CWE-330
High likelihoodUse of Insufficiently Random Values
The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.
381 vulnerabilities with CWE-330
CVE-2020-14423
MEDIUM
Convos < 4.20 - Use of Insufficiently Random Values in Local Secret Generation
CVSS 5.3
CVE-2020-14422
MEDIUM
Python < 3.5.10 - Denial of Service via IPv4Interface and IPv6Interface Hash Calculation
CVSS 5.9
CVE-2020-11901
CRITICAL
Treck TCP/IP < 6.0.1.66 - Remote Code Execution via Invalid DNS Response
CVSS 9.0
CVE-2020-12712
HIGH
SOS JobScheduler <1.13 - Info Disclosure
CVSS 7.5
CVE-2020-13817
HIGH
ntp < 4.2.8p14 and 4.3.x < 4.3.100 - Denial of Service via Predictable Transmit Timestamps
CVSS 7.4
CVE-2020-5365
MEDIUM
Dell EMC Isilon <8.2.2 - Info Disclosure
CVSS 5.3
CVE-2020-11551
HIGH
NETGEAR Orbi Tri-Band Business WiFi - Unauthenticated RCE
CVSS 8.8
CVE-2020-12858
HIGH
COVIDSafe <1.0.16 - Info Disclosure
CVSS 7.5
CVE-2020-5408
MEDIUM
Spring Security <5.3.2, 5.2.x <5.2.4, 5.1.x <5.1.10, 5.0.x <5.0.16,...
CVSS 6.5
CVE-2020-9502
CRITICAL
Dahua Firmware < 2019-12 - Session ID Predictability
CVSS 9.8
CVE-2020-8792
MEDIUM
OKLOK 3.1.1 - Information Exposure via Predictable Barcode Pattern
CVSS 5.3
CVE-2020-12270
MEDIUM
Bluezone 1.0.0 - Use of Insufficiently Random Values in Bluetooth Scan IDs
CVSS 6.5
CVE-2020-11877
HIGH
Zoom Client for Meetings <4.6.11 - Info Disclosure
CVSS 7.5
CVE-2020-1759
MEDIUM
Red Hat Ceph Storage 4-Red Hat Openshift Container Storage 4.2 - Co...
CVSS 6.4
CVE-2020-11585
MEDIUM
Dnnsoftware Dotnetnuke - Information Disclosure
CVSS 4.3
CVE-2020-11501
HIGH
GnuTLS <3.6.13 - Cryptographic Error
CVSS 7.4
CVE-2020-10870
MEDIUM
zim < 0.72.1 - Denial of Service via Predictable Temporary Directory Names
CVSS 5.5
CVE-2020-1731
CRITICAL
Keycloak Operator <8.0.2 - Info Disclosure
CVSS 9.1
CVE-2020-9449
HIGH
BlaB! AX, BlaB! AX Pro, BlaB! WS - Privilege Escalation
CVSS 8.8
CVE-2020-8988
MEDIUM
Voatz app <2020-01-01 - Info Disclosure
CVSS 5.9
CVE-2020-8631
MEDIUM
cloud-init < 19.4 - Use of Insufficiently Random Values in Password Generation
CVSS 5.5
CVE-2020-2099
HIGH
Jenkins <2.213-<2.204.1 - Info Disclosure
CVSS 8.6
CVE-2020-7241
HIGH
WP Database Backup <5.5 - Info Disclosure
CVSS 7.5
CVE-2020-0644
HIGH
Microsoft Windows - Privilege Escalation
CVSS 7.8
CVE-2019-25089
LOW
Morgawr Muon <0.2.0-indev - Insufficiently Random Values
CVSS 3.1
Details
Vulnerabilities
381
Exploit Likelihood
High