CWE-330— Use of Insufficiently Random Values
The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.— MITRE CWE catalog
383 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-330page 5 of 8
- CVE-2021-38377MEDIUMCVSS 6.1EG 6.12021-11-22
OX App Suite through 7.10.5 allows XSS via JavaScript code in an anchor HTML comment within truncated e-mail, because there is a predictable UUID with HTML transformation results.
- CVE-2021-38606CRITICALCVSS 9.8EG 9.82021-08-12
reNgine through 0.5 relies on a predictable directory name.
- CVE-2021-39249MEDIUMCVSS 6.1EG 6.12021-08-17
Invision Community (aka IPS Community Suite or IP-Board) before 4.6.5.1 allows reflected XSS because the filenames of uploaded files become predictable through a brute-force attack against the PHP mt_rand function.
- CVE-2021-40422CRITICALCVSS 10.0EG 10.02022-04-14
An authentication bypass vulnerability exists in the device password generation functionality of Swift Sensors Gateway SG3-1010. A specially-crafted network request can lead to remote code execution. An attacker can send a sequence of requ…
- CVE-2021-41061MEDIUMCVSS 5.5EG 5.52021-09-15
In RIOT-OS 2021.01, nonce reuse in 802.15.4 encryption in the ieee820154_security component allows attackers to break encryption by triggering reboots.
- CVE-2021-41694CRITICALCVSS 9.8EG 9.82021-12-09
An Incorrect Access Control vulnerability exists in Premiumdatingscript 4.2.7.7 via the password change procedure in requests\user.php.
- CVE-2021-41829HIGHCVSS 7.5EG 7.52021-09-30
Zoho ManageEngine Remote Access Plus before 10.1.2121.1 relies on the application's build number to calculate a certain encryption key.
- CVE-2021-41993MEDIUMCVSS 6.6EG 6.62022-04-30
A misconfiguration of RSA in PingID Android app prior to 1.19 is vulnerable to pre-computed dictionary attacks, leading to an offline MFA bypass when using PingID Windows Login.
- CVE-2021-41994MEDIUMCVSS 6.6EG 6.62022-04-30
A misconfiguration of RSA in PingID iOS app prior to 1.19 is vulnerable to pre-computed dictionary attacks, leading to an offline MFA bypass when using PingID Windows Login.
- CVE-2021-4240LOWCVSS 2.6EG 2.62022-11-15
A vulnerability, which was classified as problematic, was found in phpservermon. This affects the function generatePasswordResetToken of the file src/psm/Service/User.php. The manipulation leads to use of predictable algorithm in random nu…
- CVE-2021-4241LOWCVSS 2.6EG 2.62022-11-15
A vulnerability, which was classified as problematic, was found in phpservermon. Affected is the function setUserLoggedIn of the file src/psm/Service/User.php. The manipulation leads to use of predictable algorithm in random number generat…
- CVE-2021-4248MEDIUMCVSS 5.6EG 5.62022-12-18
A vulnerability was found in kapetan dns up to 6.1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file DNS/Protocol/Request.cs. The manipulation leads to insufficient entropy in prng. The a…
- CVE-2021-4277MEDIUMCVSS 2.6EG 5.32022-12-25
A vulnerability, which was classified as problematic, has been found in fredsmith utils. This issue affects some unknown processing of the file screenshot_sync of the component Filename Handler. The manipulation leads to predictable from o…
- CVE-2021-44151HIGHCVSS 7.5EG 7.52021-12-13
An issue was discovered in Reprise RLM 14.2. As the session cookies are small, an attacker can hijack any existing sessions by bruteforcing the 4 hex-character session cookie on the Windows version (the Linux version appears to have 8 char…
- CVE-2021-45458HIGHCVSS 7.5EG 7.52022-01-06
Apache Kylin provides encryption classes PasswordPlaceholderConfigurer to help users encrypt their passwords. In the encryption algorithm used by this encryption class, the cipher is initialized with a hardcoded key and IV. If users use cl…
- CVE-2021-45487HIGHCVSS 7.5EG 7.52021-12-25
In NetBSD through 9.2, the IPv4 ID generation algorithm does not use appropriate cryptographic measures.
- CVE-2021-45488HIGHCVSS 7.5EG 7.52021-12-25
In NetBSD through 9.2, there is an information leak in the TCP ISN (ISS) generation algorithm.
- CVE-2021-46010HIGHCVSS 8.8EG 8.82022-03-30
Totolink A3100R V5.9c.4577 suffers from Use of Insufficiently Random Values via the web configuration. The SESSION_ID is predictable. An attacker can hijack a valid session and conduct further malicious operations.
- CVE-2022-1615MEDIUMCVSS 5.5EG 5.52022-09-01
In Samba, GnuTLS gnutls_rnd() can fail and give predictable random values.
- CVE-2022-20941MEDIUMCVSS 5.3EG 5.32022-11-15
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to access sensitive information. This vulnerability is due to missing authorizatio…
- CVE-2022-22517HIGHCVSS 7.5EG 7.52022-04-07
An unauthenticated, remote attacker can disrupt existing communication channels between CODESYS products by guessing a valid channel ID and injecting packets. This results in the communication channel to be closed.
- CVE-2022-22700MEDIUMCVSS 5.3EG 5.32022-03-03
CyberArk Identity versions up to and including 22.1 in the 'StartAuthentication' resource, exposes the response header 'X-CFY-TX-TM'. In certain configurations, that response header contains different, predictable value ranges which can be…
- CVE-2022-22922CRITICALCVSS 9.8EG 9.82022-02-18
TP-Link TL-WA850RE Wi-Fi Range Extender before v6_200923 was discovered to use highly predictable and easily detectable session keys, allowing attackers to gain administrative privileges.
- CVE-2022-23138HIGHCVSS 7.5EG 7.52022-06-09
ZTE's MF297D product has cryptographic issues vulnerability. Due to the use of weak random values, the security of the device is reduced, and it may face the risk of attack.
- CVE-2022-23408CRITICALCVSS 9.1EG 9.12022-01-18
wolfSSL 5.x before 5.1.1 uses non-random IV values in certain situations. This affects connections (without AEAD) using AES-CBC or DES3 with TLS 1.1 or 1.2 or DTLS 1.1 or 1.2. This occurs because of misplaced memory initialization in Build…
- CVE-2022-24406MEDIUMCVSS 6.5EG 6.52022-07-27
OX App Suite through 7.10.6 allows SSRF because multipart/form-data boundaries are predictable, and this can lead to injection into internal Documentconverter API calls.
- CVE-2022-25047MEDIUMCVSS 5.9EG 5.92022-07-07
The password reset token in CWP v0.9.8.1126 is generated using known or predictable values.
- CVE-2022-25752CRITICALCVSS 9.8EG 9.82022-04-12
A vulnerability has been identified in SCALANCE X302-7 EEC (230V), SCALANCE X302-7 EEC (230V, coated), SCALANCE X302-7 EEC (24V), SCALANCE X302-7 EEC (24V, coated), SCALANCE X302-7 EEC (2x 230V), SCALANCE X302-7 EEC (2x 230V, coated), SCAL…
- CVE-2022-26071HIGHCVSS 7.4EG 7.52022-05-05
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, a flaw in the way reply ICMP packets are limited …
- CVE-2022-26080MEDIUMCVSS 6.3EG 6.32023-03-16
Use of Insufficiently Random Values vulnerability in ABB Pulsar Plus System Controller NE843_S, ABB Infinity DC Power Plant.This issue affects Pulsar Plus System Controller NE843_S : comcode 150042936; Infinity DC Power Plant: H5692448 G10…
- CVE-2022-26306HIGHCVSS 7.5EG 7.52022-07-25
LibreOffice supports the storage of passwords for web connections in the user’s configuration database. The stored passwords are encrypted with a single master key provided by the user. A flaw in LibreOffice existed where the required in…
- CVE-2022-26317MEDIUMCVSS 6.5EG 6.52022-03-08
A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.29). When returning the result of a completed Microflow execution call the affected framework does not correctly verify, if the request was ini…
- CVE-2022-26320CRITICALCVSS 9.1EG 9.12022-03-14
The Rambus SafeZone Basic Crypto Module before 10.4.0, as used in certain Fujifilm (formerly Fuji Xerox) devices before 2022-03-01, Canon imagePROGRAF and imageRUNNER devices through 2022-03-14, and potentially many other devices, generate…
- CVE-2022-26647CRITICALCVSS 8.8EG 9.82022-07-12
A vulnerability has been identified in SCALANCE X200-4P IRT (All versions < V5.5.2), SCALANCE X201-3P IRT (All versions < V5.5.2), SCALANCE X201-3P IRT PRO (All versions < V5.5.2), SCALANCE X202-2IRT (All versions < V5.5.2), SCALANCE X202-…
- CVE-2022-26851CRITICALCVSS 9.1EG 9.12022-04-08
Dell PowerScale OneFS, 8.2.2-9.3.x, contains a predictable file name from observable state vulnerability. An unprivileged network attacker could potentially exploit this vulnerability, leading to data loss.
- CVE-2022-27577CRITICALCVSS 9.1EG 9.12022-04-11
The vulnerability in the MSC800 in all versions before 4.15 allows for an attacker to predict the TCP initial sequence number. When the TCP sequence is predictable, an attacker can send packets that are forged to appear to come from a trus…
- CVE-2022-28355HIGHCVSS 7.5EG 7.52022-04-02
randomUUID in Scala.js before 1.10.0 generates predictable values.
- CVE-2022-29035LOWCVSS 3.3EG 3.32022-04-11
In JetBrains Ktor Native before version 2.0.0 random values used for nonce generation weren't using SecureRandom implementations
- CVE-2022-29330MEDIUMCVSS 4.9EG 4.92022-06-24
Missing access control in the backup system of Telesoft VitalPBX before 3.2.1 allows attackers to access the PJSIP and SIP extension credentials, cryptographic keys and voicemails files via unspecified vectors.
- CVE-2022-29808HIGHCVSS 7.5EG 7.52022-08-02
In Quest KACE Systems Management Appliance (SMA) through 12.0, predictable token generation occurs when appliance linking is enabled.
- CVE-2022-29930HIGHCVSS 8.7EG 8.72022-05-12
SHA1 implementation in JetBrains Ktor Native 2.0.0 was returning the same value. The issue was fixed in Ktor version 2.0.1.
- CVE-2022-30295MEDIUMCVSS 6.5EG 6.52022-05-06
uClibc-ng through 1.0.40 and uClibc through 0.9.33.2 use predictable DNS transaction IDs that may lead to DNS cache poisoning. This is related to a reset of a value to 0x2.
- CVE-2022-30629HIGHCVSS 3.1EG 7.52022-08-10
Non-random values for ticket_age_add in session tickets in crypto/tls before Go 1.17.11 and Go 1.18.3 allow an attacker that can observe TLS handshakes to correlate successive connections by comparing ticket ages during session resumption.
- CVE-2022-30782HIGHCVSS 7.5EG 7.52022-05-16
Openmoney API through 2020-06-29 uses the JavaScript Math.random function, which does not provide cryptographically secure random numbers.
- CVE-2022-30935CRITICALCVSS 9.1EG 9.12022-09-28
An authorization bypass in b2evolution allows remote, unauthenticated attackers to predict password reset tokens for any user through the use of a bad randomness function. This allows the attacker to get valid sessions for arbitrary users,…
- CVE-2022-31008MEDIUMCVSS 5.5EG 5.52022-10-06
RabbitMQ is a multi-protocol messaging and streaming broker. In affected versions the shovel and federation plugins perform URI obfuscation in their worker (link) state. The encryption key used to encrypt the URI was seeded with a predicta…
- CVE-2022-31034HIGHCVSS 8.3EG 8.32022-06-27
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All versions of Argo CD starting with v0.11.0 are vulnerable to a variety of attacks when an SSO login is initiated from the Argo CD CLI or UI. The vulnerabilities a…
- CVE-2022-31157HIGHCVSS 7.5EG 7.52022-07-15
LTI 1.3 Tool Library is a library used for building IMS-certified LTI 1.3 tool providers in PHP. Prior to version 5.0, the function used to generate random nonces was not sufficiently cryptographically complex. Users should upgrade to vers…
- CVE-2022-32284HIGHCVSS 7.5EG 7.52022-07-04
Use of insufficiently random values vulnerability exists in Vnet/IP communication module VI461 of YOKOGAWA Wide Area Communication Router (WAC Router) AW810D, which may allow a remote attacker to cause denial-of-service (DoS) condition by …
- CVE-2022-32296LOWCVSS 3.3EG 3.32022-06-05
The Linux kernel before 5.17.9 allows TCP servers to identify clients by observing what source ports are used. This occurs because of use of Algorithm 4 ("Double-Hash Port Selection Algorithm") of RFC 6056.
Map vulnerabilities like CWE-330 to your infrastructure
EchelonGraph correlates every CVE — across CWE-330 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →