CWE-759: Use of a One-Way Hash without a Salt
The product uses a one-way cryptographic hash against an input that should not be reversible, such as a password, but the product does not also use a salt as part of the input.
20 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-10205 — Predictable Salt and Weak Hashing Algorithm
- CVE-2025-34208 — Vasion Print (formerly PrinterLogic) Insecure Password Hashing
- CVE-2025-36253 — Multiple Vulnerabilities in IBM Concert Software.
- CVE-2026-57263 — A vulnerability has been identified in LOGO! Soft Comfort (All versions < V9). The project password feature in the affec
- CVE-2025-15544 — Weak Credential Protection During TP-Link Omada Device Adoption
- CVE-2025-53884 — NeuVector has an insecure password storage vulnerable to rainbow attack
- CVE-2026-9370 — ulisesbocchio jasypt-spring-boot Password Hash SimpleGCMConfig.java getSecretKeySaltGenerator hash predictable salt
- CVE-2026-6217 — Information Disclosure in Pik Online Software's Portal
- CVE-2026-45787 — electerm's encrypt method not safe enough
- CVE-2026-45027 — WeGIA: Use of Weak Password Hashing Algorithm (SHA-256, no salt) in html/login.php
- CVE-2025-36271 — IBM Integrated Analytics System (IIAS) is affected by a predictable salt vulnerability in Magneto component
- CVE-2025-5922 — Retrievable password hash protecting TSplus admin console
- CVE-2025-27408 — Manifest Uses a One-Way Hash without a Salt
- CVE-2025-15631 — Weak Credential Storage in TP-Link Omada Devices
Recently published
- CVE-2026-6217 — Information Disclosure in Pik Online Software's Portal
- CVE-2025-36271 — IBM Integrated Analytics System (IIAS) is affected by a predictable salt vulnerability in Magneto component
- CVE-2026-57263 — A vulnerability has been identified in LOGO! Soft Comfort (All versions < V9). The project password feature in the affec
- CVE-2025-15631 — Weak Credential Storage in TP-Link Omada Devices
- CVE-2025-15544 — Weak Credential Protection During TP-Link Omada Device Adoption
- CVE-2026-45787 — electerm's encrypt method not safe enough
- CVE-2026-45027 — WeGIA: Use of Weak Password Hashing Algorithm (SHA-256, no salt) in html/login.php
- CVE-2026-9370 — ulisesbocchio jasypt-spring-boot Password Hash SimpleGCMConfig.java getSecretKeySaltGenerator hash predictable salt
- CVE-2025-36253 — Multiple Vulnerabilities in IBM Concert Software.
- CVE-2025-34208 — Vasion Print (formerly PrinterLogic) Insecure Password Hashing
- CVE-2025-10205 — Predictable Salt and Weak Hashing Algorithm
- CVE-2025-53884 — NeuVector has an insecure password storage vulnerable to rainbow attack
- CVE-2025-5922 — Retrievable password hash protecting TSplus admin console
- CVE-2025-27408 — Manifest Uses a One-Way Hash without a Salt