CWE-330— Use of Insufficiently Random Values
The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.— MITRE CWE catalog
412 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-330page 8 of 9
- CVE-2020-14423MEDIUMCVSS 5.3EG 5.32020-06-18
Convos before 4.20 does not properly generate a random secret in Core/Settings.pm and Util.pm. This leads to a predictable CONVOS_LOCAL_SECRET value, affecting password resets and invitations.
- CVE-2020-5365MEDIUMCVSS 5.3EG 5.32020-05-20
Dell EMC Isilon versions 8.2.2 and earlier contain a remotesupport vulnerability. The pre-configured support account, remotesupport, is bundled in the Dell EMC Isilon OneFS installation. This account is used for diagnostics and other suppo…
- CVE-2020-8792MEDIUMCVSS 5.3EG 5.32020-05-04
The OKLOK (3.1.1) mobile companion app for Fingerprint Bluetooth Padlock FB50 (2.3) has an information-exposure issue. In the mobile app, an attempt to add an already-bound lock by its barcode reveals the email address of the account to wh…
- CVE-2019-18282MEDIUMCVSS 5.3EG 5.32020-01-16
The flow_dissector feature in the Linux kernel 4.3 through 5.x before 5.3.10 has a device tracking vulnerability, aka CID-55667441c84f. This occurs because the auto flowlabel of a UDP IPv6 packet relies on a 32-bit hashrnd value as a secre…
- CVE-2010-3666MEDIUMCVSS 5.3EG 5.32019-11-04
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 contains insecure randomness in the uniqid function.
- CVE-2019-17105MEDIUMCVSS 5.3EG 5.32019-10-08
The token generator in index.php in Centreon Web before 2.8.27 is predictable.
- CVE-2019-1549MEDIUMCVSS 5.3EG 5.32019-09-10
OpenSSL 1.1.1 introduced a rewritten random number generator (RNG). This was intended to include protection in the event of a fork() system call in order to ensure that the parent and child processes did not share the same RNG state. Howev…
- CVE-2019-1010025MEDIUMCVSS 5.3EG 5.32019-07-15
GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may guess the heap addresses of pthread_created thread. The component is: glibc. NOTE: the vendor's position is "ASLR bypass itself is not a vulnerability.
- CVE-2019-3795MEDIUMCVSS 5.3EG 5.32019-04-09
Spring Security versions 4.2.x prior to 4.2.12, 5.0.x prior to 5.0.12, and 5.1.x prior to 5.1.5 contain an insecure randomness vulnerability when using SecureRandomFactoryBean#setSeed to configure a SecureRandom instance. In order to be im…
- CVE-2017-16028MEDIUMCVSS 5.3EG 5.32018-06-04
react-native-meteor-oauth is a library for Oauth2 login to a Meteor server in React Native. The oauth Random Token is generated using a non-cryptographically strong RNG (Math.random()).
- CVE-2017-1000246MEDIUMCVSS 5.3EG 5.32017-11-17
Python package pysaml2 version 4.4.0 and earlier reuses the initialization vector across encryptions in the IDP server, resulting in weak encryption of data.
- CVE-2017-13088MEDIUMCVSS 5.3EG 5.32017-10-17
Wi-Fi Protected Access (WPA and WPA2) that support 802.11v allows reinstallation of the Integrity Group Temporal Key (IGTK) when processing a Wireless Network Management (WNM) Sleep Mode Response frame, allowing an attacker within radio ra…
- CVE-2017-13087MEDIUMCVSS 5.3EG 5.32017-10-17
Wi-Fi Protected Access (WPA and WPA2) that support 802.11v allows reinstallation of the Group Temporal Key (GTK) when processing a Wireless Network Management (WNM) Sleep Mode Response frame, allowing an attacker within radio range to repl…
- CVE-2017-13081MEDIUMCVSS 5.3EG 5.32017-10-17
Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11w allows reinstallation of the Integrity Group Temporal Key (IGTK) during the group key handshake, allowing an attacker within radio range to spoof frames from access points to…
- CVE-2017-13080MEDIUMCVSS 5.3EG 5.32017-10-17
Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Group Temporal Key (GTK) during the group key handshake, allowing an attacker within radio range to replay frames from access points to clients.
- CVE-2017-13079MEDIUMCVSS 5.3EG 5.32017-10-17
Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11w allows reinstallation of the Integrity Group Temporal Key (IGTK) during the four-way handshake, allowing an attacker within radio range to spoof frames from access points to …
- CVE-2017-13078MEDIUMCVSS 5.3EG 5.32017-10-17
Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Group Temporal Key (GTK) during the four-way handshake, allowing an attacker within radio range to replay frames from access points to clients.
