VYPR

CWE-330

Use of Insufficiently Random Values

ClassStableLikelihood: High

Description

The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-112 · CAPEC-485 · CAPEC-59

CVEs mapped to this weakness (398)

page 14 of 20
  • CVE-2026-40306MedApr 17, 2026
    risk 0.35cvss 6.5epss 0.00

    DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. All new installations of DNN 10.x.x - 10.2.1 have the same Host GUID. This does not affect upgrades from 9.x.x. Version 10.2.2 patches the issue.

  • CVE-2025-11723MedJan 6, 2026
    risk 0.35cvss 6.5epss 0.00

    The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.6.9.5 via the hash() function due to use of a hardcoded fall-back salt. This makes it…

  • CVE-2024-42475MedAug 15, 2024
    risk 0.35cvss 6.5epss 0.00

    In the OAuth library for nim prior to version 0.11, the `state` values generated by the `generateState` function do not have sufficient entropy. These can be successfully guessed by an attacker allowing them to perform a CSRF vs a user, associating the user's session with the…

  • CVE-2024-5149MedJun 5, 2024
    risk 0.35cvss 6.5epss 0.00

    The BuddyForms plugin for WordPress is vulnerable to Email Verification Bypass in all versions up to, and including, 2.8.9 via the use of an insufficiently random activation code. This makes it possible for unauthenticated attackers to bypass the email verification.

  • CVE-2024-21495MedFeb 17, 2024
    risk 0.35cvss 6.5epss 0.01

    Versions of the package github.com/greenpau/caddy-security before 1.0.42 are vulnerable to Insecure Randomness due to using an insecure random number generation library which could possibly be predicted via a brute-force search. Attackers could use the potentially predictable…

  • CVE-2023-46740MedJan 3, 2024
    risk 0.35cvss 6.5epss 0.00

    CubeFS is an open-source cloud-native file storage system. Prior to version 3.3.1, CubeFS used an insecure random string generator to generate user-specific, sensitive keys used to authenticate users in a CubeFS deployment. This could allow an attacker to predict and/or guess…

  • CVE-2023-6376MedNov 30, 2023
    risk 0.35cvss 5.3epss 0.01

    Henschen & Associates court document management software does not sufficiently randomize file names of cached documents, allowing a remote, unauthenticated attacker to access restricted documents.

  • CVE-2021-23451MedJul 25, 2022
    risk 0.35cvss 6.5epss 0.01

    The package otp-generator before 3.0.0 are vulnerable to Insecure Randomness due to insecure generation of random one-time passwords, which may allow a brute-force attack.

  • CVE-2022-33707MedJul 12, 2022
    risk 0.35cvss 5.3epss 0.01

    Improper identifier creation logic in Find My Mobile prior to version 7.2.24.12 allows attacker to identify the device.

  • CVE-2020-35163MedJul 11, 2022
    risk 0.35cvss 5.3epss 0.01

    Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain a Use of Insufficiently Random Values Vulnerability.

  • CVE-2022-29245MedMay 31, 2022
    risk 0.35cvss 6.5epss 0.01

    SSH.NET is a Secure Shell (SSH) library for .NET. In versions 2020.0.0 and 2020.0.1, during an `X25519` key exchange, the client’s private key is generated with `System.Random`. `System.Random` is not a cryptographically secure random number generator, it must therefore not be…

  • CVE-2022-22700MedMar 3, 2022
    risk 0.35cvss 5.3epss 0.01

    CyberArk Identity versions up to and including 22.1 in the 'StartAuthentication' resource, exposes the response header 'X-CFY-TX-TM'. In certain configurations, that response header contains different, predictable value ranges which can be used to determine whether a user exists…

  • CVE-2021-37186MedSep 14, 2021
    risk 0.35cvss 5.4epss 0.00

    A vulnerability has been identified in LOGO! CMR2020 (All versions < V2.2), LOGO! CMR2040 (All versions < V2.2), SIMATIC RTU3010C (All versions < V4.0.9), SIMATIC RTU3030C (All versions < V4.0.9), SIMATIC RTU3031C (All versions < V4.0.9), SIMATIC RTU3041C (All versions <…

  • CVE-2021-26098MedAug 4, 2021
    risk 0.35cvss 5.3epss 0.01

    An instance of small space of random values in the RPC API of FortiSandbox before 4.0.0 may allow an attacker in possession of a few information pieces about the state of the device to possibly predict valid session IDs.

  • CVE-2021-28674MedJul 30, 2021
    risk 0.35cvss 5.4epss 0.01

    The node management page in SolarWinds Orion Platform before 2020.2.5 HF1 allows an attacker to create or delete a node (outside of the attacker's perimeter) via an account with write permissions. This occurs because node IDs are predictable (with incrementing numbers) and the…

  • CVE-2021-27393MedApr 22, 2021
    risk 0.35cvss 5.3epss 0.01

    A vulnerability has been identified in Nucleus NET (All versions), Nucleus ReadyStart V3 (All versions < V2013.08), Nucleus Source Code (Versions including affected DNS modules). The DNS client does not properly randomize UDP port numbers of DNS requests. That could allow an…

  • CVE-2021-25677MedApr 22, 2021
    risk 0.35cvss 5.3epss 0.01

    A vulnerability has been identified in APOGEE PXC Compact (BACnet) (All versions < V3.5.5), APOGEE PXC Compact (P2 Ethernet) (All versions < V2.8.20), APOGEE PXC Modular (BACnet) (All versions < V3.5.5), APOGEE PXC Modular (P2 Ethernet) (All versions < V2.8.20), Nucleus NET (All…

  • CVE-2021-28055MedApr 15, 2021
    risk 0.35cvss 6.5epss 0.01

    An issue was discovered in Centreon-Web in Centreon Platform 20.10.0. The anti-CSRF token generation is predictable, which might allow CSRF attacks that add an admin user.

  • CVE-2020-17470MedDec 11, 2020
    risk 0.35cvss 5.3epss 0.02

    An issue was discovered in FNET through 4.6.4. The code that initializes the DNS client interface structure does not set sufficiently random transaction IDs (they are always set to 1 in _fnet_dns_poll in fnet_dns.c). This significantly simplifies DNS cache poisoning attacks.

  • CVE-2020-27556MedNov 17, 2020
    risk 0.35cvss 5.3epss 0.01

    A predictable device ID in BASETech GE-131 BT-1837836 firmware 20180921 allows unauthenticated remote attackers to connect to the device.