CWE-759Variant

Use of a One-Way Hash without a Salt

Incomplete in the CWE catalog · 20 CVEs mapped

20
CVEs mapped
5.9
Median CVSS
What it is

The product uses a one-way cryptographic hash against an input that should not be reversible, such as a password, but the product does not also use a salt as part of the input.

Recent examples
6.3cvss
CVE-2026-6217

CVE-2026-6217 - MEDIUM Severity Vulnerability

Use of a One-Way hash without a salt vulnerability in Pik Online Software Solutions Inc. Pik Online Portal allows Cryptanalysis. This issue affects Pik Online Portal: through 3.5.1.

MEDIUMno explanation yet
0%
epss
5.9cvss
CVE-2025-36271

CVE-2025-36271 - MEDIUM Severity Vulnerability

IBM Integrated Analytics System 1.0.0.0 through 1.0.31.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.

MEDIUMno explanation yet
0%
epss
6.8cvss
CVE-2026-57263

CVE-2026-57263 - MEDIUM Severity Vulnerability

A vulnerability has been identified in LOGO! Soft Comfort (All versions < V9). The project password feature in the affected products stores the password as an unsalted SHA-256 hash. This could allow an attacker who has obtained the project file to perform efficient offline dictionary or brute-force attacks against the unsalted hash.

MEDIUMno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-759
Abstraction
Variant
Structure
Simple
Status
Incomplete
References (17)