CWE-340— Generation of Predictable Numbers or Identifiers
The product uses a scheme that generates numbers or identifiers that are more predictable than required.— MITRE CWE catalog
56 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-340page 1 of 2
- CVE-2025-15604CRITICALCVSS 9.8EG 9.82026-03-28
Amon2 versions before 6.17 for Perl use an insecure random_string implementation for security functions. In versions 6.06 through 6.16, the random_string function will attempt to read bytes from the /dev/urandom device, but if that is una…
- CVE-2026-3256CRITICALCVSS 9.8EG 9.82026-03-28
HTTP::Session versions before 0.54 for Perl defaults to using insecurely generated session ids. HTTP::Session defaults to using HTTP::Session::ID::SHA1 to generate session ids using a SHA-1 hash seeded with the built-in rand function, the…
- CVE-2025-40926CRITICALCVSS 9.8EG 9.82026-03-05
Plack::Middleware::Session::Simple versions before 0.05 for Perl generates session ids insecurely. The default session id generator returns a SHA-1 hash seeded with the built-in rand function, the epoch time, and the PID. The PID will com…
- CVE-2026-2439CRITICALCVSS 9.8EG 9.82026-02-16
Concierge::Sessions versions from 0.8.1 before 0.8.5 for Perl generate insecure session ids. The generate_session_id function in Concierge::Sessions::Base defaults to using the uuidgen command to generate a UUID, with a fallback to using P…
- CVE-2025-69286CRITICALCVSS 9.8EG 9.82025-12-31
RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In versions prior to 0.22.0, the use of an insecure key generation algorithm in the API key and beta (assistant/agent share auth) token generation process allows these …
- CVE-2024-47945CRITICALCVSS 9.8EG 9.82024-10-15
The devices are vulnerable to session hijacking due to insufficient entropy in its session ID generation algorithm. The session IDs are predictable, with only 32,768 possible values per user, which allows attackers to pre-generate valid…
- CVE-2026-75106CRITICALCVSS 9.1EG 9.12026-08-17
OpnForm derives editable-submission secrets from sequential row identifiers using Hashids with an empty default salt, allowing unauthenticated attackers to compute hashes for any submission. Attackers can read other respondents' full submi…
- CVE-2026-9733CRITICALCVSS 9.1EG 9.12026-06-23
Mojolicious::Plugin::Web::Auth::OAuth2 versions through 0.17 for Perl have an insecure default state parameter. When no state generator is specified in the constructor, the module defaults to using a SHA-1 hash of predictable and low-entr…
- CVE-2026-5081CRITICALCVSS 9.1EG 9.12026-05-06
Apache::Session::Generate::ModUniqueId versions from 1.54 through 1.94 for Perl session ids are insecure. Apache::Session::Generate::ModUniqueId (added in version 1.54) uses the value of the UNIQUE_ID environment variable for the session …
- CVE-2026-40496CRITICALCVSS 9.1EG 9.12026-04-21
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, attachment download tokens are generated using a weak and predictable formula: `md5(APP_KEY + attachment_id + size)`. Since attachment_id is sequential…
- CVE-2026-5085CRITICALCVSS 9.1EG 9.12026-04-13
Solstice::Session versions through 1440 for Perl generates session ids insecurely. The _generateSessionID method returns an MD5 digest seeded by the epoch time, a random hash reference, a call to the built-in rand() function and the proce…
- CVE-2025-40931CRITICALCVSS 9.1EG 9.12026-03-05
Apache::Session::Generate::MD5 versions through 1.94 for Perl create insecure session id. Apache::Session::Generate::MD5 generates session ids insecurely. The default session id generator returns a MD5 hash seeded with the built-in rand()…
- CVE-2025-40925CRITICALCVSS 9.1EG 9.12025-09-20
Starch versions 0.14 and earlier generate session ids insecurely. The default session id generator returns a SHA-1 hash seeded with a counter, the epoch time, the built-in rand function, the PID, and internal Perl reference addresses. The…
- CVE-2026-11374CRITICALCVSS 9.0EG 9.02026-06-23
In ManageEngine ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus, the SSO tickets generated to authenticate that session could be predicted by an unauthenticated user, leading to account takeover.
- CVE-2026-85496HIGHCVSS 8.8EG 8.82026-09-24
The Botslab G980H dash camera firmware generates session identifiers using a small sequential value space rather than a suitably unpredictable source. An unauthenticated attacker with adjacent network access and knowledge that an active se…
- CVE-2024-7558HIGHCVSS 8.7EG 8.72024-10-02
JUJU_CONTEXT_ID is a predictable authentication secret. On a Juju machine (non-Kubernetes) or Juju charm container (on Kubernetes), an unprivileged user in the same network namespace can connect to an abstract domain socket and guess the J…
- CVE-2025-40920HIGHCVSS 8.6EG 8.62025-08-11
Catalyst::Authentication::Credential::HTTP versions 1.018 and earlier for Perl generate nonces using the Perl Data::UUID library. * Data::UUID does not use a strong cryptographic source for generating UUIDs. * Data::UUID returns v3 U…
- CVE-2026-13577HIGHCVSS 8.2EG 8.22026-07-20
Dancer2 versions before 2.2.0 for Perl generate insecure session ids when required CSPRNG modules are unavailable. Dancer2::Core::Role::SessionFactory::generate_id silently falls back to a built-in rand-derived session id unless both Math…
- CVE-2025-40932HIGHCVSS 8.2EG 8.22026-02-27
Apache::SessionX versions through 2.01 for Perl create insecure session id. Apache::SessionX generates session ids insecurely. The default session id generator in Apache::SessionX::Generate::MD5 returns a MD5 hash seeded with the built-in…
- CVE-2026-2473HIGHCVSS 7.7EG 7.72026-02-20
Predictable bucket naming in Vertex AI Experiments in Google Cloud Vertex AI from version 1.21.0 up to (but not including) 1.133.0 on Google Cloud Platform allows an unauthenticated remote attacker to achieve cross-tenant remote code exec…
- CVE-2026-95653HIGHCVSS 7.5EG 7.52026-09-22
Concrete CMS Community Store before 2.7.8 derives digital product download tokens from order creation timestamps instead of random values, making tokens predictable. Unauthenticated attackers can enumerate sequential order and file identif…
- CVE-2026-4269HIGHCVSS 7.5EG 7.52026-03-16
A missing S3 ownership verification in the Bedrock AgentCore Starter Toolkit before version v0.1.13 may allow a remote actor to inject code during the build process, leading to code execution in the AgentCore Runtime. This issue only affec…
- CVE-2025-68701HIGHCVSS 7.5EG 7.52026-01-13
Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, Jervis uses deterministic AES IV derivation from a passphrase. This vulnerability is fixed in 2.2.
- CVE-2025-62294HIGHCVSS 7.5EG 7.52025-11-20
SOPlanning is vulnerable to Predictable Generation of Password Recovery Token. Due to weak mechanism of generating recovery tokens, a malicious attacker is able to brute-force all possible values and takeover any account in reasonable amou…
- CVE-2025-40933HIGHCVSS 7.5EG 7.52025-09-17
Apache::AuthAny::Cookie v0.201 or earlier for Perl generates session ids insecurely. Session ids are generated using an MD5 hash of the epoch time and a call to the built-in rand function. The epoch time may be guessed, if it is not leake…
- CVE-2024-52299HIGHCVSS 7.5EG 7.52024-11-13
macro-pdfviewer is a PDF Viewer Macro for XWiki using Mozilla pdf.js. Any user with view right on XWiki.PDFViewerService can access any attachment stored in the wiki as the "key" that is passed to prevent this is computed incorrectly, call…
- CVE-2025-40923HIGHCVSS 7.3EG 7.32025-07-16
Plack-Middleware-Session before version 0.35 for Perl generates session ids insecurely. The default session id generator returns a SHA-1 hash seeded with the built-in rand function, the epoch time, and the PID. The PID will come from a sm…
- CVE-2026-45673MEDIUMCVSS 6.8EG 6.82026-06-08
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's DNS resolver uses a predictable PRNG for generating DNS transaction IDs and defaults to a s…
- CVE-2026-9219MEDIUMCVSS 6.5EG 6.52026-06-26
Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior have a predictable registration ID derived from IMEI. The enrollment system lacks additional authentication before assignment. If an attacker is able to obtain …
- CVE-2026-8503MEDIUMCVSS 6.5EG 6.52026-05-15
Apache::Session::Generate::SHA256 versions before 1.3.19 for Perl create insecure session ids. Apache::Session::Generate::SHA256 generated session ids insecurely. The default session id generator returns a SHA-256 hash of the built-in ran…
- CVE-2026-5084MEDIUMCVSS 6.5EG 6.52026-05-11
WebDyne::Session versions before 3.003_704 for Perl generate the session id insecurely. The session handler generates the session id from an MD5 hash seeded with a call to the built-in rand() function. The rand function is passed a maximu…
- CVE-2026-3255MEDIUMCVSS 6.5EG 6.52026-02-27
HTTP::Session2 versions before 1.12 for Perl for Perl may generate weak session ids using the rand() function. The HTTP::Session2 session id generator returns a SHA-1 hash seeded with the built-in rand function, the epoch time, and the PI…
- CVE-2025-40924MEDIUMCVSS 6.5EG 6.52025-07-17
Catalyst::Plugin::Session before version 0.44 for Perl generates session ids insecurely. The session id is generated from a (usually SHA-1) hash of a simple counter, the epoch time, the built-in rand function, the PID and the current Cata…
- CVE-2025-40919MEDIUMCVSS 6.5EG 6.52025-07-16
Authen::DigestMD5 versions 0.01 through 0.02 for Perl generate the cnonce insecurely. The cnonce (client nonce) is generated from an MD5 hash of the PID, the epoch time and the built-in rand function. The PID will come from a small set of…
- CVE-2025-40918MEDIUMCVSS 6.5EG 6.52025-07-16
Authen::SASL::Perl::DIGEST_MD5 versions 2.04 through 2.1800 for Perl generates the cnonce insecurely. The cnonce (client nonce) is generated from an MD5 hash of the PID, the epoch time and the built-in rand function. The PID will come fro…
- CVE-2026-64964MEDIUMCVSS 6.3EG 6.32026-08-20
ATutor generates predictable email confirmation tokens due to the use of insufficiently random values in the account confirmation functionality. Due to the use of predictable values related to user registration, an attacker who knows or ca…
- CVE-2025-13044MEDIUMCVSS 6.2EG 6.22026-04-07
IBM Concert 1.0.0 through 2.2.0 creates temporary files with predictable names, which allows local users to overwrite arbitrary files via a symlink attack.
- CVE-2026-56016MEDIUMCVSS 5.9EG 5.92026-07-01
CGI::Session::ID::md5 versions before 4.49 for Perl generate predictable session ids from low-entropy sources. The generate_id method builds the session id from a MD5 digest of the process id, the epoch time, and the built-in rand() funct…
- CVE-2026-5080MEDIUMCVSS 5.9EG 5.92026-04-30
Dancer::Session::Abstract versions through 1.3522 for Perl generates session ids insecurely. The session id is generated from summing the character codepoints of the absolute pathname with the process id, the epoch time and calls to the b…
- CVE-2025-59452MEDIUMCVSS 5.8EG 5.82025-10-06
The YoSmart YoLink API through 2025-10-02 uses an endpoint URL that is derived from a device's MAC address along with an MD5 hash of non-secret information, such as a key that begins with cf50.
- CVE-2025-0218MEDIUMCVSS 5.5EG 5.52025-01-07
When batch jobs are executed by pgAgent, a script is created in a temporary directory and then executed. In versions of pgAgent prior to 4.2.3, an insufficiently seeded random number generator is used when generating the directory name, le…
- CVE-2025-14602MEDIUMCVSS 5.3EG 5.32026-08-20
The application generates uploaded file names using a weak and predictable method based on the request timestamp. This allows a remote attacker to accurately guess or brute-force the generated filename within a short time window. An attac…
- CVE-2026-9692MEDIUMCVSS 5.3EG 5.32026-06-18
Mojolicious::Sessions::Storable versions through 0.05 for Perl generate session ids insecurely. The default session id generator returns a SHA-1 hash seeded with the built-in rand function, the epoch time, the heap address of an anonymous…
- CVE-2026-42932MEDIUMCVSS 5.3EG 5.32026-06-12
Naxclow device identifiers use fixed manufacturing prefixes combined with sequential counters, producing a fully predictable and enumerable identifier space. Because the platform also exposes an endpoint that reveals the current identifier…
- CVE-2026-5083MEDIUMCVSS 5.3EG 5.32026-04-08
Ado::Sessions versions through 0.935 for Perl generates insecure session ids. The session id is generated from a SHA-1 hash seeded with the built-in rand function, the epoch time, and the PID. The PID will come from a small set of numbers…
- CVE-2026-5082MEDIUMCVSS 5.3EG 5.32026-04-08
Amon2::Plugin::Web::CSRFDefender versions from 7.00 through 7.03 for Perl generate an insecure session id. The generate_session_id function will attempt to read bytes from the /dev/urandom device, but if that is unavailable then it genera…
- CVE-2025-58424MEDIUMCVSS 5.3EG 5.32025-10-15
On BIG-IP systems, undisclosed traffic can cause data corruption and unauthorized data modification in protocols which do not have message integrity protection. Note: Software versions which have reached End of Technical Support (EoTS) …
- CVE-2025-10148MEDIUMCVSS 5.3EG 5.32025-09-12
curl's WebSocket code did not update the 32-bit mask pattern for each new outgoing frame as the specification says. Instead it used a fixed mask that persisted and was used throughout the entire connection. A predictable mask pattern allo…
- CVE-2024-10603MEDIUMCVSS 5.3EG 5.32025-01-30
Weaknesses in the generation of TCP/UDP source ports and some other header values in Google's gVisor allowed them to be predicted by an external attacker in some circumstances.
- CVE-2024-12034MEDIUMCVSS 5.3EG 5.32024-12-24
The Advanced Google reCAPTCHA plugin for WordPress is vulnerable to IP unblocking in all versions up to, and including, 1.25. This is due to the plugin not utilizing a strong unique key when generating an unblock request. This makes it pos…
Map vulnerabilities like CWE-340 to your infrastructure
EchelonGraph correlates every CVE — across CWE-340 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →