2349

Published Mar 16, 2025

A vulnerability was found in IROAD Dash Cam FX2 up to 20250308. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /etc/pa…

CVSS 2.3 · Low
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2025-2265

Published Mar 13, 2025

The password of a web user in "Sante PACS Server.exe" is zero-padded to 0x2000 bytes, SHA1-hashed, base64-encoded, and stored in the USER table in the SQLite database HTTP.db. How…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2023-33838

Published Jan 29, 2025

IBM Security Verify Governance 10.0.2 Identity Manager uses a one-way cryptographic hash against an input that should not be reversible, such as a password, but the product does…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 119 CVEsPage 1 of 5