VYPR

CWE-330

Use of Insufficiently Random Values

ClassStableLikelihood: High

Description

The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-112 · CAPEC-485 · CAPEC-59

CVEs mapped to this weakness (417)

page 19 of 21
  • CVE-2020-1905LowOct 6, 2020
    risk 0.22cvss 3.3epss 0.01

    Media ContentProvider URIs used for opening attachments in other apps were generated sequentially prior to WhatsApp for Android v2.20.185, which could have allowed a malicious third party app chosen to open the file to guess the URIs for previously opened attachments until the…

  • CVE-2026-28415MedFeb 27, 2026
    risk 0.21cvss 4.3epss 0.00

    Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.6.0, the _redirect_to_target() function in Gradio's OAuth flow accepts an unvalidated _target_url query parameter, allowing redirection to arbitrary external URLs. This affects the /logout…

  • CVE-2019-20494LowMar 17, 2020
    risk 0.21cvss 3.3epss 0.00

    In cPanel before 82.0.18, Cpanel::Rand::Get can produce a predictable series of numbers (SEC-525).

  • CVE-2025-49198LowJun 12, 2025
    risk 0.20cvss 3.1epss 0.00

    The Media Server’s authorization tokens have a poor quality of randomness. An attacker may be able to guess the token of an active user by computing plausible tokens.

  • CVE-2023-2418LowApr 29, 2023
    risk 0.20cvss 3.1epss 0.01

    A vulnerability was found in Konga 2.8.3 on Kong. It has been classified as problematic. This affects an unknown part of the component Login API. The manipulation leads to insufficiently random values. The complexity of an attack is rather high. The exploitability is told to be…

  • CVE-2022-30629LowAug 10, 2022
    risk 0.20cvss 3.1epss 0.01

    Non-random values for ticket_age_add in session tickets in crypto/tls before Go 1.17.11 and Go 1.18.3 allow an attacker that can observe TLS handshakes to correlate successive connections by comparing ticket ages during session resumption.

  • CVE-2026-19906LowAug 15, 2026
    risk 0.17cvss 3.7epss 0.00

    A weakness has been identified in pkp pkp-lib 3.3.0/3.4.0/3.5.0. This vulnerability affects the function setData of the file classes/user/form/APIProfileForm.php of the component API Key Generation. Executing a manipulation of the argument apiKey can lead to insufficient…

  • CVE-2026-19896LowAug 15, 2026
    risk 0.17cvss 3.7epss 0.00

    A flaw has been found in mangroup dtale up to 3.22.0. This vulnerability affects the function build_secret_key of the file dtale/app.py of the component Flask Session Cookie. This manipulation causes insufficiently random values. Remote exploitation of the attack is possible.…

  • CVE-2026-7847LowMay 5, 2026
    risk 0.17cvss 2.6epss 0.00

    A vulnerability was found in chatchat-space Langchain-Chatchat up to 0.3.1.3. The affected element is the function _get_file_id of the file libs/chatchat-server/chatchat/server/api_server/openai_routes.py of the component Uploaded File Handler. Performing a manipulation results…

  • CVE-2025-1953LowMar 4, 2025
    risk 0.17cvss 2.6epss 0.00

    A vulnerability has been found in vLLM AIBrix 0.2.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file pkg/plugins/gateway/prefixcacheindexer/hash.go of the component Prefix Caching. The manipulation leads to insufficiently…

  • CVE-2023-3247LowJul 22, 2023
    risk 0.17cvss 2.6epss 0.01

    In PHP versions 8.0.* before 8.0.29, 8.1.* before 8.1.20, 8.2.* before 8.2.7 when using SOAP HTTP Digest Authentication, random value generator was not checked for failure, and was using narrower range of values than it should have. In case of random generator failure, it could…

  • CVE-2023-3803LowJul 21, 2023
    risk 0.17cvss 2.6epss 0.01

    A vulnerability classified as problematic has been found in Chengdu Flash Flood Disaster Monitoring and Warning System 2.0. This affects an unknown part of the file /Service/ImageStationDataService.asmx of the component File Name Handler. The manipulation leads to insufficiently…

  • CVE-2021-4277LowDec 25, 2022
    risk 0.17cvss 2.6epss 0.00

    A vulnerability, which was classified as problematic, has been found in fredsmith utils. This issue affects some unknown processing of the file screenshot_sync of the component Filename Handler. The manipulation leads to predictable from observable state. The name of the patch…

  • CVE-2016-4980LowNov 27, 2019
    risk 0.16cvss 2.5epss 0.00

    A password generation weakness exists in xquest through 2016-06-13.

  • CVE-2019-25089LowDec 27, 2022
    risk 0.13cvss 3.1epss 0.01

    A vulnerability has been found in Morgawr Muon 0.1.1 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file src/muon/handler.clj. The manipulation leads to insufficiently random values. The attack can be launched remotely. Upgrading…

  • CVE-2021-4241LowNov 15, 2022
    risk 0.10cvss 2.6epss 0.01

    A vulnerability, which was classified as problematic, was found in phpservermon. Affected is the function setUserLoggedIn of the file src/psm/Service/User.php. The manipulation leads to use of predictable algorithm in random number generator. The exploit has been disclosed to…

  • CVE-2021-4240LowNov 15, 2022
    risk 0.10cvss 2.6epss 0.01

    A vulnerability, which was classified as problematic, was found in phpservermon. This affects the function generatePasswordResetToken of the file src/psm/Service/User.php. The manipulation leads to use of predictable algorithm in random number generator. The exploit has been…

  • CVE-2026-81852LowAug 31, 2026
    risk 0.07cvss —epss 0.00

    Use of Insufficiently Random Values vulnerability in ash-project ash_admin ships a hardcoded, publicly known CSP nonce, defeating nonce-based Content-Security-Policy protection. When mounted without :csp_nonce_assign_key, AshAdmin.Router.ash_admin/2 defaulted the img, style,…

  • CVE-2026-46351HigJul 16, 2026
    risk 0.00cvss 8.1epss 0.00

    BigBlueButton is an open-source virtual classroom. Prior to 3.0.21, bbb-web generated conference sessionToken values with insufficiently secure randomness in bbb-common-web/src/main/java/org/bigbluebutton/api/Util.java and bigbluebutton-web/grails-app/controllers/org/bigbluebutto…

  • CVE-2026-14702LowJul 5, 2026
    risk 0.00cvss 2.5epss 0.00

    A flaw has been found in zcaceres markdownify-mcp up to 1.1.0. This impacts the function saveToTempFile of the file src/Markdownify.ts of the component webpage-to-markdown/youtube-to-markdown/bing-search-to-markdown. This manipulation causes insufficiently random values. The…