CWE-330— Use of Insufficiently Random Values
The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.— MITRE CWE catalog
412 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-330page 6 of 9
- CVE-2025-66511MEDIUMCVSS 6.5EG 6.52025-12-05
Nextcloud Calendar is a calendar app for Nextcloud. Prior to 6.0.3, the Calendar app generates participant tokens for meeting proposals using a hash function, allowing an attacker to compute valid participant tokens, which allowed them to …
- CVE-2024-50684MEDIUMCVSS 6.5EG 6.52025-02-26
SunGrow iSolarCloud Android app V2.1.6.20241017 and prior uses an insecure AES key to encrypt client data (insufficient entropy). This may allow attackers to decrypt intercepted communications between the mobile app and iSolarCloud.
- CVE-2024-42475MEDIUMCVSS 6.5EG 6.52024-08-15
In the OAuth library for nim prior to version 0.11, the `state` values generated by the `generateState` function do not have sufficient entropy. These can be successfully guessed by an attacker allowing them to perform a CSRF vs a user, as…
- CVE-2024-5868MEDIUMCVSS 6.5EG 6.52024-06-15
The WooCommerce - Social Login plugin for WordPress is vulnerable to Email Verification in all versions up to, and including, 2.6.2 via the use of insufficiently random activation code. This makes it possible for unauthenticated attackers …
- CVE-2024-5149MEDIUMCVSS 6.5EG 6.52024-06-05
The BuddyForms plugin for WordPress is vulnerable to Email Verification Bypass in all versions up to, and including, 2.8.9 via the use of an insufficiently random activation code. This makes it possible for unauthenticated attackers to byp…
- CVE-2024-21495MEDIUMCVSS 6.5EG 6.52024-02-17
Versions of the package github.com/greenpau/caddy-security before 1.0.42 are vulnerable to Insecure Randomness due to using an insecure random number generation library which could possibly be predicted via a brute-force search. Attackers …
- CVE-2022-44795MEDIUMCVSS 6.5EG 6.52022-11-07
An issue was discovered in Object First Ootbi BETA build 1.0.7.712. A flaw was found in the Web Service, which could lead to local information disclosure. The command that creates the URL for the support bundle uses an insecure RNG. That c…
- CVE-2022-38970MEDIUMCVSS 6.5EG 6.52022-09-26
ieGeek IG20 hipcam RealServer V1.0 is vulnerable to Incorrect Access Control. The algorithm used to generate device IDs (UIDs) for devices that utilize Shenzhen Yunni Technology iLnkP2P suffers from a predictability flaw that allows remote…
- CVE-2022-24406MEDIUMCVSS 6.5EG 6.52022-07-27
OX App Suite through 7.10.6 allows SSRF because multipart/form-data boundaries are predictable, and this can lead to injection into internal Documentconverter API calls.
- CVE-2021-23451MEDIUMCVSS 6.5EG 6.52022-07-25
The package otp-generator before 3.0.0 are vulnerable to Insecure Randomness due to insecure generation of random one-time passwords, which may allow a brute-force attack.
- CVE-2022-34295MEDIUMCVSS 6.5EG 6.52022-06-23
totd before 1.5.3 does not properly randomize mesg IDs.
- CVE-2022-30295MEDIUMCVSS 6.5EG 6.52022-05-06
uClibc-ng through 1.0.40 and uClibc through 0.9.33.2 use predictable DNS transaction IDs that may lead to DNS cache poisoning. This is related to a reset of a value to 0x2.
- CVE-2022-26317MEDIUMCVSS 6.5EG 6.52022-03-08
A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.29). When returning the result of a completed Microflow execution call the affected framework does not correctly verify, if the request was ini…
- CVE-2021-28055MEDIUMCVSS 6.5EG 6.52021-04-15
An issue was discovered in Centreon-Web in Centreon Platform 20.10.0. The anti-CSRF token generation is predictable, which might allow CSRF attacks that add an admin user.
- CVE-2021-21729MEDIUMCVSS 6.5EG 6.52021-04-13
Some ZTE products have CSRF vulnerability. Because some pages lack CSRF random value verification, attackers could perform illegal authorization operations by constructing messages.This affects: ZXHN H168N V3.5.0_EG1T5_TE, V2.5.5, ZXHN H10…
- CVE-2021-25375MEDIUMCVSS 6.5EG 6.52021-04-09
Using predictable index for attachments in Samsung Email prior to version 6.1.41.0 allows remote attackers to get attachments of another emails when users open the malicious attachment.
- CVE-2020-5408MEDIUMCVSS 6.5EG 6.52020-05-14
Spring Security versions 5.3.x prior to 5.3.2, 5.2.x prior to 5.2.4, 5.1.x prior to 5.1.10, 5.0.x prior to 5.0.16 and 4.2.x prior to 4.2.16 use a fixed null initialization vector with CBC Mode in the implementation of the queryable text en…
- CVE-2020-12270MEDIUMCVSS 6.5EG 6.52020-04-27
React Native Bluetooth Scan in Bluezone 1.0.0 uses six-character alphanumeric IDs, which might make it easier for remote attackers to interfere with COVID-19 contact tracing by using many IDs. NOTE: the vendor disputes the relevance of thi…
- CVE-2019-13929MEDIUMCVSS 6.5EG 6.52019-10-10
A vulnerability has been identified in SIMATIC IT UADM (All versions < V1.3). An authenticated remote attacker with network access to port 1434/tcp of SIMATIC IT UADM could potentially recover a password that can be used to gain read and w…
- CVE-2019-15955MEDIUMCVSS 6.5EG 6.52019-09-05
An issue was discovered in Total.js CMS 12.0.0. A low privilege user can perform a simple transformation of a cookie to obtain the random values inside it. If an attacker can discover a session cookie owned by an admin, then it is possible…
- CVE-2018-18425MEDIUMCVSS 6.5EG 6.52019-06-19
The doAirdrop function of a smart contract implementation for Primeo (PEO), an Ethereum token, does not check the numerical relationship between the amount of the air drop and the token's total supply, which lets the owner of the contract …
- CVE-2019-6821MEDIUMCVSS 6.5EG 6.52019-05-22
CWE-330: Use of Insufficiently Random Values vulnerability, which could cause the hijacking of the TCP connection when using Ethernet communication in Modicon M580 firmware versions prior to V2.30, and all firmware versions of Modicon M340…
- CVE-2018-19983MEDIUMCVSS 6.5EG 6.52018-12-09
An issue was discovered on Sigma Design Z-Wave S0 through S2 devices. An attacker first prepares a Z-Wave frame-transmission program (e.g., Z-Wave PC Controller, OpenZWave, CC1110, etc.). Next, the attacker conducts a DoS attack against th…
- CVE-2017-17910MEDIUMCVSS 6.5EG 6.52017-12-29
On Hoermann BiSecur devices before 2018, a vulnerability can be exploited by recording a single radio transmission. An attacker can intercept an arbitrary radio frame exchanged between a BiSecur transmitter and a receiver to obtain the enc…
- CVE-2023-20016MEDIUMCVSS 6.3EG 6.52023-02-23
A vulnerability in the backup configuration feature of Cisco UCS Manager Software and in the configuration export feature of Cisco FXOS Software could allow an unauthenticated attacker with access to a backup file to decrypt sensitive info…
- CVE-2020-1759MEDIUMCVSS 6.4EG 6.42020-04-13
A vulnerability was found in Red Hat Ceph Storage 4 and Red Hat Openshift Container Storage 4.2 where, A nonce reuse vulnerability was discovered in the secure mode of the messenger v2 protocol, which can allow an attacker to forge auth ta…
- CVE-2026-102719MEDIUMCVSS 6.3EG 6.32026-09-29
Predictable DTLS HelloVerifyRequest Cookie in NetX Secure
- CVE-2024-42165MEDIUMCVSS 6.3EG 6.32024-08-12
Insufficiently random values for generating activation token in FIWARE Keyrock <= 8.4 allow attackers to activate accounts of any user by predicting the token for the activation link.
- CVE-2022-26080MEDIUMCVSS 6.3EG 6.32023-03-16
Use of Insufficiently Random Values vulnerability in ABB Pulsar Plus System Controller NE843_S, ABB Infinity DC Power Plant.This issue affects Pulsar Plus System Controller NE843_S : comcode 150042936; Infinity DC Power Plant: H5692448 G10…
- CVE-2026-92930MEDIUMCVSS 6.2EG 6.22026-09-22
OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 uses an administrator password-reset unlock-code design that lacks a per-device secret or other server-side cryptographic material. An attacker with physical-console access and a…
- CVE-2022-43485MEDIUMCVSS 6.2EG 6.22023-05-30
Use of Insufficiently Random Values in Honeywell OneWireless. This vulnerability may allow attacker to manipulate claims in client's JWT token. This issue affects OneWireless version 322.1
- CVE-2021-38377MEDIUMCVSS 6.1EG 6.12021-11-22
OX App Suite through 7.10.5 allows XSS via JavaScript code in an anchor HTML comment within truncated e-mail, because there is a predictable UUID with HTML transformation results.
- CVE-2021-39249MEDIUMCVSS 6.1EG 6.12021-08-17
Invision Community (aka IPS Community Suite or IP-Board) before 4.6.5.1 allows reflected XSS because the filenames of uploaded files become predictable through a brute-force attack against the PHP mt_rand function.
