← Back
CWE-330

380 CVEs • Abstraction: Class • Likelihood of Exploit: High

Use of Insufficiently Random Values

The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.

JSON object

Loading...

CVEs (380)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Schneider Electric
2Modicon M241 Firmware
Modicon M251 Firmware
May 13, 2026
Jun 30, 2017
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
A Use of Insufficiently Random Values issue was discovered in Schneider Electric Modicon PLCs Modicon M241, firmware versions prior to Version 4.0.5.11, and Modicon M251, firmware versions prior to Version 4.0.5.11. The...Show more
A Use of Insufficiently Random Values issue was discovered in Schneider Electric Modicon PLCs Modicon M241, firmware versions prior to Version 4.0.5.11, and Modicon M251, firmware versions prior to Version 4.0.5.11. The session numbers generated by the web application are lacking randomization and are shared between several users. This may allow a current session to be compromised.Show less
1Expressionengine
1Expressionengine
May 13, 2026
Jun 22, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
ExpressionEngine version 2.x < 2.11.8 and version 3.x < 3.5.5 create an object signing token with weak entropy. Successfully guessing the token can lead to remote code execution.
1Aescrypt Project
1Aescrypt
May 13, 2026
Apr 19, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The aescrypt gem 1.0.0 for Ruby does not randomize the CBC IV for use with the AESCrypt.encrypt and AESCrypt.decrypt functions, which allows attackers to defeat cryptographic protection mechanisms via a chosen plaintext...Show more
The aescrypt gem 1.0.0 for Ruby does not randomize the CBC IV for use with the AESCrypt.encrypt and AESCrypt.decrypt functions, which allows attackers to defeat cryptographic protection mechanisms via a chosen plaintext attack.Show less
1Xmlsoft
1Libxslt
May 13, 2026
Apr 5, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In libxslt 1.1.29 and earlier, the EXSLT math.random function was not initialized with a random seed during startup, which could cause usage of this function to produce predictable outputs.
1Froxlor
1Froxlor
May 13, 2026
Feb 13, 2017
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Froxlor before 0.9.35 uses the PHP rand function for random number generation, which makes it easier for remote attackers to guess the password reset token by predicting a value.
1Dlink
1Dwr 932b Firmware
May 13, 2026
Jan 30, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered on the D-Link DWR-932B router. WPS PIN generation is based on srand(time(0)) seeding.
1Animas
1Onetouch Ping Firmware
May 6, 2026
Oct 5, 2016
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Johnson & Johnson Animas OneTouch Ping devices do not properly generate random numbers, which makes it easier for remote attackers to spoof meters by sniffing the network and then engaging in an authentication handshake.
1Windriver
1Vxworks
May 6, 2026
Aug 4, 2015
N/A· v4
N/A· v3
5.8 MEDIUM· v2
Wind River VxWorks before 5.5.1, 6.5.x through 6.7.x before 6.7.1.1, 6.8.x before 6.8.3, 6.9.x before 6.9.4.4, and 7.x before 7 ipnet_coreip 1.2.2.0, as used on Schneider Electric SAGE RTU devices before J2 and other dev...Show more
Wind River VxWorks before 5.5.1, 6.5.x through 6.7.x before 6.7.1.1, 6.8.x before 6.8.3, 6.9.x before 6.9.4.4, and 7.x before 7 ipnet_coreip 1.2.2.0, as used on Schneider Electric SAGE RTU devices before J2 and other devices, does not properly generate TCP initial sequence number (ISN) values, which makes it easier for remote attackers to spoof TCP sessions by predicting an ISN value.Show less
1Siemens
1Ruggedcom Rugged Operating System
Apr 29, 2026
Dec 17, 2013
N/A· v4
N/A· v3
8.3 HIGH· v2
The integrated HTTPS server in Siemens RuggedCom ROS before 3.12.2 allows remote attackers to hijack web sessions by predicting a session id value.
2Digital Alert Systems
Monroe Electronics
2Dasdec Eas
R189 One Net Eas
Jun 2, 2026
Jun 30, 2013
N/A· v4
7.3 HIGH· v3
7.5 HIGH· v2
dasdec_mkuser on the Digital Alert Systems DASDEC EAS device before 2.0-2 and the Monroe Electronics R189 One-Net EAS device before 2.0-2 generates predictable passwords, which might make it easier for attackers to obtai...Show more
dasdec_mkuser on the Digital Alert Systems DASDEC EAS device before 2.0-2 and the Monroe Electronics R189 One-Net EAS device before 2.0-2 generates predictable passwords, which might make it easier for attackers to obtain non-administrative access via unspecified vectors.Show less
1Torrenttrader Project
1Torrenttrader
Apr 23, 2026
Jun 22, 2009
N/A· v4
7.5 HIGH· v3
7.5 HIGH· v2
account-recover.php in TorrentTrader Classic 1.09 chooses random passwords from an insufficiently large set, which makes it easier for remote attackers to obtain a password via a brute-force attack.
2Debian
Typo3
2Debian Linux
Typo3
Apr 23, 2026
Jan 22, 2009
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The System extension Install tool in TYPO3 4.0.0 through 4.0.9, 4.1.0 through 4.1.7, and 4.2.0 through 4.2.3 creates the encryption key with an insufficiently random seed, which makes it easier for attackers to crack the...Show more
The System extension Install tool in TYPO3 4.0.0 through 4.0.9, 4.1.0 through 4.1.7, and 4.2.0 through 4.2.3 creates the encryption key with an insufficiently random seed, which makes it easier for attackers to crack the key.Show less
1Freebsd
1Freebsd
Apr 23, 2026
Nov 26, 2008
N/A· v4
7.0 HIGH· v3
6.9 MEDIUM· v2
The arc4random function in the kernel in FreeBSD 6.3 through 7.1 does not have a proper entropy source for a short time period immediately after boot, which makes it easier for attackers to predict the function's return...Show more
The arc4random function in the kernel in FreeBSD 6.3 through 7.1 does not have a proper entropy source for a short time period immediately after boot, which makes it easier for attackers to predict the function's return values and conduct certain attacks against the GEOM framework and various network protocols, related to the Yarrow random number generator.Show less
1Mybb
1Mybb
Apr 23, 2026
Nov 4, 2008
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
MyBB (aka MyBulletinBoard) 1.4.2 uses insufficient randomness to compose filenames of uploaded files used as attachments, which makes it easier for remote attackers to read these files by guessing filenames.
1Typosphere
1Typo
Apr 23, 2026
Nov 4, 2008
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Typo 5.1.3 and earlier uses a hard-coded salt for calculating password hashes, which makes it easier for attackers to guess passwords via a brute force attack.
1Apple
1Iphone Os
Apr 23, 2026
Sep 11, 2008
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The Networking subsystem in Apple iPod touch 2.0 through 2.0.2, and iPhone 2.0 through 2.0.2, uses predictable TCP initial sequence numbers, which allows remote attackers to spoof or hijack a TCP connection.
1Trendmicro
3Client Server Messaging Suite
OfficescanWorry Free Business Security
Apr 23, 2026
Aug 27, 2008
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The web management console in Trend Micro OfficeScan 7.0 through 8.0, Worry-Free Business Security 5.0, and Client/Server/Messaging Suite 3.5 and 3.6 creates a random session token based only on the login time, which mak...Show more
The web management console in Trend Micro OfficeScan 7.0 through 8.0, Worry-Free Business Security 5.0, and Client/Server/Messaging Suite 3.5 and 3.6 creates a random session token based only on the login time, which makes it easier for remote attackers to hijack sessions via brute-force attacks. NOTE: this can be leveraged for code execution through an unspecified "manipulation of the configuration."Show less
8E107
LabgabMy123tkshop+5 more
8E Commerce Suite
E107Labgab+5 more
Apr 23, 2026
Apr 30, 2008
N/A· v4
7.5 HIGH· v3
6.8 MEDIUM· v2
The CAPTCHA implementation as used in (1) Francisco Burzi PHP-Nuke 7.0 and 8.1, (2) my123tkShop e-Commerce-Suite (aka 123tkShop) 0.9.1, (3) phpMyBitTorrent 1.2.2, (4) TorrentFlux 2.3, (5) e107 0.7.11, (6) WebZE 0.5.9, (7...Show more
The CAPTCHA implementation as used in (1) Francisco Burzi PHP-Nuke 7.0 and 8.1, (2) my123tkShop e-Commerce-Suite (aka 123tkShop) 0.9.1, (3) phpMyBitTorrent 1.2.2, (4) TorrentFlux 2.3, (5) e107 0.7.11, (6) WebZE 0.5.9, (7) Open Media Collectors Database (aka OpenDb) 1.5.0b4, and (8) Labgab 1.1 uses a code_bg.jpg background image and the PHP ImageString function in a way that produces an insufficient number of different images, which allows remote attackers to pass the CAPTCHA test via an automated attack using a table of all possible image checksums and their corresponding digit strings.Show less
1Microsoft
4Windows 2000
Windows Server 2003Windows Vista+1 more
Apr 23, 2026
Apr 8, 2008
N/A· v4
7.5 HIGH· v3
8.8 HIGH· v2
The DNS client in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, and Vista uses predictable DNS transaction IDs, which allows remote attackers to spoof DNS responses.
1Webportal Cms Project
1Webportal Cms
Apr 23, 2026
Jan 8, 2008
N/A· v4
7.5 HIGH· v3
7.5 HIGH· v2
actions.php in WebPortal CMS 0.6-beta generates predictable passwords containing only the time of day, which makes it easier for remote attackers to obtain access to any account via a lostpass action.