Threats Tagged 'cwe-759'
View all threats tagged with 'cwe-759'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-759'
Click on any threat for detailed analysis and mitigation recommendations
0 CVE-2026-6217 is a vulnerability in Pik Online Software Solutions Inc.'s Pik Online Portal where a one-way hash is used without a salt. This cryptographic weakness can facilitate cryptanalysis attacks. The issue affects versions through 3.5.1 of the software. The vulnerability has a CVSS score of 6.3, indicating a medium severity level. Join the discussion | GCVE Database | 09/04/2026, 07:27:16 UTC Added: 09/04/2026, 14:25:35 UTC |
0 Use of a One-Way hash without a salt vulnerability in Pik Online Software Solutions Inc. Pik Online Portal allows Cryptanalysis. This issue affects Pik Online Portal: through 3.5.1. Join the discussion | CVE Database V5 | 09/04/2026, 07:27:16 UTC Added: 09/04/2026, 07:37:41 UTC |
0 IBM Integrated Analytics System versions 1.0.0.0 through 1.0.31.0 use a one-way hash without a salt, employing weaker than expected cryptographic algorithms. This weakness could allow an attacker to decrypt highly sensitive information. The vulnerability is identified as CWE-759. No official patch or remediation guidance is currently available from the vendor. The CVSS 3.1 base score is 5.9, indicating a medium severity level. Join the discussion | CVE Database V5 | 08/28/2026, 20:41:58 UTC Added: 08/28/2026, 22:08:01 UTC |
0 A vulnerability has been identified in LOGO! Soft Comfort (All versions < V9). The project password feature in the affected products stores the password as an unsalted SHA-256 hash. This could allow an attacker who has obtained the project file to perform efficient offline dictionary or brute-force attacks against the unsalted hash. Join the discussion | CVE Database V5 | 08/11/2026, 12:20:22 UTC Added: 08/11/2026, 12:42:08 UTC |
0 A cryptographic weakness exists in affected Omada devices where site credentials are protected using a legacy hashing algorithm that does not provide sufficient protection. An attacker who obtains access to stored credential data may be able to recover valid credentials to gain unauthorized access to affected devices or management environments. Join the discussion | CVE Database V5 | 08/03/2026, 17:51:52 UTC Added: 08/03/2026, 18:33:33 UTC |
0 A cryptographic weakness exists in the Omada device adoption process. During adoption, authentication credentials associated with site management are transmitted using a weak hashing algorithm that does not provide sufficient protection. An attacker who successfully intercepts adoption-related authentication traffic may be able to recover valid credentials and gain unauthorized access to managed devices or controller-managed environments. Join the discussion | CVE Database V5 | 08/03/2026, 17:49:13 UTC Added: 08/03/2026, 18:33:33 UTC |
0 WeGIA is a web manager for charitable institutions. In versions prior to 3.7.3, when a user logs in, html/login.php hashes the submitted password using PHP's hash() function with the SHA-256 algorithm and no salt before comparing it to the stored value. The password change flow in controle/FuncionarioControle.php follows the same pattern. SHA-256 is a general-purpose cryptographic hash built for speed, not password storage. Without a salt, identical passwords produce identical digests, making the entire hash database vulnerable to a single precomputed rainbow table lookup. This vulnerability is fixed in 3.7.3. Join the discussion | CVE Database V5 | 05/27/2026, 15:24:21 UTC Added: 05/27/2026, 16:33:44 UTC |
IBM Concert 1.0.0 through 2.1.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. Join the discussion | CVE Database V5 | 02/02/2026, 21:52:55 UTC Added: 02/02/2026, 23:15:14 UTC |
0 Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA/SaaS deployments) store user passwords using unsalted SHA-512 hashes with a fall-back to unsalted SHA-1. The hashing is performed via PHP's `hash()` function in multiple files (server_write_requests_users.php, update_database.php, legacy/Login.php, tests/Unit/Api/IdpControllerTest.php). No per-user salt is used and the fast hash algorithms are unsuitable for password storage. An attacker who obtains the password database can recover cleartext passwords via offline dictionary or rainbow table attacks. The vulnerable code also contains logic that migrates legacy SHA-1 hashes to SHA-512 on login, further exposing users still on the old hash. This vulnerability was partially resolved, but still present within the legacy authentication platform. Join the discussion | CVE Database V5 | 10/02/2025, 16:13:06 UTC Added: 10/02/2025, 16:25:20 UTC |
Use of a One-Way Hash with a Predictable Salt vulnerability in ABB FLXEON.This issue affects FLXEON: through 9.3.5. and newer versions Join the discussion | CVE Database V5 | 09/17/2025, 14:51:52 UTC Added: 09/17/2025, 15:16:44 UTC |
Showing 1 to 10 of 12 results