CWE-330
397 CVEs • Abstraction: Class • Likelihood of Exploit: High
Use of Insufficiently Random Values
The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.
CVEs (397)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A remote code execution vulnerability affecting a Valmet DNA service listening on TCP port 1517, allows an attacker to execute commands with SYSTEM privileges This issue affects: Valmet DNA versions from Collection 2012...Show more |
1Dell 1Emc Unity Operating Environment Jun 17, 2026 Jan 25, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Dell VNX2 OE for File versions 8.1.21.266 and earlier, contain an authentication bypass vulnerability. A remote unauthenticated attacker may exploit this vulnerability by forging a cookie to login as any user. |
wolfSSL 5.x before 5.1.1 uses non-random IV values in certain situations. This affects connections (without AEAD) using AES-CBC or DES3 with TLS 1.1 or 1.2 or DTLS 1.1 or 1.2. This occurs because of misplaced memory init...Show more |
Apache Kylin provides encryption classes PasswordPlaceholderConfigurer to help users encrypt their passwords. In the encryption algorithm used by this encryption class, the cipher is initialized with a hardcoded key and...Show more |
1Simple Jwt Login Project 1Simple Jwt Login Jun 17, 2026 Dec 27, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The Simple JWT Login WordPress plugin before 3.3.0 can be used to create new WordPress user accounts with a randomly generated password. The password is generated using the str_shuffle PHP function that "does not genera...Show more |
In NetBSD through 9.2, there is an information leak in the TCP ISN (ISS) generation algorithm. |
In NetBSD through 9.2, the IPv4 ID generation algorithm does not use appropriate cryptographic measures. |
1Reprisesoftware 1Reprise License Manager Jun 17, 2026 Dec 13, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Reprise RLM 14.2. As the session cookies are small, an attacker can hijack any existing sessions by bruteforcing the 4 hex-character session cookie on the Windows version (the Linux version app...Show more |
1Globaldatingsoftware 1Premiumdatingscript Jun 17, 2026 Dec 9, 2021 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 An Incorrect Access Control vulnerability exists in Premiumdatingscript 4.2.7.7 via the password change procedure in requests\user.php. |
OX App Suite through 7.10.5 allows XSS via JavaScript code in an anchor HTML comment within truncated e-mail, because there is a predictable UUID with HTML transformation results. |
A bypass of adding remote files in Concrete CMS (previously concrete5) File Manager leads to remote code execution in Concrete CMS (concrete5) versions 8.5.6 and below.The external file upload feature stages files in the...Show more |
1Amd 57Epyc 7232p Firmware Epyc 7251 FirmwareEpyc 7252 Firmware+54 moreJun 17, 2026 Nov 16, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Persistent platform private key may not be protected with a random IV leading to a potential “two time pad attack”. |
Unauthorized system access in the login form in ServiceTonic Helpdesk software version < 9.0.35937 allows attacker to login without using a password. |
On Windows, the uninstaller binary copies itself to a fixed temporary location, which is then executed (the originally called uninstaller exits, so it does not block the installation directory). This temporary location i...Show more |
1Zohocorp 1Manageengine Remote Access Plus Jun 17, 2026 Sep 30, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Zoho ManageEngine Remote Access Plus before 10.1.2121.1 relies on the application's build number to calculate a certain encryption key. |
In RIOT-OS 2021.01, nonce reuse in 802.15.4 encryption in the ieee820154_security component allows attackers to break encryption by triggering reboots. |
1Siemens 6Logo! Cmr2020 Firmware Logo! Cmr2040 FirmwareSimatic Rtu3010c Firmware+3 moreJun 17, 2026 Sep 14, 2021 N/A· v4 5.4 MEDIUM· v3 4.8 MEDIUM· v2 A vulnerability has been identified in LOGO! CMR2020 (All versions < V2.2), LOGO! CMR2040 (All versions < V2.2), SIMATIC RTU3010C (All versions < V4.0.9), SIMATIC RTU3030C (All versions < V4.0.9), SIMATIC RTU3031C (All v...Show more |
1Booster 1Booster For Woocommerce Jun 17, 2026 Aug 30, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Versions up to, and including, 5.4.3, of the Booster for WooCommerce WordPress plugin are vulnerable to authentication bypass via the process_email_verification function due to a random token generation weakness in the r...Show more |
2Hcc Embedded Siemens3Nichestack Sentron 3wa Com190 FirmwareSentron 3wl Com35 FirmwareJun 17, 2026 Aug 19, 2021 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 An issue was discovered in HCC Nichestack 3.0. The code that generates Initial Sequence Numbers (ISNs) for TCP connections derives the ISN from an insufficiently random source. As a result, an attacker may be able to det...Show more |
An issue was discovered in HCC embedded InterNiche 4.0.1. This vulnerability allows the attacker to predict a DNS query's source port in order to send forged DNS response packets that will be accepted as valid answers to...Show more |