VYPR

CWE-330

Use of Insufficiently Random Values

ClassStableLikelihood: High

Description

The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-112 · CAPEC-485 · CAPEC-59

CVEs mapped to this weakness (398)

page 19 of 20
  • CVE-2026-14702LowJul 5, 2026
    risk 0.00cvss 2.5epss 0.00

    A flaw has been found in zcaceres markdownify-mcp up to 1.1.0. This impacts the function saveToTempFile of the file src/Markdownify.ts of the component webpage-to-markdown/youtube-to-markdown/bing-search-to-markdown. This manipulation causes insufficiently random values. The…

  • CVE-2026-57082MedJun 30, 2026
    risk 0.00cvss 5.9epss 0.00

    Net::BitTorrent versions before 2.1.0 for Perl generate the MSE Diffie-Hellman private key with a non-cryptographic PRNG. The MSE (Message Stream Encryption) handshake derives its 160-bit Diffie-Hellman private key from Perl's rand(), a non-cryptographic drand48-class generator…

  • CVE-2025-15603Mar 9, 2026
    risk 0.00cvss epss 0.00

    Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: The vendor explains: "The 't0p-s3cr3t' default was dead code on every…

  • CVE-2026-27637CriFeb 25, 2026
    risk 0.00cvss 9.8epss 0.01

    FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.206, FreeScout's `TokenAuth` middleware uses a predictable authentication token computed as `MD5(user_id + created_at + APP_KEY)`. This token is static (never…

  • CVE-2024-48928HigFeb 24, 2026
    risk 0.00cvss 7.5epss 0.00

    Piwigo is an open source photo gallery application for the web. In versions on the 14.x branch, when installing, the secret_key configuration parameter is set to MD5(RAND()) in MySQL. However, RAND() only has 30 bits of randomness, making it feasible to brute-force the secret…

  • CVE-2025-64097CriJan 22, 2026
    risk 0.00cvss 9.8epss 0.00

    NervesHub is a web service that allows users to manage over-the-air (OTA) firmware updates of devices in the field. A vulnerability present starting in version 1.0.0 and prior to version 2.3.0 allowed attackers to brute-force user API tokens due to the predictable format of…

  • CVE-2026-21444MedJan 2, 2026
    risk 0.00cvss 5.5epss 0.00

    libtpms, a library that provides software emulation of a Trusted Platform Module, has a flaw in versions 0.10.0 and 0.10.1. The commonly used integration of libtpms with OpenSSL 3.x contained a vulnerability related to the returned IV (initialization vector) when certain…

  • CVE-2025-66511MedDec 5, 2025
    risk 0.00cvss 4.8epss 0.00

    Nextcloud Calendar is a calendar app for Nextcloud. Prior to 6.0.3, the Calendar app generates participant tokens for meeting proposals using a hash function, allowing an attacker to compute valid participant tokens, which allowed them to request details and submit dates in…

  • CVE-2025-0218MedJan 7, 2025
    risk 0.00cvss 5.5epss 0.00

    When batch jobs are executed by pgAgent, a script is created in a temporary directory and then executed. In versions of pgAgent prior to 4.2.3, an insufficiently seeded random number generator is used when generating the directory name, leading to the possibility for a local…

  • CVE-2024-7659LowAug 12, 2024
    risk 0.00cvss 3.7epss 0.01

    A vulnerability, which was classified as problematic, was found in projectsend up to r1605. Affected is the function generate_random_string of the file includes/functions.php of the component Password Reset Token Handler. The manipulation leads to insufficiently random values.…

  • CVE-2022-39216HigMar 14, 2023
    risk 0.00cvss 7.4epss 0.01

    Combodo iTop is an open source, web-based IT service management platform. Prior to versions 2.7.8 and 3.0.2-1, the reset password token is generated without any randomness parameter. This may lead to account takeover. The issue is fixed in versions 2.7.8 and 3.0.2-1.

  • CVE-2023-22746HigFeb 3, 2023
    risk 0.00cvss 8.6epss 0.01

    CKAN is an open-source DMS (data management system) for powering data hubs and data portals. When creating a new container based on one of the Docker images listed below, the same secret key was being used by default. If the users didn't set a custom value via environment…

  • CVE-2022-3959LowNov 11, 2022
    risk 0.00cvss 3.1epss 0.01

    A vulnerability, which was classified as problematic, has been found in drogon up to 1.8.1. Affected by this issue is some unknown functionality of the component Session Hash Handler. The manipulation leads to small space of random values. The attack may be launched remotely.…

  • CVE-2022-40299HigSep 9, 2022
    risk 0.00cvss 7.8epss 0.00

    In Singular before 4.3.1, a predictable /tmp pathname is used (e.g., by sdb.cc), which allows local users to gain the privileges of other users via a procedure in a file under /tmp. NOTE: this CVE Record is about sdb.cc and similar files in the Singular interface that have…

  • CVE-2022-34295MedJun 23, 2022
    risk 0.00cvss 6.5epss 0.02

    totd before 1.5.3 does not properly randomize mesg IDs.

  • CVE-2022-32296LowJun 5, 2022
    risk 0.00cvss 3.3epss 0.00

    The Linux kernel before 5.17.9 allows TCP servers to identify clients by observing what source ports are used. This occurs because of use of Algorithm 4 ("Double-Hash Port Selection Algorithm") of RFC 6056.

  • CVE-2022-29930HigMay 12, 2022
    risk 0.00cvss 8.7epss 0.01

    SHA1 implementation in JetBrains Ktor Native 2.0.0 was returning the same value. The issue was fixed in Ktor version 2.0.1.

  • CVE-2022-29035LowApr 11, 2022
    risk 0.00cvss 3.3epss 0.01

    In JetBrains Ktor Native before version 2.0.0 random values used for nonce generation weren't using SecureRandom implementations

  • CVE-2022-23408CriJan 18, 2022
    risk 0.00cvss 9.1epss 0.01

    wolfSSL 5.x before 5.1.1 uses non-random IV values in certain situations. This affects connections (without AEAD) using AES-CBC or DES3 with TLS 1.1 or 1.2 or DTLS 1.1 or 1.2. This occurs because of misplaced memory initialization in BuildMessage in internal.c.

  • CVE-2021-45458HigJan 6, 2022
    risk 0.00cvss 7.5epss 0.02

    Apache Kylin provides encryption classes PasswordPlaceholderConfigurer to help users encrypt their passwords. In the encryption algorithm used by this encryption class, the cipher is initialized with a hardcoded key and IV. If users use class PasswordPlaceholderConfigurer to…