VYPR

CWE-340

Generation of Predictable Numbers or Identifiers

ClassIncomplete

Description

The product uses a scheme that generates numbers or identifiers that are more predictable than required.

Hierarchy (View 1000)

CVEs mapped to this weakness (54)

page 3 of 3
  • CVE-2024-12034MedDec 24, 2024
    risk 0.34cvss 5.3epss 0.00

    The Advanced Google reCAPTCHA plugin for WordPress is vulnerable to IP unblocking in all versions up to, and including, 1.25. This is due to the plugin not utilizing a strong unique key when generating an unblock request. This makes it possible for unauthenticated attackers to…

  • CVE-2021-29480MedJun 29, 2021
    risk 0.29cvss 4.4epss 0.00

    Ratpack is a toolkit for creating web applications. In versions prior to 1.9.0, the client side session module uses the application startup time as the signing key by default. This means that if an attacker can determine this time, and if encryption is not also used (which is…

  • CVE-2025-3449MedOct 7, 2025
    risk 0.27cvss 4.2epss 0.00

    A Generation of Predictable Numbers or Identifiers vulnerability in the SDM component of B&R Automation Runtime versions before 6.4 may allow an unauthenticated network-based attacker to take over already established sessions.

  • CVE-2026-47085MedJul 16, 2026
    risk 0.26cvss 4.0epss 0.00

    An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. URLAUTH token forgery can occur via a missing mboxkey. If an attacker knew a folder name on the victim's account for which the victim had never issued an auth URL, they could forge a working URLAUTH token by…

  • CVE-2020-1905LowOct 6, 2020
    risk 0.22cvss 3.3epss 0.01

    Media ContentProvider URIs used for opening attachments in other apps were generated sequentially prior to WhatsApp for Android v2.20.185, which could have allowed a malicious third party app chosen to open the file to guess the URIs for previously opened attachments until the…

  • CVE-2026-28810LowApr 7, 2026
    risk 0.17cvss 3.7epss 0.00

    Generation of Predictable Numbers or Identifiers vulnerability in Erlang/OTP kernel (inet_res, inet_db modules) allows DNS Cache Poisoning. The built-in DNS resolver (inet_res) uses a sequential, process-global 16-bit transaction ID for UDP queries and does not implement source…

  • CVE-2026-9219MedJun 26, 2026
    risk 0.00cvss 6.5epss 0.00

    Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior have a predictable registration ID derived from IMEI. The enrollment system lacks additional authentication before assignment. If an attacker is able to obtain the registration ID, they would be able…

  • CVE-2025-40926CriMar 5, 2026
    risk 0.00cvss 9.8epss 0.00

    Plack::Middleware::Session::Simple versions before 0.05 for Perl generates session ids insecurely. The default session id generator returns a SHA-1 hash seeded with the built-in rand function, the epoch time, and the PID. The PID will come from a small set of numbers, and the…

  • CVE-2026-3255MedFeb 27, 2026
    risk 0.00cvss 6.5epss 0.00

    HTTP::Session2 versions before 1.12 for Perl for Perl may generate weak session ids using the rand() function. The HTTP::Session2 session id generator returns a SHA-1 hash seeded with the built-in rand function, the epoch time, and the PID. The PID will come from a small set of…

  • CVE-2026-2439CriFeb 16, 2026
    risk 0.00cvss 9.8epss 0.00

    Concierge::Sessions versions from 0.8.1 before 0.8.5 for Perl generate insecure session ids. The generate_session_id function in Concierge::Sessions::Base defaults to using the uuidgen command to generate a UUID, with a fallback to using Perl's built-in rand function. Neither of…

  • CVE-2025-69286CriDec 31, 2025
    risk 0.00cvss 9.8epss 0.01

    RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In versions prior to 0.22.0, the use of an insecure key generation algorithm in the API key and beta (assistant/agent share auth) token generation process allows these tokens to be mutually derivable.…

  • CVE-2024-10603MedJan 30, 2025
    risk 0.00cvss 5.3epss 0.00

    Weaknesses in the generation of TCP/UDP source ports and some other header values in Google's gVisor allowed them to be predicted by an external attacker in some circumstances.

  • CVE-2025-0218MedJan 7, 2025
    risk 0.00cvss 5.5epss 0.00

    When batch jobs are executed by pgAgent, a script is created in a temporary directory and then executed. In versions of pgAgent prior to 4.2.3, an insufficiently seeded random number generator is used when generating the directory name, leading to the possibility for a local…

  • CVE-2011-3871Oct 27, 2011
    risk 0.00cvss epss 0.00

    Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x, when running in --edit mode, uses a predictable file name, which allows local users to run arbitrary Puppet code or trick a user into editing arbitrary files.