CWE-330
380 CVEs • Abstraction: Class • Likelihood of Exploit: High
Use of Insufficiently Random Values
The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.
CVEs (380)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Dahuasecurity 20Ipc Hdbw1320e W Firmware Ipc Hx2xxx FirmwareIpc Hx5842h Firmware+17 moreJun 17, 2026 May 13, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Some Dahua products with Build time before December 2019 have Session ID predictable vulnerabilities. During normal user access, an attacker can use the predicted Session ID to construct a data packet to attack the devic...Show more |
The OKLOK (3.1.1) mobile companion app for Fingerprint Bluetooth Padlock FB50 (2.3) has an information-exposure issue. In the mobile app, an attempt to add an already-bound lock by its barcode reveals the email address o...Show more |
React Native Bluetooth Scan in Bluezone 1.0.0 uses six-character alphanumeric IDs, which might make it easier for remote attackers to interfere with COVID-19 contact tracing by using many IDs. NOTE: the vendor disputes t...Show more |
airhost.exe in Zoom Client for Meetings 4.6.11 uses 3423423432325249 as the Initialization Vector (IV) for AES-256 CBC encryption. NOTE: the vendor states that this IV is used only within unreachable code |
3Fedoraproject LinuxfoundationRedhat5Ceph Ceph StorageFedora+2 moreJun 17, 2026 Apr 13, 2020 N/A· v4 6.8 MEDIUM· v3 5.8 MEDIUM· v2 A vulnerability was found in Red Hat Ceph Storage 4 and Red Hat Openshift Container Storage 4.2 where, A nonce reuse vulnerability was discovered in the secure mode of the messenger v2 protocol, which can allow an attack...Show more |
There is an information disclosure issue in DNN (formerly DotNetNuke) 9.5 within the built-in Activity-Feed/Messaging/Userid/ Message Center module. A registered user is able to enumerate any file in the Admin File Manag...Show more |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraGnutls+2 moreJun 17, 2026 Apr 3, 2020 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 GnuTLS 3.6.x before 3.6.13 uses incorrect cryptography for DTLS. The earliest affected version is 3.6.3 (2018-07-16) because of an error in a 2017-10-06 commit. The DTLS client always uses 32 '\0' bytes instead of a rand...Show more |
Zim through 0.72.1 creates temporary directories with predictable names. A malicious user could predict and create Zim's temporary directories and prevent other users from being able to start Zim, resulting in a denial o...Show more |
In cPanel before 82.0.18, Cpanel::Rand::Get can produce a predictable series of numbers (SEC-525). |
1Opcfoundation 2Netstandard.opc.ua Ua .netstandardJun 17, 2026 Mar 16, 2020 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 In OPC Foundation OPC UA .NET Standard codebase 1.4.357.28, servers do not create sufficiently random numbers in OPCFoundation.NetStandard.Opc.Ua before 1.4.359.31, which allows man in the middle attackers to reuse encry...Show more |
1Moxa 6Mb3170 Firmware Mb3180 FirmwareMb3270 Firmware+3 moreJun 17, 2026 Mar 11, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1. A predictable mechanism of generating tokens all...Show more |
An issue was discovered in GitLab Community and Enterprise Edition 10.6 through 11.11. Users could guess the URL slug of private projects through the contrast of the destination URLs of issues linked in comments. It allo...Show more |
1Qualcomm 20Msm8905 Firmware Msm8909 FirmwareMsm8917 Firmware+17 moreJun 17, 2026 Mar 5, 2020 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 The secret key used to make the Initial Sequence Number in the TCP SYN packet could be brute forced and therefore can be predicted in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IO...Show more |
A flaw was found in all versions of the Keycloak operator, before version 8.0.2,(community only) where the operator generates a random admin password when installing Keycloak, however the password remains the same when d...Show more |
1Justblab 4Blab! Ax Blab! Ax ProBlab! Ws+1 moreJun 17, 2026 Feb 28, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 An insecure random number generation vulnerability in BlaB! AX, BlaB! AX Pro, BlaB! WS (client), and BlaB! WS Pro (client) version 19.11 allows an attacker (with a guest or user session cookie) to escalate privileges by...Show more |
The Voatz application 2020-01-01 for Android allows only 100 million different PINs, which makes it easier for attackers (after using root access to make a copy of the local database) to discover login credentials and vo...Show more |
3Canonical DebianOpensuse3Cloud Init Debian LinuxLeapJun 17, 2026 Feb 5, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 cloud-init through 19.4 relies on Mersenne Twister for a random password, which makes it easier for attackers to predict passwords, because rand_str in cloudinit/util.py calls the random.choice function. |
Jenkins 2.213 and earlier, LTS 2.204.1 and earlier improperly reuses encryption key parameters in the Inbound TCP Agent Protocol/3, allowing unauthorized attackers with knowledge of agent names to obtain the connection s...Show more |
2Fedoraproject Pyrad Project2Fedora PyradNov 21, 2024 Jan 28, 2020 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 packet.py in pyrad before 2.1 uses weak random numbers to generate RADIUS authenticators and hash passwords, which makes it easier for remote attackers to obtain sensitive information via a brute force attack. |
1Neatorobotics 1Botvac Connected Firmware Nov 21, 2024 Jan 27, 2020 N/A· v4 4.7 MEDIUM· v3 1.9 LOW· v2 An issue was discovered in Neato Botvac Connected 2.2.0. The GenerateRobotPassword function of the NeatoCrypto library generates insufficiently random numbers for robot secret_key values used for local and cloud authenti...Show more |