CWE-330
High likelihoodUse of Insufficiently Random Values
The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.
375 vulnerabilities with CWE-330
CVE-2026-50009
MEDIUM
Netty QUIC stateless reset token material exposed through header-visible connection IDs
CVSS 4.8
CVE-2026-45673
MEDIUM
Netty: DNS Cache Poisoning due to Predictable PRNG and Default Static Source Port
CVSS 6.8
CVE-2026-41701
MEDIUM
In Spring AMQP sequential correlation IDs enable reply poisoning on fixed reply queues
CVSS 4.4
CVE-2026-41838
MEDIUM
Spring Framework Predictable Session ID in WebSocket Module
CVSS 4.8
CVE-2026-41207
MEDIUM
netty-incubator-codec-ohttp's HPKEContext operations may produce empty byte[] on failures
CVSS 5.3
CVE-2026-50208
CRITICAL
Acer Connect M6E 5G Portable WiFi Router - Permissive TrustAllCerts TLS Verification
CVSS 9.4
CVE-2026-44054
MEDIUM
Netatalk 2.0.0-4.4.2 - Authenticated Denial of Service via Predictable AFP Session Tokens
CVSS 6.5
CVE-2026-42155
CRITICAL
Magento LTS: Weak API Session ID — Predictable MD5 of Time-Derived Inputs
CVE-2026-41505
HIGH
RELATE: Predictable Token Generation in auth.py and exam.py
CVSS 8.7
CVE-2026-7847
LOW
chatchat-space Langchain-Chatchat Uploaded File openai_routes.py _get_file_id random values
CVSS 2.6
CVE-2026-40975
MEDIUM
Spring Boot <4.0.6 - Weak PRNG for Secrets
CVSS 4.8
CVE-2026-40496
CRITICAL
FreeScout has Predictable Attachment Token that Allows Unauthenticated Private File Download via Brute Force
CVSS 9.1
CVE-2026-40306
MEDIUM
DNN has same HostGUID for all new installs
CVE-2026-33710
HIGH
Chamilo LMS has Weak REST API Key Generation (Predictable)
CVSS 7.5
CVE-2026-34511
MEDIUM
OpenClaw < 2026.4.2 - PKCE Verifier Exposure via OAuth State Parameter
CVSS 5.3
CVE-2026-25072
CRITICAL
XikeStor SKS8310-8X <1.04.B07 - Auth Bypass
CVSS 9.8
CVE-2026-20101
HIGH
Cisco Secure Firewall ASA/FTD - DoS
CVSS 8.6
CVE-2026-28415
MEDIUM
Gradio < 6.6.0 - Open Redirect via Unvalidated _target_url Parameter
CVSS 4.3
CVE-2026-27755
CRITICAL
SODOLA SL902-SWTGW124AS <200.1.20 - Auth Bypass
CVSS 9.8
CVE-2026-23999
MEDIUM
Fleet <4.80.1 - Predictable PIN Generation
CVSS 5.5
CVE-2026-27637
CRITICAL
FreeScout < 1.8.206 - Predictable Token Authentication Bypass via MD5 Token
CVSS 9.8
CVE-2026-27515
CRITICAL
Binardat 10G08-0800GSM <V300SP10260209 - Auth Bypass
CVSS 9.1
CVE-2026-2966
LOW
Cesanta Mongoose <=7.20 - DNS Transaction ID Weakness
CVSS 3.7
CVE-2026-21444
MEDIUM
libtpms 0.10.0-0.10.1 - Use of Insufficiently Random Values in IV Generation
CVSS 5.5
CVE-2025-15603
LOW
open-webui <=0.6.16 - Insufficient Randomness
CVSS 3.7
Details
Vulnerabilities
375
Exploit Likelihood
High