CWE-760: Use of a One-Way Hash with a Predictable Salt
The product uses a one-way cryptographic hash against an input that should not be reversible, such as a password, but the product uses a predictable salt as part of the input.
9 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2024-13951 — One way hash with predictable salt
- CVE-2025-9290 — Authentication Weakness on Omada Controllers, Gateways and Access Points
- CVE-2025-26486 — Broken or Risky Cryptographic Algorithm, Use of Password Hash With Insufficient Computational Effort, Use of Weak Hash,
- CVE-2026-9370 — ulisesbocchio jasypt-spring-boot Password Hash SimpleGCMConfig.java getSecretKeySaltGenerator hash predictable salt
- CVE-2026-46749 — A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected application uses a pas
Recently published
- CVE-2026-46749 — A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected application uses a pas
- CVE-2026-9370 — ulisesbocchio jasypt-spring-boot Password Hash SimpleGCMConfig.java getSecretKeySaltGenerator hash predictable salt
- CVE-2025-9290 — Authentication Weakness on Omada Controllers, Gateways and Access Points
- CVE-2024-13951 — One way hash with predictable salt
- CVE-2025-26486 — Broken or Risky Cryptographic Algorithm, Use of Password Hash With Insufficient Computational Effort, Use of Weak Hash,