CWE-330
380 CVEs • Abstraction: Class • Likelihood of Exploit: High
Use of Insufficiently Random Values
The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.
CVEs (380)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The WP Database Backup plugin through 5.5 for WordPress stores downloads by default locally in the directory wp-content/uploads/db-backup/. This might allow attackers to read ZIP archives by guessing random ID numbers, g...Show more |
3Debian LinuxNetapp148300 Firmware 8700 FirmwareA400 Firmware+11 moreJun 17, 2026 Jan 16, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The flow_dissector feature in the Linux kernel 4.3 through 5.x before 5.3.10 has a device tracking vulnerability, aka CID-55667441c84f. This occurs because the auto flowlabel of a UDP IPv6 packet relies on a 32-bit hashr...Show more |
Joomla! core before 2.5.3 allows unauthorized password change. |
1Microsoft 6Windows 10 Windows 8.1Windows Rt 8.1+3 moreJun 17, 2026 Jan 14, 2020 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 An elevation of privilege vulnerability exists when Microsoft Windows implements predictable memory section names, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0635. |
1Weidmueller 40Ie Sw Pl08m 6tx 2sc Firmware Ie Sw Pl08m 6tx 2scs FirmwareIe Sw Pl08m 6tx 2st Firmware+37 moreJun 17, 2026 Dec 6, 2019 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Build 16102415, IE-SW-VL08MT 3.5.2 Build 16102415, and IE-SW-PL10M 3.3.16 Build 16102416 devices. Authentication Information used in a cookie is predictable and ca...Show more |
TrevorC2 v1.1/v1.2 fails to prevent fingerprinting primarily via a discrepancy between response headers when responding to different HTTP methods, also via predictible responses when accessing and interacting with the "S...Show more |
1Huawei 3Vp9630 Firmware Vp9650 FirmwareVp9660 FirmwareJun 17, 2026 Nov 29, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 There is a use of insufficiently random values vulnerability in Huawei ViewPoint products. An unauthenticated, remote attacker can guess information by a large number of attempts. Successful exploitation may cause inform...Show more |
3Ethz FedoraprojectRedhat3Enterprise Linux FedoraXquestNov 21, 2024 Nov 27, 2019 N/A· v4 2.5 LOW· v3 1.9 LOW· v2 A password generation weakness exists in xquest through 2016-06-13. |
2Debian Vanderbilt2Adaptive Communication Environment Debian LinuxNov 21, 2024 Nov 22, 2019 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 generate_doygen.pl in ace before 6.2.7+dfsg-2 creates predictable file names in the /tmp directory which allows attackers to gain elevated privileges. |
IBM Cognos Controller 10.3.0, 10.3.1, 10.4.0, and 10.4.1 could allow an authenticated user to obtain sensitive information due to easy to guess session identifier names. IBM X-Force ID: 162658. |
A vulnerability, in Brocade SANnav versions before v2.0, could allow remote attackers to brute-force a valid session ID. The vulnerability is due to an insufficiently random session ID for several post-authentication act...Show more |
In Apache Impala 2.7.0 to 3.2.0, an authenticated user with access to the IDs of active Impala queries or sessions can interact with those sessions or queries via a specially-constructed request and thereby potentially b...Show more |
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 contains insecure randomness in the uniqid function. |
1Cryptocat Project 1Cryptocat Nov 21, 2024 Nov 4, 2019 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 Cryptocat before 2.0.22 strophe.js Math.random() Random Number Generator Weakness |
A vulnerability has been identified in SIMATIC IT UADM (All versions < V1.3). An authenticated remote attacker with network access to port 1434/tcp of SIMATIC IT UADM could potentially recover a password that can be used...Show more |
The token generator in index.php in Centreon Web before 2.8.27 is predictable. |
1Qualcomm 47Mdm9205 Firmware Mdm9206 FirmwareMdm9607 Firmware+44 moreJun 17, 2026 Sep 30, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Usage of hard-coded magic number for calculating heap guard bytes can allow users to corrupt heap blocks without heap algorithm knowledge in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consum...Show more |
OpenSSL 1.1.1 introduced a rewritten random number generator (RNG). This was intended to include protection in the event of a fork() system call in order to ensure that the parent and child processes did not share the sa...Show more |
An issue was discovered in Total.js CMS 12.0.0. A low privilege user can perform a simple transformation of a cookie to obtain the random values inside it. If an attacker can discover a session cookie owned by an admin,...Show more |
The Recruitment module in Humanica Humatrix 7 1.0.0.203 and 1.0.0.681 allows an unauthenticated attacker to upload any file type to a candidate's profile picture folder via a crafted recruitment_online/personalData/act_p...Show more |