Vulnerabilities > Use of Password Hash With Insufficient Computational Effort

DATE CVE VULNERABILITY TITLE RISK
2021-05-24 CVE-2021-33563 Use of Password Hash With Insufficient Computational Effort vulnerability in Koel
Koel before 5.1.4 lacks login throttling, lacks a password strength policy, and shows whether a failed login attempt had a valid username.
network
low complexity
koel CWE-916
7.5
2021-04-02 CVE-2019-20466 Use of Password Hash With Insufficient Computational Effort vulnerability in Sannce Smart HD Wifi Security Camera EAN 2 950004 595317 Firmware
An issue was discovered on Sannce Smart HD Wifi Security Camera EAN 2 950004 595317 devices.
local
low complexity
sannce CWE-916
7.8
2021-03-17 CVE-2020-28873 Use of Password Hash With Insufficient Computational Effort vulnerability in Fluxbb 1.5.11
Fluxbb 1.5.11 is affected by a denial of service (DoS) vulnerability by sending an extremely long password via the user login form.
network
low complexity
fluxbb CWE-916
7.5
2021-02-05 CVE-2020-10538 Use of Password Hash With Insufficient Computational Effort vulnerability in Epikur 20.1.0.1
An issue was discovered in Epikur before 20.1.1.
local
low complexity
epikur CWE-916
5.5
2021-01-26 CVE-2020-6780 Use of Password Hash With Insufficient Computational Effort vulnerability in Bosch Fsm-2500 Firmware and Fsm-5000 Firmware
Use of Password Hash With Insufficient Computational Effort in the database of Bosch FSM-2500 server and Bosch FSM-5000 server up to and including version 5.2 allows a remote attacker with admin privileges to dump the credentials of other users and possibly recover their plain-text passwords by brute-forcing the MD5 hash.
network
low complexity
bosch CWE-916
4.9
2021-01-21 CVE-2021-21253 Use of Password Hash With Insufficient Computational Effort vulnerability in Onlinevotingsystem Project Onlinevotingsystem 1.1.1
OnlineVotingSystem is an open source project hosted on GitHub.
network
low complexity
onlinevotingsystem-project CWE-916
5.3
2020-11-17 CVE-2020-14389 Use of Password Hash With Insufficient Computational Effort vulnerability in Redhat Keycloak
It was found that Keycloak before version 12.0.0 would permit a user with only view-profile role to manage the resources in the new account console, allowing access and modification of data the user was not intended to have.
network
low complexity
redhat CWE-916
8.1
2020-11-09 CVE-2020-27693 Use of Password Hash With Insufficient Computational Effort vulnerability in Trendmicro Interscan Messaging Security Virtual Appliance 8.5.1.1516/9.0/9.1
Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 stores administrative passwords using a hash that is considered outdated.
local
low complexity
trendmicro CWE-916
4.4
2020-10-20 CVE-2019-9080 Use of Password Hash With Insufficient Computational Effort vulnerability in Domainmod
DomainMOD before 4.14.0 uses MD5 without a salt for password storage.
network
low complexity
domainmod CWE-916
7.5
2020-08-25 CVE-2020-14512 Use of Password Hash With Insufficient Computational Effort vulnerability in Secomea Gatemanager 8250 Firmware 9.1B/9.2/9.2B
GateManager versions prior to 9.2c, The affected product uses a weak hash type, which may allow an attacker to view user passwords.
network
low complexity
secomea CWE-916
7.5