- CVE-2015-9019MEDIUMCVSS 5.3EG 5.32017-04-05
In libxslt 1.1.29 and earlier, the EXSLT math.random function was not initialized with a random seed during startup, which could cause usage of this function to produce predictable outputs.
- CVE-2021-26909MEDIUMCVSS 3.7EG 5.32021-04-23
Automox Agent prior to version 31 uses an insufficiently protected S3 bucket endpoint for storing sensitive files, which could be brute-forced by an attacker to subvert an organization's security program. The issue has since been fixed in …
- CVE-2022-3959MEDIUMCVSS 3.1EG 5.32022-11-11
A vulnerability, which was classified as problematic, has been found in drogon up to 1.8.1. Affected by this issue is some unknown functionality of the component Session Hash Handler. The manipulation leads to small space of random values.…
- CVE-2021-4277MEDIUMCVSS 2.6EG 5.32022-12-25
A vulnerability, which was classified as problematic, has been found in fredsmith utils. This issue affects some unknown processing of the file screenshot_sync of the component Filename Handler. The manipulation leads to predictable from o…
- CVE-2021-27884MEDIUMCVSS 5.1EG 5.12021-03-01
Weak JSON Web Token (JWT) signing secret generation in YMFE YApi through 1.9.2 allows recreation of other users' JWT tokens. This occurs because Math.random in Node.js is used.
- CVE-2022-29330MEDIUMCVSS 4.9EG 4.92022-06-24
Missing access control in the backup system of Telesoft VitalPBX before 3.2.1 allows attackers to access the PJSIP and SIP extension credentials, cryptographic keys and voicemails files via unspecified vectors.
- CVE-2026-50009MEDIUMCVSS 4.8EG 4.82026-06-12
Netty is a network application framework for development of protocol servers and clients. Prior to version 4.2.15.Final, Netty QUIC exposes the stateless reset token on the network path when using the default HMAC-based connection-ID and s…
- CVE-2019-12821MEDIUMCVSS 4.8EG 4.82019-07-19
A vulnerability was found in the app 2.0 of the Shenzhen Jisiwei i3 robot vacuum cleaner, while adding a device to the account using a QR-code. The QR-code follows an easily predictable pattern that depends only on the specific device ID o…
- CVE-2026-28415MEDIUMCVSS 4.7EG 4.72026-03-01
Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.6.0, the _redirect_to_target() function in Gradio's OAuth flow accepts an unvalidated _target_url query parameter, allowing redirection to arbitrary…
- CVE-2018-19441MEDIUMCVSS 4.7EG 4.72020-01-27
An issue was discovered in Neato Botvac Connected 2.2.0. The GenerateRobotPassword function of the NeatoCrypto library generates insufficiently random numbers for robot secret_key values used for local and cloud authentication/authorizatio…
- CVE-2026-41701MEDIUMCVSS 4.4EG 4.42026-06-10
Correlation IDs for replies in the RabbitTemplate.sendAndReceive() with the fixed reply queue are predictable due to internal simple counter. Affected versions: Spring AMQP 4.0.0 through 4.0.3; 3.2.0 through 3.2.10; 3.1.0 through 3.1.15; …
- CVE-2021-29480MEDIUMCVSS 4.4EG 4.42021-06-29
Ratpack is a toolkit for creating web applications. In versions prior to 1.9.0, the client side session module uses the application startup time as the signing key by default. This means that if an attacker can determine this time, and if …
- CVE-2021-28099MEDIUMCVSS 4.4EG 4.42021-03-23
In Netflix OSS Hollow, since the Files.exists(parent) is run before creating the directories, an attacker can pre-create these directories with wide permissions. Additionally, since an insecure source of randomness is used, the file names …
- CVE-2020-0407MEDIUMCVSS 4.4EG 4.42020-09-17
In various functions in fscrypt_ice.c and related files in some implementations of f2fs encryption that use encryption hardware which only supports 32-bit IVs (Initialization Vectors), 64-bit IVs are used and later are truncated to 32 bits…
- CVE-2024-42164MEDIUMCVSS 4.3EG 4.32024-08-12
Insufficiently random values for generating password reset token in FIWARE Keyrock <= 8.4 allow attackers to disable two factor authorization of any user by predicting the token for the disable_2fa link.
- CVE-2020-11585MEDIUMCVSS 4.3EG 4.32020-04-06
There is an information disclosure issue in DNN (formerly DotNetNuke) 9.5 within the built-in Activity-Feed/Messaging/Userid/ Message Center module. A registered user is able to enumerate any file in the Admin File Manager (other than ones…
- CVE-2019-12434MEDIUMCVSS 4.3EG 4.32020-03-10
An issue was discovered in GitLab Community and Enterprise Edition 10.6 through 11.11. Users could guess the URL slug of private projects through the contrast of the destination URLs of issues linked in comments. It allows Information Disc…
- CVE-2019-4411MEDIUMCVSS 4.3EG 4.32019-11-09
IBM Cognos Controller 10.3.0, 10.3.1, 10.4.0, and 10.4.1 could allow an authenticated user to obtain sensitive information due to easy to guess session identifier names. IBM X-Force ID: 162658.
- CVE-2017-12361MEDIUMCVSS 4.0EG 4.02017-11-30
A vulnerability in Cisco Jabber for Windows could allow an unauthenticated, local attacker to access sensitive communications made by the Jabber client. An attacker could exploit this vulnerability to gain information to conduct additional…
- CVE-2020-13304LOWCVSS 3.8EG 3.82020-09-14
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Same 2 factor Authentication secret code was generated which resulted an attacker to maintain access under certain conditions.
- CVE-2026-82555LOWCVSS 3.7EG 3.72026-08-30
A vulnerability has been found in TOTOLINK N600R 4.3.0cu.7866_B20220506. This vulnerability affects the function loginAuth of the file /web_cste/cgi-bin/cstecgi.cgi of the component Authentication Handler. Such manipulation leads to insuff…
- CVE-2026-19906LOWCVSS 3.7EG 3.72026-08-15
A weakness has been identified in pkp pkp-lib 3.3.0/3.4.0/3.5.0. This vulnerability affects the function setData of the file classes/user/form/APIProfileForm.php of the component API Key Generation. Executing a manipulation of the argument…
- CVE-2026-19896LOWCVSS 3.7EG 3.72026-08-15
A flaw has been found in mangroup dtale up to 3.22.0. This vulnerability affects the function build_secret_key of the file dtale/app.py of the component Flask Session Cookie. This manipulation causes insufficiently random values. Remote ex…
- CVE-2026-19748LOWCVSS 3.7EG 3.72026-08-13
A security vulnerability has been detected in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to 20260625. Affected is the function CWebSessionManager_ParseSession of the file /user/bin/Kylin of the compo…
- CVE-2026-2966LOWCVSS 3.7EG 3.72026-02-23
A weakness has been identified in Cesanta Mongoose up to 7.20. The impacted element is the function mg_sendnsreq of the file /src/dns.c of the component DNS Transaction ID Handler. Executing a manipulation of the argument random can lead t…
- CVE-2025-10671LOWCVSS 3.7EG 3.72025-09-18
A vulnerability has been found in youth-is-as-pale-as-poetry e-learning 1.0. Impacted is the function encryptSecret of the file e-learning-master\exam-api\src\main\java\com\yf\exam\ability\shiro\jwt\JwtUtils.java of the component JWT Token…
- CVE-2025-5136LOWCVSS 3.7EG 3.72025-05-25
A vulnerability, which was classified as problematic, was found in Tmall Demo up to 20250505. This affects an unknown part of the file /tmall/order/pay/ of the component Payment Identifier Handler. The manipulation leads to insufficiently …
- CVE-2024-7659LOWCVSS 3.7EG 3.72024-08-12
A vulnerability, which was classified as problematic, was found in projectsend up to r1605. Affected is the function generate_random_string of the file includes/functions.php of the component Password Reset Token Handler. The manipulation …
- CVE-2023-31124LOWCVSS 3.7EG 3.72023-05-25
c-ares is an asynchronous resolver library. When cross-compiling c-ares and using the autotools build system, CARES_RANDOM_FILE will not be set, as seen when cross compiling aarch64 android. This will downgrade to using rand() as a fallba…
- CVE-2020-16166LOWCVSS 3.7EG 3.72020-07-30
The Linux kernel through 5.7.11 allows remote attackers to make observations that help to obtain sensitive information about the internal state of the network RNG, aka CID-f227e3ec3b5c. This is related to drivers/char/random.c and kernel/t…
- CVE-2022-32296LOWCVSS 3.3EG 3.32022-06-05
The Linux kernel before 5.17.9 allows TCP servers to identify clients by observing what source ports are used. This occurs because of use of Algorithm 4 ("Double-Hash Port Selection Algorithm") of RFC 6056.
- CVE-2022-29035LOWCVSS 3.3EG 3.32022-04-11
In JetBrains Ktor Native before version 2.0.0 random values used for nonce generation weren't using SecureRandom implementations
- CVE-2020-1905LOWCVSS 3.3EG 3.32020-10-06
Media ContentProvider URIs used for opening attachments in other apps were generated sequentially prior to WhatsApp for Android v2.20.185, which could have allowed a malicious third party app chosen to open the file to guess the URIs for p…
Map vulnerabilities like CWE-330 to your infrastructure
EchelonGraph correlates every CVE — across CWE-330 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →