CWE-330— Use of Insufficiently Random Values
The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.— MITRE CWE catalog
412 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-330page 1 of 9
- CVE-2020-1472CRITICALCVSS 10.0EG 10.0⚠ KEV2020-08-17
An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Protocol (MS-NRPC). An attacker who successfully exploited the vu…
- CVE-2023-22601CRITICALCVSS 10.0EG 10.02023-01-12
InHand Networks InRouter 302, prior to version IR302 V3.5.56, and InRouter 615, prior to version InRouter6XX-S-V2.3.0.r5542, contain vulnerability CWE-330: Use of Insufficiently Random Values. They do not properly randomize MQTT ClientI…
- CVE-2021-40422CRITICALCVSS 10.0EG 10.02022-04-14
An authentication bypass vulnerability exists in the device password generation functionality of Swift Sensors Gateway SG3-1010. A specially-crafted network request can lead to remote code execution. An attacker can send a sequence of requ…
- CVE-2019-0007CRITICALCVSS 9.3EG 10.02019-01-15
The vMX Series software uses a predictable IP ID Sequence Number. This leaves the system as well as clients connecting through the device susceptible to a family of attacks which rely on the use of predictable IP ID sequence numbers as the…
- CVE-2026-25072CRITICALCVSS 9.8EG 9.82026-03-07
XikeStor SKS8310-8X Network Switch firmware versions 1.04.B07 and prior contain a predictable session identifier vulnerability in the /goform/SetLogin endpoint that allows remote attackers to hijack authenticated sessions. Attackers can pr…
- CVE-2026-27755CRITICALCVSS 9.8EG 9.82026-02-27
SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a weak session identifier generation vulnerability that allows attackers to forge authenticated sessions by computing predictable MD5-based cookies. Attackers who know or g…
- CVE-2026-27637CRITICALCVSS 9.8EG 9.82026-02-25
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.206, FreeScout's `TokenAuth` middleware uses a predictable authentication token computed as `MD5(user_id + created_at + APP_KEY)`. This…
- CVE-2025-64097CRITICALCVSS 9.8EG 9.82026-01-22
NervesHub is a web service that allows users to manage over-the-air (OTA) firmware updates of devices in the field. A vulnerability present starting in version 1.0.0 and prior to version 2.3.0 allowed attackers to brute-force user API toke…
- CVE-2025-4607CRITICALCVSS 9.8EG 9.82025-05-31
The PSW Front-end Login & Registration plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.12 via the customer_registration() function. This is due to the use of a weak, low-entropy OTP mechan…
- CVE-2024-36389CRITICALCVSS 9.8EG 9.82024-06-02
MileSight DeviceHub - CWE-330 Use of Insufficiently Random Values may allow Authentication Bypass
- CVE-2023-46740CRITICALCVSS 9.8EG 9.82024-01-03
CubeFS is an open-source cloud-native file storage system. Prior to version 3.3.1, CubeFS used an insecure random string generator to generate user-specific, sensitive keys used to authenticate users in a CubeFS deployment. This could allo…
- CVE-2020-27631CRITICALCVSS 9.8EG 9.82023-10-10
In Oryx CycloneTCP 1.9.6, TCP ISNs are improperly random.
- CVE-2020-27630CRITICALCVSS 9.8EG 9.82023-10-10
In Silicon Labs uC/TCP-IP 3.6.0, TCP ISNs are improperly random.
- CVE-2023-39979CRITICALCVSS 9.8EG 9.82023-09-02
There is a vulnerability in MXsecurity versions prior to 1.0.1 that can be exploited to bypass authentication. A remote attacker might access the system if the web service authenticator has insufficient random values.
- CVE-2023-4344CRITICALCVSS 9.8EG 9.82023-08-15
Broadcom RAID Controller web interface is vulnerable to insufficient randomness due to improper use of ssl.rnd to setup CIM connection
- CVE-2023-2884CRITICALCVSS 9.8EG 9.82023-05-25
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG), Use of Insufficiently Random Values vulnerability in CBOT Chatbot allows Signature Spoofing by Key Recreation. This issue affects Chatbot: before Core: v4.0.3.4 Panel: v…
- CVE-2022-46353CRITICALCVSS 9.8EG 9.82022-12-13
A vulnerability has been identified in SCALANCE X204RNA (HSR) (All versions < V3.2.7), SCALANCE X204RNA (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (HSR) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP) (All versions < V3.2.7), …
- CVE-2022-44938CRITICALCVSS 9.8EG 9.82022-12-08
Weak reset token generation in SeedDMS v6.0.20 and v5.1.7 allows attackers to execute a full account takeover via a brute force attack.
- CVE-2022-36536CRITICALCVSS 9.8EG 9.82022-09-16
An issue in the component post_applogin.php of Super Flexible Software GmbH & Co. KG Syncovery 9 for Linux v9.47x and below allows attackers to escalate privileges via creating crafted session tokens.
- CVE-2022-25752CRITICALCVSS 9.8EG 9.82022-04-12
A vulnerability has been identified in SCALANCE X302-7 EEC (230V), SCALANCE X302-7 EEC (230V, coated), SCALANCE X302-7 EEC (24V), SCALANCE X302-7 EEC (24V, coated), SCALANCE X302-7 EEC (2x 230V), SCALANCE X302-7 EEC (2x 230V, coated), SCAL…
- CVE-2021-36166CRITICALCVSS 9.8EG 9.82022-03-01
An improper authentication vulnerability in FortiMail before 7.0.1 may allow a remote attacker to efficiently guess one administrative account's authentication token by means of the observation of certain system's properties.
- CVE-2022-22922CRITICALCVSS 9.8EG 9.82022-02-18
TP-Link TL-WA850RE Wi-Fi Range Extender before v6_200923 was discovered to use highly predictable and easily detectable session keys, allowing attackers to gain administrative privileges.
- CVE-2021-36294CRITICALCVSS 9.8EG 9.82022-01-25
Dell VNX2 OE for File versions 8.1.21.266 and earlier, contain an authentication bypass vulnerability. A remote unauthenticated attacker may exploit this vulnerability by forging a cookie to login as any user.
- CVE-2021-41694CRITICALCVSS 9.8EG 9.82021-12-09
An Incorrect Access Control vulnerability exists in Premiumdatingscript 4.2.7.7 via the password change procedure in requests\user.php.
- CVE-2021-28024CRITICALCVSS 9.8EG 9.82021-11-08
Unauthorized system access in the login form in ServiceTonic Helpdesk software version < 9.0.35937 allows attacker to login without using a password.
- CVE-2021-34646CRITICALCVSS 9.8EG 9.82021-08-30
Versions up to, and including, 5.4.3, of the Booster for WooCommerce WordPress plugin are vulnerable to authentication bypass via the process_email_verification function due to a random token generation weakness in the reset_and_mail_activ…
- CVE-2021-38606CRITICALCVSS 9.8EG 9.82021-08-12
reNgine through 0.5 relies on a predictable directory name.
- CVE-2021-27200CRITICALCVSS 9.8EG 9.82021-06-11
In WoWonder 3.0.4, remote attackers can take over any account due to the weak cryptographic algorithm in recover.php. The code parameter is easily predicted from the time of day.
- CVE-2020-35926CRITICALCVSS 9.8EG 9.82020-12-31
An issue was discovered in the nanorand crate before 0.5.1 for Rust. It caused any random number generator (even ChaCha) to return all zeroes because integer truncation was mishandled.
- CVE-2020-7548CRITICALCVSS 9.8EG 9.82020-12-01
A CWE-330 - Use of Insufficiently Random Values vulnerability exists in Smartlink, PowerTag, and Wiser Series Gateways (see security notification for version information) that could allow unauthorized users to login.
- CVE-2020-27743CRITICALCVSS 9.8EG 9.82020-10-26
libtac in pam_tacplus through 1.5.1 lacks a check for a failure of RAND_bytes()/RAND_pseudo_bytes(). This could lead to use of a non-random/predictable session_id.
- CVE-2020-9502CRITICALCVSS 9.8EG 9.82020-05-13
Some Dahua products with Build time before December 2019 have Session ID predictable vulnerabilities. During normal user access, an attacker can use the predicted Session ID to construct a data packet to attack the device.
- CVE-2019-2317CRITICALCVSS 9.8EG 9.82020-03-05
The secret key used to make the Initial Sequence Number in the TCP SYN packet could be brute forced and therefore can be predicted in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, …
- CVE-2019-16674CRITICALCVSS 9.8EG 9.82019-12-06
An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Build 16102415, IE-SW-VL08MT 3.5.2 Build 16102415, and IE-SW-PL10M 3.3.16 Build 16102416 devices. Authentication Information used in a cookie is predictable and can lead to admin pas…
- CVE-2014-6311CRITICALCVSS 9.8EG 9.82019-11-22
generate_doygen.pl in ace before 6.2.7+dfsg-2 creates predictable file names in the /tmp directory which allows attackers to gain elevated privileges.
- CVE-2019-2294CRITICALCVSS 9.8EG 9.82019-09-30
Usage of hard-coded magic number for calculating heap guard bytes can allow users to corrupt heap blocks without heap algorithm knowledge in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Conn…
- CVE-2019-15130CRITICALCVSS 9.8EG 9.82019-08-18
The Recruitment module in Humanica Humatrix 7 1.0.0.203 and 1.0.0.681 allows an unauthenticated attacker to upload any file type to a candidate's profile picture folder via a crafted recruitment_online/personalData/act_personaltab.cfm mult…
- CVE-2019-7667CRITICALCVSS 9.8EG 9.82019-07-01
Prima Systems FlexAir, Versions 2.3.38 and prior. The application generates database backup files with a predictable name, and an attacker can use brute force to identify the database backup file name. A malicious actor can exploit this is…
- CVE-2019-9863CRITICALCVSS 9.8EG 9.82019-03-27
Due to the use of an insecure algorithm for rolling codes in the ABUS Secvest wireless alarm system FUAA50000 3.01.01 and its remote controls FUBE50014 and FUBE50015, an attacker is able to predict valid future rolling codes, and can thus …
- CVE-2019-5420CRITICALCVSS 9.8EG 9.82019-03-27
A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess the automatically generated development mode secret token. This secret token can be used in combination with other Rails …
- CVE-2019-9898CRITICALCVSS 9.8EG 9.82019-03-21
Potential recycling of random numbers used in cryptography exists within PuTTY before 0.71.
- CVE-2019-0729CRITICALCVSS 9.8EG 9.82019-03-05
An Elevation of Privilege vulnerability exists in the way Azure IoT Java SDK generates symmetric keys for encryption, allowing an attacker to predict the randomness of the key, aka 'Azure IoT Java SDK Elevation of Privilege Vulnerability'.
- CVE-2018-18602CRITICALCVSS 9.8EG 9.82018-12-31
The Cloud API on Guardzilla smart cameras allows user enumeration, with resultant arbitrary camera access and monitoring.
- CVE-2018-18531CRITICALCVSS 9.8EG 9.82018-10-19
text/impl/DefaultTextCreator.java, text/impl/ChineseTextProducer.java, and text/impl/FiveLetterFirstNameTextCreator.java in kaptcha 2.3.2 use the Random (rather than SecureRandom) function for generating CAPTCHA values, which makes it easi…
- CVE-2018-18375CRITICALCVSS 9.8EG 9.82018-10-16
goform/getProfileList in Orange AirBox Y858_FL_01.16_04 allows attackers to extract APN data (name, number, username, and password) via the rand parameter.
- CVE-2018-17888CRITICALCVSS 9.8EG 9.82018-10-12
NUUO CMS all versions 3.1 and prior, The application uses a session identification mechanism that could allow attackers to obtain the active session ID, which could allow arbitrary remote code execution.
- CVE-2018-16239CRITICALCVSS 9.8EG 9.82018-08-30
An issue was discovered in damiCMS V6.0.1. It relies on the PHP time() function for cookies, which makes it possible to determine the cookie for an existing admin session via 10800 guesses.
- CVE-2017-16924CRITICALCVSS 9.8EG 9.82018-02-19
Remote Information Disclosure and Escalation of Privileges in ManageEngine Desktop Central MSP 10.0.137 allows attackers to download unencrypted XML files containing all data for configuration policies via a predictable /client-data/<clien…
- CVE-2017-7905CRITICALCVSS 9.8EG 9.82017-06-30
A Weak Cryptography for Passwords issue was discovered in General Electric (GE) Multilin SR 750 Feeder Protection Relay, firmware versions prior to Version 7.47; SR 760 Feeder Protection Relay, firmware versions prior to Version 7.47; SR 4…
- CVE-2017-7902CRITICALCVSS 9.8EG 9.82017-06-30
A "Reusing a Nonce, Key Pair in Encryption" issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1100 programmable-logic controllers 1763-L16AWA, Series A and B, Version 16.00 and prior versions; 1763-L16BBB, Series A and B…
Map vulnerabilities like CWE-330 to your infrastructure
EchelonGraph correlates every CVE — across CWE-330 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →