CWE-330
380 CVEs • Abstraction: Class • Likelihood of Exploit: High
Use of Insufficiently Random Values
The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.
CVEs (380)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Broadcom 1Raid Controller Web Interface Jun 17, 2026 Aug 15, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Broadcom RAID Controller web interface is vulnerable to insufficient randomness due to improper use of ssl.rnd to setup CIM connection |
Use of insufficiently random values for some Intel Agilex(R) software included as part of Intel(R) Quartus(R) Prime Pro Edition for linux before version 22.4 may allow an authenticated user to potentially enable informat...Show more |
1Mitsubishielectric 2Gs21 Firmware Gt21 FirmwareJun 17, 2026 Aug 4, 2023 N/A· v4 9.1 CRITICAL· v3 N/A· v2 Predictable Exact Value from Previous Values vulnerability in Mitsubishi Electric Corporation GOT2000 Series GT21 model versions 01.49.000 and prior and GOT SIMPLE Series GS21 model versions 01.49.000 and prior allows a...Show more |
1Open Xchange 1Open Xchange Appsuite Backend Jun 17, 2026 Aug 2, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Functions with insufficient randomness were used to generate authorization tokens of the integrated oAuth Authorization Service. Authorization codes were predictable for third parties and could be used to intercept and t...Show more |
In PHP versions 8.0.* before 8.0.29, 8.1.* before 8.1.20, 8.2.* before 8.2.7 when using SOAP HTTP Digest Authentication, random value generator was not checked for failure, and was using narrower range of values than it...Show more |
1Cdwanjiang 1Flash Flood Disaster Monitoring And Warning System Jun 17, 2026 Jul 21, 2023 N/A· v4 3.7 LOW· v3 1.4 LOW· v2 A vulnerability classified as problematic has been found in Chengdu Flash Flood Disaster Monitoring and Warning System 2.0. This affects an unknown part of the file /Service/ImageStationDataService.asmx of the component...Show more |
A vulnerability in the Cisco ACI Multi-Site CloudSec encryption feature of Cisco Nexus 9000 Series Fabric Switches in ACI mode could allow an unauthenticated, remote attacker to read or modify intersite encrypted traffic...Show more |
1Atlascopco 1Power Focus 6000 Firmware Jun 17, 2026 Jun 12, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Atlas Copco Power Focus 6000 web server uses a small amount of session ID numbers. An attacker could enter a session ID number to retrieve data for an active user’s session. |
The crypto-js package before 3.2.1 for Node.js generates random numbers by concatenating the string "0." with an integer, which makes the output more predictable than necessary. |
1Honeywell 1Onewireless Network Wireless Device Manager Firmware Jun 17, 2026 May 30, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2
Use of Insufficiently Random Values in Honeywell OneWireless. This vulnerability may allow attacker to manipulate claims in client's JWT token. This issue affects OneWireless version 322.1 |
2C Ares Project Fedoraproject2C Ares FedoraJun 17, 2026 May 25, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 c-ares is an asynchronous resolver library. When /dev/urandom or RtlGenRandom() are unavailable, c-ares uses rand() to generate random numbers used for DNS query ids. This is not a CSPRNG, and it is also not seeded by sr...Show more |
2C Ares Project Fedoraproject2C Ares FedoraJun 17, 2026 May 25, 2023 N/A· v4 3.7 LOW· v3 N/A· v2 c-ares is an asynchronous resolver library. When cross-compiling c-ares and using the autotools build system, CARES_RANDOM_FILE will not be set, as seen when cross compiling aarch64 android. This will downgrade to using...Show more |
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG), Use of Insufficiently Random Values vulnerability in CBOT Chatbot allows Signature Spoofing by Key Recreation. This issue affects Chatbot: before Core...Show more |
Improper JPAKE implementation allows offline PIN brute-forcing due to the initialization of random values to a known value, which leads to unauthorized authentication to amzn.lightning services. This issue affects: Ama...Show more |
A vulnerability was found in Konga 2.8.3 on Kong. It has been classified as problematic. This affects an unknown part of the component Login API. The manipulation leads to insufficiently random values. The complexity of...Show more |
Netflix Lemur before version 1.3.2 used insufficiently random values when generating default credentials. The insufficiently random values may allow an attacker to guess the credentials and gain access to resources manag...Show more |
The hashing algorithm of ChurchCRM v4.5.3 utilizes a non-random salt value which allows attackers to use precomputed hash tables or dictionary attacks to crack the hashed passwords. |
Akuvox E11 contains a function that encrypts messages which are then forwarded. The IV vector and the key are static, and this may allow an attacker to decrypt messages. |
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of TP-Link TL-WR940N 6_211111 3.20.1(US) routers. Authentication is not required to exploit this vulnerability. The...Show more |
1Abb 7H5692448 G104 Firmware H5692448 G224l FirmwareH5692448 G451c(2) Firmware+4 moreJun 17, 2026 Mar 16, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 Use of Insufficiently Random Values vulnerability in ABB Pulsar Plus System Controller NE843_S, ABB Infinity DC Power Plant.This issue affects Pulsar Plus System Controller NE843_S : comcode 150042936; Infinity DC Power...Show more |