- CVE-2026-96599MEDIUMCVSS 5.9EG 5.92026-09-23
Isotope eCommerce through 2.9.10 derives order identifiers from uniqid() instead of a cryptographically secure source, allowing unauthenticated attackers to guess identifiers. Guest orders lack ownership verification, enabling attackers to…
- CVE-2026-86187MEDIUMCVSS 5.9EG 5.92026-09-05
WWBN AVideo generates passwords for external-login accounts using rand() instead of a cryptographic generator, producing only 31-bit integers. Attackers with access to password hashes can recover plaintext passwords in minutes through offl…
- CVE-2026-57082MEDIUMCVSS 5.9EG 5.92026-06-30
Net::BitTorrent versions before 2.1.0 for Perl generate the MSE Diffie-Hellman private key with a non-cryptographic PRNG. The MSE (Message Stream Encryption) handshake derives its 160-bit Diffie-Hellman private key from Perl's rand(), a n…
- CVE-2026-34511MEDIUMCVSS 5.9EG 5.92026-04-03
OpenClaw before 2026.4.2 reuses the PKCE verifier as the OAuth state parameter in the Gemini OAuth flow, exposing it through the redirect URL. Attackers who capture the redirect URL can obtain both the authorization code and PKCE verifier,…
- CVE-2023-6799MEDIUMCVSS 5.9EG 5.92024-04-09
The WP Reset – Most Advanced WordPress Reset Tool plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.0 via the use of insufficiently random snapshot names. This makes it possible …
- CVE-2023-4462MEDIUMCVSS 5.9EG 5.92023-12-29
A vulnerability classified as problematic has been found in Poly Trio 8300, Trio 8500, Trio 8800, Trio C60, CCX 350, CCX 400, CCX 500, CCX 505, CCX 600, CCX 700, EDGE E100, EDGE E220, EDGE E300, EDGE E320, EDGE E350, EDGE E400, EDGE E450, …
- CVE-2023-3373MEDIUMCVSS 5.9EG 5.92023-08-04
Predictable Exact Value from Previous Values vulnerability in Mitsubishi Electric Corporation GOT2000 Series GT21 model versions 01.49.000 and prior and GOT SIMPLE Series GS21 model versions 01.49.000 and prior allows a remote unauthentica…
- CVE-2023-2729MEDIUMCVSS 5.9EG 5.92023-06-13
Use of insufficiently random values vulnerability in User Management Functionality in Synology DiskStation Manager (DSM) before 7.2-64561 allows remote attackers to obtain user credential via unspecified vectors.
- CVE-2023-31147MEDIUMCVSS 5.9EG 5.92023-05-25
c-ares is an asynchronous resolver library. When /dev/urandom or RtlGenRandom() are unavailable, c-ares uses rand() to generate random numbers used for DNS query ids. This is not a CSPRNG, and it is also not seeded by srand() so will gener…
- CVE-2022-25047MEDIUMCVSS 5.9EG 5.92022-07-07
The password reset token in CWP v0.9.8.1126 is generated using known or predictable values.
- CVE-2021-27499MEDIUMCVSS 5.9EG 5.92021-08-02
Ypsomed mylife Cloud, mylife Mobile Application, Ypsomed mylife Cloud: All versions prior to 1.7.2, Ypsomed mylife App: All versions prior to 1.7.5,The application layer encryption of the communication protocol between the Ypsomed mylife A…
- CVE-2021-32791MEDIUMCVSS 5.9EG 5.92021-07-26
mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Connect Relying Party, authenticating users against an OpenID Connect Provider. In mod_auth_openidc before version 2.4.9,…
- CVE-2020-15023MEDIUMCVSS 5.9EG 5.92020-12-11
Askey AP5100W devices through AP5100W_Dual_SIG_1.01.097 are affected by WPS PIN offline brute-force cracking. This arises because of issues with the random number selection for the Diffie-Hellman exchange. By capturing an attempted (and ev…
- CVE-2020-14422MEDIUMCVSS 5.9EG 5.92020-06-18
Lib/ipaddress.py in Python through 3.8.3 improperly computes hash values in the IPv4Interface and IPv6Interface classes, which might allow a remote attacker to cause a denial of service if an application is affected by the performance of a…
- CVE-2020-8988MEDIUMCVSS 5.9EG 5.92020-02-13
The Voatz application 2020-01-01 for Android allows only 100 million different PINs, which makes it easier for attackers (after using root access to make a copy of the local database) to discover login credentials and voting history via an…
- CVE-2013-0294MEDIUMCVSS 5.9EG 5.92020-01-28
packet.py in pyrad before 2.1 uses weak random numbers to generate RADIUS authenticators and hash passwords, which makes it easier for remote attackers to obtain sensitive information via a brute force attack.
- CVE-2019-13603MEDIUMCVSS 5.9EG 5.92019-07-16
An issue was discovered in the HID Global DigitalPersona (formerly Crossmatch) U.are.U 4500 Fingerprint Reader Windows Biometric Framework driver 5.0.0.5. It has a statically coded initialization vector to encrypt a user's fingerprint imag…
Map vulnerabilities like CWE-330 to your infrastructure
EchelonGraph correlates every CVE — across CWE-330 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →