VulnSea

CWE-916

CVEs classified under CWE-916, newest first.

14 CVEsRSS

CVE-2026-85497Critical· 9.8
4d ago

CareCam CM2507 IP cameras store the device's root-account password using a fixed legacy password hash that provides insufficient resistance to offline cracking

CareCam CM2507 IP cameras store the device's root-account password using a fixed legacy password hash that provides insufficient resistance to offline cracking. An attacker who obtains the firmware image or password database could recove…

MidnightCareCam · HMT.CM2507 FirmwareEPSS 0.21%via NVD
CVE-2026-92921Medium· 4.9PoC
5d ago

admin3 through 3.0.0 stores account passwords using single-round MD5 with only the username as salt and no key derivation function

admin3 through 3.0.0 stores account passwords using single-round MD5 with only the username as salt and no key derivation function. Attackers with database access can recover plaintext passwords through offline dictionary or brute-force …

Twilightcjbi · admin3EPSS 0.18%via NVD
CVE-2026-90457Medium· 6.9
1w ago

The administrative password is hashed using a comparatively weak, fast algorithm for the credential store backing one authentication path, and the file containing that hash is written with permissions allowing it to be read by any local …

The administrative password is hashed using a comparatively weak, fast algorithm for the credential store backing one authentication path, and the file containing that hash is written with permissions allowing it to be read by any local …

SunlitCISA · MalcolmEPSS 0.09%via NVD
CVE-2026-86670Low· 3.7PoC
2w ago

A flaw has been found in aircheng-org iWebShop-5 up to 5.15

A flaw has been found in aircheng-org iWebShop-5 up to 5.15. This impacts an unknown function of the file controllers/admin.php of the component Authentication Storage. Executing a manipulation of the argument Password can lead to passwo…

Twilightaircheng-org · iWebShop-5EPSS 0.25%via NVD
CVE-2026-81704High· 7.5
3w ago

openssl_encrypt versions before 1.4.9 contain a weak key derivation vulnerability in the D-Bus CryptoService.EncryptFile handler that uses unstretched SHA-256 instead of Argon2id

openssl_encrypt versions before 1.4.9 contain a weak key derivation vulnerability in the D-Bus CryptoService.EncryptFile handler that uses unstretched SHA-256 instead of Argon2id. Attackers can perform offline password guessing against e…

Twilightjahlives · openssl_encryptEPSS 0.20%via NVD
CVE-2026-80211Medium· 5.9
3w ago

FrontAccounting through 2.4.20 stores and verifies user passwords as unsalted MD5 digests

FrontAccounting through 2.4.20 stores and verifies user passwords as unsalted MD5 digests. admin/users.php passes md5($_POST['password']) to add_user() and update_user_password(), admin/change_current_user_password.php does the same when…

SunlitEPSS 0.24%via NVD
CVE-2026-53762Medium· 6.2
1mo ago

VeraCrypt provides disk encryption with strong security based on TrueCrypt

VeraCrypt provides disk encryption with strong security based on TrueCrypt. Prior to 1.26.29, non-default builds created with WOLFCRYPT=1 and WOLFCRYPT_BACKEND route SHA-256 and SHA-512 volume-header key derivation through derive_key_sha…

SunlitEPSS 0.09%via NVD
CVE-2026-74871Medium· 6.2
1mo ago

openssl_encrypt versions before 1.4.6 contain a key derivation flaw in sequential XOR composition mode where the last stage cancels out during key generation

openssl_encrypt versions before 1.4.6 contain a key derivation flaw in sequential XOR composition mode where the last stage cancels out during key generation. When configured with a single KDF and no prior hashing stage, attackers can by…

Sunlitjahlives · openssl_encryptEPSS 0.08%via NVD
CVE-2026-44611Medium· 5.4
3mo ago

Danelec MacGregor Voyage Data Recorder passwords are stored with a hashing method which limits password length and is susceptible to brute force attacks.

Danelec MacGregor Voyage Data Recorder passwords are stored with a hashing method which limits password length and is susceptible to brute force attacks.

Sunlitmacgregor · interschalt_vdr_g4e_firmwareEPSS 0.14%via NVD
CVE-2026-30789Critical· 9.8
6mo ago

Use of Password Hash With Insufficient Computational Effort, Improper Restriction of Excessive Authentication Attempts vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Client login,…

Use of Password Hash With Insufficient Computational Effort, Improper Restriction of Excessive Authentication Attempts vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Client login,…

MidnightEPSS 0.27%via NVD
CVE-2023-46233Critical· 9.1
2y ago

crypto-js is a JavaScript library of crypto standards

crypto-js is a JavaScript library of crypto standards. Prior to version 4.2.0, crypto-js PBKDF2 is 1,000 times weaker than originally specified in 1993, and at least 1,300,000 times weaker than current industry standard. This is because …

Midnightcrypto-js_project · crypto-jsEPSS 0.64%via NVD
CVE-2023-0567High· 7.7
3y ago

In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, password_verify() function may accept some invalid Blowfish hashes as valid

In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, password_verify() function may accept some invalid Blowfish hashes as valid. If such invalid hash ever ends up in the password database, it may lead to an applicatio…

Twilightphp · phpEPSS 0.95%via NVD
CVE-2022-23348Medium· 5.3PoC
4y ago

BigAnt Software BigAnt Server v5.6.06 was discovered to utilize weak password hashes.

BigAnt Software BigAnt Server v5.6.06 was discovered to utilize weak password hashes.

Twilightbigantsoft · bigant_serverEPSS 3.3%via NVD
CVE-2020-28873High· 7.5
5y ago

Fluxbb 1.5.11 is affected by a denial of service (DoS) vulnerability by sending an extremely long password via the user login form

Fluxbb 1.5.11 is affected by a denial of service (DoS) vulnerability by sending an extremely long password via the user login form. When a long password is sent, the password hashing process will result in CPU and memory exhaustion on th…

Twilightfluxbb · fluxbbEPSS 0.86%via NVD
CWE-916 vulnerabilities (CVEs) · VulnSea