CWE-341
11 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-341page 1 of 1
- CVE-2018-17917MEDIUMCVSS 5.3EG 5.32018-10-10
All versions of Hangzhou Xiongmai Technology Co., Ltd XMeye P2P Cloud Server may allow an attacker to use MAC addresses to enumerate potential Cloud IDs. Using this ID, the attacker can discover and connect to valid devices using one of th…
- CVE-2019-6563CRITICALCVSS 9.8EG 9.82019-03-05
Moxa IKS and EDS generate a predictable cookie calculated with an MD5 hash, allowing an attacker to capture the administrator's password, which could lead to a full compromise of the device.
- CVE-2020-1731CRITICALCVSS 9.1EG 9.12020-03-02
A flaw was found in all versions of the Keycloak operator, before version 8.0.2,(community only) where the operator generates a random admin password when installing Keycloak, however the password remains the same when deployed to the same…
- CVE-2020-5365MEDIUMCVSS 5.3EG 5.32020-05-20
Dell EMC Isilon versions 8.2.2 and earlier contain a remotesupport vulnerability. The pre-configured support account, remotesupport, is bundled in the Dell EMC Isilon OneFS installation. This account is used for diagnostics and other suppo…
- CVE-2021-4277LOWCVSS 2.6EG 5.32022-12-25
A vulnerability, which was classified as problematic, has been found in fredsmith utils. This issue affects some unknown processing of the file screenshot_sync of the component Filename Handler. The manipulation leads to predictable from o…
- CVE-2023-49259HIGHCVSS 7.5EG 7.52024-01-12
The authentication cookies are generated using an algorithm based on the username, hardcoded secret and the up-time, and can be guessed in a reasonable time.
- CVE-2024-10141LOWCVSS 3.7EG 3.72024-10-19
A vulnerability, which was classified as problematic, was found in jsbroks COCO Annotator 0.11.1. This affects an unknown part of the component Session Handler. The manipulation of the argument SECRET_KEY leads to predictable from observab…
- CVE-2025-40780HIGHCVSS 8.6EG 8.62025-10-22
In specific circumstances, due to a weakness in the Pseudo Random Number Generator (PRNG) that is used, it is possible for an attacker to predict the source port and query ID that BIND will use. This issue affects BIND 9 versions 9.16.0 th…
- CVE-2025-42925MEDIUMCVSS 4.3EG 4.32025-09-09
Due to the lack of randomness in assigning Object Identifiers in the SAP NetWeaver AS JAVA IIOP service, an authenticated attacker with low privileges could predict the identifiers by conducting a brute force search. By leveraging knowledg…
- CVE-2025-48461MEDIUMCVSS 5.0EG 5.02025-06-24
Successful exploitation of the vulnerability could allow an unauthenticated attacker to conduct brute force guessing and account takeover as the session cookies are predictable, potentially allowing the attackers to gain root, admin or use…
- CVE-2026-42365HIGHCVSS 8.6EG 8.62026-05-04
A guessable session cookie vulnerability exists in the Web Interface functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted series of HTTP requests can lead to an authentication bypas. An attacker can bruteforce session cooki…
Map vulnerabilities like CWE-341 to your infrastructure
EchelonGraph correlates every CVE — across CWE-341 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →