CWE-330
High likelihoodUse of Insufficiently Random Values
The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.
381 vulnerabilities with CWE-330
CVE-2026-66391
MEDIUM
Apache Wicket: leaked and missing CSP headers
CVSS 6.5
CVE-2026-46351
HIGH
BigBlueButton: Insecure Randomness allows to guess user's conference session token and impersonate them
CVSS 8.1
CVE-2026-47703
MEDIUM
AdGuard Home: DoQ-to-UDP State Reduction and Source-Port Oracle
CVSS 5.3
CVE-2026-14702
LOW
zcaceres markdownify-mcp webpage-to-markdown Markdownify.ts saveToTempFile random values
CVSS 2.5
CVE-2026-14570
HIGH
Crypt::DSA versions before 1.22 for Perl draw the DSA signing nonce and private key from a biased random generator, leading to private-key recovery
CVSS 7.5
CVE-2026-57082
MEDIUM
Net::BitTorrent versions through 2.0.1 for Perl generate the MSE Diffie-Hellman private key with a non-cryptographic PRNG
CVSS 5.9
CVE-2026-11374
CRITICAL
zohocorp manageengine_adselfservice_plus - Account Takeover via Predictable SSO Ticket Generation
CVSS 9.0
CVE-2026-50009
MEDIUM
Netty QUIC stateless reset token material exposed through header-visible connection IDs
CVSS 4.8
CVE-2026-45673
MEDIUM
Netty: DNS Cache Poisoning due to Predictable PRNG and Default Static Source Port
CVSS 6.8
CVE-2026-41701
MEDIUM
In Spring AMQP sequential correlation IDs enable reply poisoning on fixed reply queues
CVSS 4.4
CVE-2026-41838
MEDIUM
Spring Framework Predictable Session ID in WebSocket Module
CVSS 4.8
CVE-2026-41207
MEDIUM
netty-incubator-codec-ohttp's HPKEContext operations may produce empty byte[] on failures
CVSS 5.3
CVE-2026-50208
CRITICAL
Acer Connect M6E 5G Portable WiFi Router - Permissive TrustAllCerts TLS Verification
CVSS 9.4
CVE-2026-44054
MEDIUM
Netatalk 2.0.0-4.4.2 - Authenticated Denial of Service via Predictable AFP Session Tokens
CVSS 6.5
CVE-2026-42155
CRITICAL
Magento LTS: Weak API Session ID — Predictable MD5 of Time-Derived Inputs
CVE-2026-41505
HIGH
RELATE: Predictable Token Generation in auth.py and exam.py
CVSS 8.7
CVE-2026-7847
LOW
chatchat-space Langchain-Chatchat Uploaded File openai_routes.py _get_file_id random values
CVSS 2.6
CVE-2026-40975
MEDIUM
Spring Boot <4.0.6 - Weak PRNG for Secrets
CVSS 4.8
CVE-2026-40496
CRITICAL
FreeScout has Predictable Attachment Token that Allows Unauthenticated Private File Download via Brute Force
CVSS 9.1
CVE-2026-40306
MEDIUM
DNN has same HostGUID for all new installs
CVSS 6.5
CVE-2026-33710
HIGH
Chamilo LMS has Weak REST API Key Generation (Predictable)
CVSS 7.5
CVE-2026-34511
MEDIUM
OpenClaw < 2026.4.2 - PKCE Verifier Exposure via OAuth State Parameter
CVSS 5.3
CVE-2026-25072
CRITICAL
XikeStor SKS8310-8X <1.04.B07 - Auth Bypass
CVSS 9.8
CVE-2026-20101
HIGH
Cisco Secure Firewall ASA/FTD - DoS
CVSS 8.6
CVE-2026-28415
MEDIUM
Gradio < 6.6.0 - Open Redirect via Unvalidated _target_url Parameter
CVSS 4.3
Details
Vulnerabilities
381
Exploit Likelihood
High