CWE-330— Use of Insufficiently Random Values
The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.— MITRE CWE catalog
383 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-330page 7 of 8
- CVE-2024-10604MEDIUMCVSS 5.3EG 5.32025-01-30
Vulnerabilities in the algorithms used by Fuchsia to populate network protocol header fields, specifically the TCP ISN, TCP timestamp, TCP and UDP source ports, and IPv4/IPv6 fragment ID allow for these values to be guessed under circumsta…
- CVE-2024-12432HIGHCVSS 8.1EG 8.12024-12-18
The WPC Shop as a Customer for WooCommerce plugin for WordPress is vulnerable to account takeover and privilege escalation in all versions up to, and including, 1.2.8. This is due to the 'generate_key' function not producing a sufficiently…
- CVE-2024-1631CRITICALCVSS 9.1EG 9.12024-02-21
Impact: The library offers a function to generate an ed25519 key pair via Ed25519KeyIdentity.generate with an optional param to provide a 32 byte seed value, which will then be used as the secret key. When no seed value is provided, it is …
- CVE-2024-20331MEDIUMCVSS 6.8EG 6.82024-10-23
A vulnerability in the session authentication functionality of the Remote Access SSL VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote a…
- CVE-2024-21460HIGHCVSS 7.1EG 7.12024-07-01
Information disclosure when ASLR relocates the IMEM and Secure DDR portions as one chunk in virtual address space.
- CVE-2024-21495MEDIUMCVSS 6.5EG 6.52024-02-17
Versions of the package github.com/greenpau/caddy-security before 1.0.42 are vulnerable to Insecure Randomness due to using an insecure random number generation library which could possibly be predicted via a brute-force search. Attackers …
- CVE-2024-22473MEDIUMCVSS 6.8EG 6.82024-02-21
TRNG is used before initialization by ECDSA signing driver when exiting EM2/EM3 on Virtual Secure Vault (VSE) devices. This defect may allow Signature Spoofing by Key Recreation.This issue affects Gecko SDK through v4.4.0.
- CVE-2024-23688MEDIUMCVSS 5.3EG 5.32024-01-19
Consensys Discovery versions less than 0.4.5 uses the same AES/GCM nonce for the entire session. which should ideally be unique for every message. The node's private key isn't compromised, only the session key generated for specific peer c…
- CVE-2024-25943HIGHCVSS 7.6EG 7.62024-06-29
iDRAC9, versions prior to 7.00.00.172 for 14th Generation and 7.10.50.00 for 15th and 16th Generations, contains a session hijacking vulnerability in IPMI. A remote attacker could potentially exploit this vulnerability, leading to arbitrar…
- CVE-2024-28013MEDIUMCVSS 5.3EG 5.32024-03-28
Use of Insufficiently Random Values vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2, W1200EX(-MS), WG1200HS, WG1200HP, WF300HP2, W300P, WF800HP, WR8165N, WG2200HP…
- CVE-2024-35292HIGHCVSS 8.2EG 8.22024-06-11
A vulnerability has been identified in SIMATIC S7-200 SMART CPU CR40 (6ES7288-1CR40-0AA0) (All versions), SIMATIC S7-200 SMART CPU CR60 (6ES7288-1CR60-0AA0) (All versions), SIMATIC S7-200 SMART CPU SR20 (6ES7288-1SR20-0AA0) (All versions),…
- CVE-2024-36389CRITICALCVSS 9.8EG 9.82024-06-02
MileSight DeviceHub - CWE-330 Use of Insufficiently Random Values may allow Authentication Bypass
- CVE-2024-41708HIGHCVSS 7.5EG 7.52024-09-25
An issue was discovered in AdaCore ada_web_services 20.0 allows an attacker to escalate privileges and steal sessions via the Random_String() function in the src/core/aws-utils.adb module.
- CVE-2024-4185HIGHCVSS 8.1EG 8.12024-04-30
The Customer Email Verification for WooCommerce plugin for WordPress is vulnerable to Email Verification and Authentication Bypass in all versions up to, and including, 2.7.4 via the use of insufficiently random activation code. This makes…
- CVE-2024-42164MEDIUMCVSS 4.3EG 4.32024-08-12
Insufficiently random values for generating password reset token in FIWARE Keyrock <= 8.4 allow attackers to disable two factor authorization of any user by predicting the token for the disable_2fa link.
- CVE-2024-42165MEDIUMCVSS 6.3EG 6.32024-08-12
Insufficiently random values for generating activation token in FIWARE Keyrock <= 8.4 allow attackers to activate accounts of any user by predicting the token for the activation link.
- CVE-2024-42475MEDIUMCVSS 6.5EG 6.52024-08-15
In the OAuth library for nim prior to version 0.11, the `state` values generated by the `generateState` function do not have sufficient entropy. These can be successfully guessed by an attacker allowing them to perform a CSRF vs a user, as…
- CVE-2024-47187HIGHCVSS 7.5EG 7.52024-10-16
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.7, missing initialization of the random seed for "thash" leads to datasets having predictable hash t…
- CVE-2024-47188HIGHCVSS 7.5EG 7.52024-10-16
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.7, missing initialization of the random seed for "thash" leads to byte-range tracking having predict…
- CVE-2024-48928HIGHCVSS 7.5EG 7.52026-02-24
Piwigo is an open source photo gallery application for the web. In versions on the 14.x branch, when installing, the secret_key configuration parameter is set to MD5(RAND()) in MySQL. However, RAND() only has 30 bits of randomness, making …
- CVE-2024-50684MEDIUMCVSS 6.5EG 6.52025-02-26
SunGrow iSolarCloud Android app V2.1.6.20241017 and prior uses an insecure AES key to encrypt client data (insufficient entropy). This may allow attackers to decrypt intercepted communications between the mobile app and iSolarCloud.
- CVE-2024-51346HIGHCVSS 7.7EG 7.72026-03-25
An issue in Eufy Homebase 2 version 3.3.4.1h allows a local attacker to obtain sensitive information via the cryptographic scheme.
- CVE-2024-5149MEDIUMCVSS 6.5EG 6.52024-06-05
The BuddyForms plugin for WordPress is vulnerable to Email Verification Bypass in all versions up to, and including, 2.8.9 via the use of an insufficiently random activation code. This makes it possible for unauthenticated attackers to byp…
- CVE-2024-52615MEDIUMCVSS 5.3EG 5.32024-11-21
A flaw was found in Avahi-daemon, which relies on fixed source ports for wide-area DNS queries. This issue simplifies attacks where malicious DNS responses are injected.
- CVE-2024-56089HIGHCVSS 7.5EG 7.52025-12-01
An issue in Technitium through v13.2.2 enables attackers to conduct a DNS cache poisoning attack and inject fake responses by reviving the birthday attack.
- CVE-2024-5868MEDIUMCVSS 6.5EG 6.52024-06-15
The WooCommerce - Social Login plugin for WordPress is vulnerable to Email Verification in all versions up to, and including, 2.6.2 via the use of insufficiently random activation code. This makes it possible for unauthenticated attackers …
- CVE-2024-6348HIGHCVSS 7.5EG 7.52024-08-19
Predictable seed generation in the security access mechanism of UDS in the Blind Spot Protection Sensor ECU in Nissan Altima (2022) allows attackers to predict the requested seeds and bypass security controls via repeated ECU resets and se…
- CVE-2024-7558HIGHCVSS 8.7EG 8.72024-10-02
JUJU_CONTEXT_ID is a predictable authentication secret. On a Juju machine (non-Kubernetes) or Juju charm container (on Kubernetes), an unprivileged user in the same network namespace can connect to an abstract domain socket and guess the J…
- CVE-2024-7659LOWCVSS 3.7EG 3.72024-08-12
A vulnerability, which was classified as problematic, was found in projectsend up to r1605. Affected is the function generate_random_string of the file includes/functions.php of the component Password Reset Token Handler. The manipulation …
- CVE-2025-0218MEDIUMCVSS 5.5EG 5.52025-01-07
When batch jobs are executed by pgAgent, a script is created in a temporary directory and then executed. In versions of pgAgent prior to 4.2.3, an insufficiently seeded random number generator is used when generating the directory name, le…
- CVE-2025-10671LOWCVSS 3.7EG 3.72025-09-18
A vulnerability has been found in youth-is-as-pale-as-poetry e-learning 1.0. Impacted is the function encryptSecret of the file e-learning-master\exam-api\src\main\java\com\yf\exam\ability\shiro\jwt\JwtUtils.java of the component JWT Token…
- CVE-2025-10745MEDIUMCVSS 5.3EG 5.32025-09-26
The Banhammer – Monitor Site Traffic, Block Bad Users and Bots plugin for WordPress is vulnerable to Blocking Bypass in all versions up to, and including, 3.4.8. This is due to a site-wide “secret key” being deterministically generat…
- CVE-2025-11707MEDIUMCVSS 5.3EG 5.32025-12-13
The Login Lockdown & Protection plugin for WordPress is vulnerable to IP Block Bypass in all versions up to, and including, 2.14. This is due to $unblock_key key being insufficiently random allowing unauthenticated users, with access to an…
- CVE-2025-11723MEDIUMCVSS 6.5EG 6.52026-01-06
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.6.9.5 via the hash() function due to use of a har…
- CVE-2025-12787MEDIUMCVSS 5.3EG 5.32025-11-11
The Hydra Booking — Appointment Scheduling & Booking Calendar plugin for WordPress is vulnerable to unauthorized booking cancellation in all versions up to, and including, 1.1.27. This is due to the plugin's "tfhb_meeting_form_submit_cal…
- CVE-2025-13353MEDIUMCVSS 5.5EG 5.52025-12-02
In gokey versions <0.2.0, a flaw in the seed decryption logic resulted in passwords incorrectly being derived solely from the initial vector and the AES-GCM authentication tag of the key seed. This issue has been fixed in gokey versio…
- CVE-2025-13470HIGHCVSS 7.5EG 7.52025-11-21
In RNP version 0.18.0 a refactoring regression causes the symmetric session key used for Public-Key Encrypted Session Key (PKESK) packets to be left uninitialized except for zeroing, resulting in it always being an all-zero byte array. …
- CVE-2025-13955CRITICALCVSS 9.3EG 9.32025-12-10
Predictable default Wi-Fi Password in Access Point functionality in EZCast Pro II before version 1.17478.177 allows attackers in Wi-Fi range to gain access to the dongle by calculating the default password from observable device identif…
- CVE-2025-15574MEDIUMCVSS 6.5EG 6.52026-02-12
When connecting to the Solax Cloud MQTT server the username is the "registration number", which is the 10 character string printed on the SolaX Power Pocket device / the QR code on the device. The password is derived from the "registration…
- CVE-2025-1953LOWCVSS 2.6EG 2.62025-03-04
A vulnerability has been found in vLLM AIBrix 0.2.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file pkg/plugins/gateway/prefixcacheindexer/hash.go of the component Prefix Caching. The m…
- CVE-2025-22150MEDIUMCVSS 6.8EG 6.82025-01-21
Undici is an HTTP/1.1 client. Starting in version 4.5.0 and prior to versions 5.28.5, 6.21.1, and 7.2.3, undici uses `Math.random()` to choose the boundary for a multipart/form-data request. It is known that the output of `Math.random()` c…
- CVE-2025-43866HIGHCVSS 7.5EG 7.52025-06-12
vantage6 is an open-source infrastructure for privacy preserving analysis. The JWT secret key in the vantage6 server is auto-generated unless defined by the user. The auto-generated key is a UUID1, which is not cryptographically secure as …
- CVE-2025-4607CRITICALCVSS 9.8EG 9.82025-05-31
The PSW Front-end Login & Registration plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.12 via the customer_registration() function. This is due to the use of a weak, low-entropy OTP mechan…
- CVE-2025-49198LOWCVSS 3.1EG 3.12025-06-12
The Media Server’s authorization tokens have a poor quality of randomness. An attacker may be able to guess the token of an active user by computing plausible tokens.
- CVE-2025-5136LOWCVSS 3.7EG 3.72025-05-25
A vulnerability, which was classified as problematic, was found in Tmall Demo up to 20250505. This affects an unknown part of the file /tmall/order/pay/ of the component Payment Identifier Handler. The manipulation leads to insufficiently …
- CVE-2025-59371HIGHCVSS 7.5EG 7.52025-11-25
An authentication bypass vulnerability has been identified in the IFTTT integration feature. A remote, authenticated attacker could leverage this vulnerability to potentially gain unauthorized access to the device. This vulnerability does …
- CVE-2025-64097CRITICALCVSS 9.8EG 9.82026-01-22
NervesHub is a web service that allows users to manage over-the-air (OTA) firmware updates of devices in the field. A vulnerability present starting in version 1.0.0 and prior to version 2.3.0 allowed attackers to brute-force user API toke…
- CVE-2025-6515MEDIUMCVSS 6.8EG 6.82025-10-20
The MCP SSE endpoint in oatpp-mcp returns an instance pointer as the session ID, which is not unique nor cryptographically secure. This allows network attackers with access to the oatpp-mcp server to guess future session IDs and hijack leg…
- CVE-2025-66511MEDIUMCVSS 6.5EG 6.52025-12-05
Nextcloud Calendar is a calendar app for Nextcloud. Prior to 6.0.3, the Calendar app generates participant tokens for meeting proposals using a hash function, allowing an attacker to compute valid participant tokens, which allowed them to …
- CVE-2025-68704HIGHCVSS 7.5EG 7.52026-01-13
Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, Jervis uses java.util.Random() which is not cryptographically secure for timing attack mitigation. This vulnerability is fixed in 2.2.
Map vulnerabilities like CWE-330 to your infrastructure
EchelonGraph correlates every CVE — across CWE-330 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →