CWE-330— Use of Insufficiently Random Values
The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.— MITRE CWE catalog
412 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-330page 2 of 9
- CVE-2016-5100CRITICALCVSS 9.8EG 9.82017-02-13
Froxlor before 0.9.35 uses the PHP rand function for random number generation, which makes it easier for remote attackers to guess the password reset token by predicting a value.
- CVE-2022-42787CRITICALCVSS 8.8EG 9.82022-11-10
Multiple W&T products of the Comserver Series use a small number space for allocating sessions ids. After login of an user an unathenticated remote attacker can brute force the users session id and get access to his account on the the devi…
- CVE-2022-26647CRITICALCVSS 8.8EG 9.82022-07-12
A vulnerability has been identified in SCALANCE X200-4P IRT (All versions < V5.5.2), SCALANCE X201-3P IRT (All versions < V5.5.2), SCALANCE X201-3P IRT PRO (All versions < V5.5.2), SCALANCE X202-2IRT (All versions < V5.5.2), SCALANCE X202-…
- CVE-2020-35163CRITICALCVSS 5.3EG 9.82022-07-11
Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain a Use of Insufficiently Random Values Vulnerability.
- CVE-2026-80154CRITICALCVSS 9.6EG 9.62026-09-22
All firmware versions of Lantronix SLC8000, SLC9000, EMG8500, EMG7500, SLB882, SLCx-03, and SLCx-02 contain an authentication bypass vulnerability in the web management portal that allows unauthenticated attackers to derive valid session t…
- CVE-2026-50208CRITICALCVSS 9.4EG 9.42026-06-04
High-risk TrustAllCerts routines disable standard TLS certificate validation. Combined with hard-coded DES symmetric encryption keys, a Man-in-the-Middle (MITM) actor could decrypt network traffic.
- CVE-2025-7783CRITICALCVSS 9.4EG 9.42025-07-18
Use of Insufficiently Random Values vulnerability in form-data allows HTTP Parameter Pollution (HPP). This vulnerability is associated with program files lib/form_data.Js. This issue affects form-data: < 2.5.4, 3.0.0 - 3.0.3, 4.0.0 - 4.0.…
- CVE-2023-1898CRITICALCVSS 9.4EG 9.42023-06-12
Atlas Copco Power Focus 6000 web server uses a small amount of session ID numbers. An attacker could enter a session ID number to retrieve data for an active user’s session.
- CVE-2026-19485CRITICALCVSS 9.3EG 9.32026-08-26
A Predictable Resource Name vulnerability in BigQuery Import Staging in Google Cloud Vertex AI Search for Commerce versions prior to 2026-04-27 on Google Cloud Platform allows an attacker knowing the victim's project number to obtain read/…
- CVE-2026-42155CRITICALCVSS 9.3EG 9.32026-05-15
Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platform with a high level of backward compatibility. Prior to 20.18.0, the XML-RPC / SOAP API s…
- CVE-2025-13955CRITICALCVSS 9.3EG 9.32025-12-10
Predictable default Wi-Fi Password in Access Point functionality in EZCast Pro II before version 1.17478.177 allows attackers in Wi-Fi range to gain access to the dongle by calculating the default password from observable device identif…
- CVE-2026-94456CRITICALCVSS 9.1EG 9.12026-09-22
Postiz generates security-sensitive credentials using `Math.random()` instead of a cryptographically secure source. The same helper is used for OAuth access tokens, authorization codes, client secrets, organization API keys, and PKCE verif…
- CVE-2026-53939CRITICALCVSS 9.1EG 9.12026-09-08
OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE). In versions 0.6.1 through 0.6.2.5, when cjose encrypts a JWE using an AES-CBC-HMAC content-encryption algorithm (`A128CBC-HS256`, `A192CBC-HS384…
- CVE-2026-62862CRITICALCVSS 9.1EG 9.12026-08-25
Typebot is an open-source chatbot builder. In self-hosted versions up to and including 3.17.1, the default passwordless email magic-link authentication is vulnerable to login-code brute forcing that leads to account takeover. The email pro…
- CVE-2026-40496CRITICALCVSS 9.1EG 9.12026-04-21
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, attachment download tokens are generated using a weak and predictable formula: `md5(APP_KEY + attachment_id + size)`. Since attachment_id is sequential…
- CVE-2026-27515CRITICALCVSS 9.1EG 9.12026-02-24
Binardat 10G08-0800GSM network switch firmware versions prior to V300SP10260209 generate predictable numeric session identifiers in the web management interface. An attacker can guess valid session IDs and hijack authenticated sessions.
- CVE-2024-1631CRITICALCVSS 9.1EG 9.12024-02-21
Impact: The library offers a function to generate an ed25519 key pair via Ed25519KeyIdentity.generate with an optional param to provide a 32 byte seed value, which will then be used as the secret key. When no seed value is provided, it is …
- CVE-2020-27636CRITICALCVSS 9.1EG 9.12023-10-10
In Microchip MPLAB Net 3.6.1, TCP ISNs are improperly random.
- CVE-2020-27635CRITICALCVSS 9.1EG 9.12023-10-10
In PicoTCP 1.7.0, TCP ISNs are improperly random.
- CVE-2020-27634CRITICALCVSS 9.1EG 9.12023-10-10
In Contiki 4.5, TCP ISNs are improperly random.
- CVE-2020-27633CRITICALCVSS 9.1EG 9.12023-10-10
In FNET 4.6.3, TCP ISNs are improperly random.
- CVE-2022-43501CRITICALCVSS 9.1EG 9.12023-02-10
KASAGO TCP/IP stack provided by Zuken Elmic generates ISNs(Initial Sequence Number) for TCP connections from an insufficiently random source. An attacker may be able to determine the ISN of the current or future TCP connections and either …
- CVE-2022-30935CRITICALCVSS 9.1EG 9.12022-09-28
An authorization bypass in b2evolution allows remote, unauthenticated attackers to predict password reset tokens for any user through the use of a bad randomness function. This allows the attacker to get valid sessions for arbitrary users,…
- CVE-2022-27577CRITICALCVSS 9.1EG 9.12022-04-11
The vulnerability in the MSC800 in all versions before 4.15 allows for an attacker to predict the TCP initial sequence number. When the TCP sequence is predictable, an attacker can send packets that are forged to appear to come from a trus…
- CVE-2022-26851CRITICALCVSS 9.1EG 9.12022-04-08
Dell PowerScale OneFS, 8.2.2-9.3.x, contains a predictable file name from observable state vulnerability. An unprivileged network attacker could potentially exploit this vulnerability, leading to data loss.
- CVE-2022-26320CRITICALCVSS 9.1EG 9.12022-03-14
The Rambus SafeZone Basic Crypto Module before 10.4.0, as used in certain Fujifilm (formerly Fuji Xerox) devices before 2022-03-01, Canon imagePROGRAF and imageRUNNER devices through 2022-03-14, and potentially many other devices, generate…
- CVE-2022-23408CRITICALCVSS 9.1EG 9.12022-01-18
wolfSSL 5.x before 5.1.1 uses non-random IV values in certain situations. This affects connections (without AEAD) using AES-CBC or DES3 with TLS 1.1 or 1.2 or DTLS 1.1 or 1.2. This occurs because of misplaced memory initialization in Build…
- CVE-2020-35685CRITICALCVSS 9.1EG 9.12021-08-19
An issue was discovered in HCC Nichestack 3.0. The code that generates Initial Sequence Numbers (ISNs) for TCP connections derives the ISN from an insufficiently random source. As a result, an attacker may be able to determine the ISN of c…
- CVE-2020-16271CRITICALCVSS 9.1EG 9.12020-08-03
The SRP-6a implementation in Kee Vault KeePassRPC before 1.12.0 generates insufficiently random numbers, which allows remote attackers to read and modify data in the KeePass database via a WebSocket connection.
- CVE-2020-1731CRITICALCVSS 9.1EG 9.12020-03-02
A flaw was found in all versions of the Keycloak operator, before version 8.0.2,(community only) where the operator generates a random admin password when installing Keycloak, however the password remains the same when deployed to the same…
- CVE-2013-4102CRITICALCVSS 9.1EG 9.12019-11-04
Cryptocat before 2.0.22 strophe.js Math.random() Random Number Generator Weakness
- CVE-2017-6026CRITICALCVSS 9.1EG 9.12017-06-30
A Use of Insufficiently Random Values issue was discovered in Schneider Electric Modicon PLCs Modicon M241, firmware versions prior to Version 4.0.5.11, and Modicon M251, firmware versions prior to Version 4.0.5.11. The session numbers gen…
- CVE-2026-11374CRITICALCVSS 9.0EG 9.02026-06-23
In ManageEngine ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus, the SSO tickets generated to authenticate that session could be predicted by an unauthenticated user, leading to account takeover.
- CVE-2022-36045CRITICALCVSS 9.0EG 9.02022-08-31
NodeBB Forum Software is powered by Node.js and supports either Redis, MongoDB, or a PostgreSQL database. It utilizes web sockets for instant interactions and real-time notifications. `utils.generateUUID`, a helper function available in es…
- CVE-2020-11901CRITICALCVSS 9.0EG 9.02020-06-17
The Treck TCP/IP stack before 6.0.1.66 allows Remote Code execution via a single invalid DNS response.
- CVE-2022-43636HIGHCVSS 8.8EG 8.82023-03-29
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of TP-Link TL-WR940N 6_211111 3.20.1(US) routers. Authentication is not required to exploit this vulnerability. The specific flaw exist…
- CVE-2022-37400HIGHCVSS 8.8EG 8.82022-08-15
Apache OpenOffice supports the storage of passwords for web connections in the user's configuration database. The stored passwords are encrypted with a single master key provided by the user. A flaw in OpenOffice existed where the required…
- CVE-2021-46010HIGHCVSS 8.8EG 8.82022-03-30
Totolink A3100R V5.9c.4577 suffers from Use of Insufficiently Random Values via the web configuration. The SESSION_ID is predictable. An attacker can hijack a valid session and conduct further malicious operations.
- CVE-2021-26726HIGHCVSS 8.8EG 8.82022-02-16
A remote code execution vulnerability affecting a Valmet DNA service listening on TCP port 1517, allows an attacker to execute commands with SYSTEM privileges This issue affects: Valmet DNA versions from Collection 2012 until Collection 20…
- CVE-2021-22038HIGHCVSS 8.8EG 8.82021-10-29
On Windows, the uninstaller binary copies itself to a fixed temporary location, which is then executed (the originally called uninstaller exits, so it does not block the installation directory). This temporary location is not randomized an…
- CVE-2020-27264HIGHCVSS 8.8EG 8.82021-01-19
In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, the communication protocol of the insulin pump and its AnyDana-i and AnyDana-A mobile applications use deterministic keys, which allows unauthenticated, physically proxi…
- CVE-2020-11551HIGHCVSS 8.8EG 8.82020-05-18
An issue was discovered on NETGEAR Orbi Tri-Band Business WiFi Add-on Satellite (SRS60) AC3000 V2.5.1.106, Outdoor Satellite (RBS50Y) V2.5.1.106, and Pro Tri-Band Business WiFi Router (SRR60) AC3000 V2.5.1.106. The administrative SOAP inte…
- CVE-2019-9102HIGHCVSS 8.8EG 8.82020-03-11
An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1. A predictable mechanism of generating tokens allows remote attacker…
- CVE-2020-9449HIGHCVSS 8.8EG 8.82020-02-28
An insecure random number generation vulnerability in BlaB! AX, BlaB! AX Pro, BlaB! WS (client), and BlaB! WS Pro (client) version 19.11 allows an attacker (with a guest or user session cookie) to escalate privileges by retrieving the cook…
- CVE-2019-16205HIGHCVSS 8.8EG 8.82019-11-08
A vulnerability, in Brocade SANnav versions before v2.0, could allow remote attackers to brute-force a valid session ID. The vulnerability is due to an insufficiently random session ID for several post-authentication actions in the SANnav …
- CVE-2017-17091HIGHCVSS 8.8EG 8.82017-12-02
wp-admin/user-new.php in WordPress before 4.9.1 sets the newbloguser key to a string that can be directly derived from the user ID, which allows remote attackers to bypass intended access restrictions by entering this string.
- CVE-2026-105674HIGHCVSS 8.7EG 8.72026-10-08
TP-Link Tapo C325WB V2 generates the pre-shared key used by its local media streaming service with a time-seeded pseudo-random number generator, making the key predictable and recoverable. An unauthenticated attacker on the adjacent networ…
- CVE-2026-41505HIGHCVSS 8.7EG 8.72026-05-07
RELATE is a web-based courseware package. Prior to commit 2f68e16, RELATE is vulnerable to predictable token generation in auth.py's make_sign_in_key() function and exam.py's gen_ticket_code() function. This issue has been patched via comm…
- CVE-2024-10082HIGHCVSS 8.7EG 8.72024-11-06
CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. Authentication method confusion allows logging in as the built-in root user from an external service. The built-in root…
- CVE-2024-7558HIGHCVSS 8.7EG 8.72024-10-02
JUJU_CONTEXT_ID is a predictable authentication secret. On a Juju machine (non-Kubernetes) or Juju charm container (on Kubernetes), an unprivileged user in the same network namespace can connect to an abstract domain socket and guess the J…
Map vulnerabilities like CWE-330 to your infrastructure
EchelonGraph correlates every CVE — across CWE-330 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →