CWE-330

High likelihood

Use of Insufficiently Random Values

Parent: CWE-693 - Protection Mechanism Failure

The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.

381 vulnerabilities with CWE-330
CVE-2019-20494 LOW
cPanel 77.9999.110-81.9999.999 - Use of Insufficiently Random Values in Cpanel::Rand::Get
CVSS 3.3
CVE-2019-19135 HIGH
OPC Foundation OPC UA .NET Standard <1.4.359.31 - Info Disclosure
CVSS 7.4
CVE-2019-9102 HIGH
Moxa MB3170 MB3270 MB3180 MB3280 MB3480 MB3660 Firmware - CSRF Protection Bypass via Predictable Token
CVSS 8.8
CVE-2019-12434 MEDIUM
GitLab 10.6-11.11 - Information Disclosure via Issue Link URL Contrast
CVSS 4.3
CVE-2019-2317 CRITICAL
Snapdragon Auto-SDM632 - Info Disclosure
CVSS 9.8
CVE-2019-18282 MEDIUM
Linux kernel <5.3.10 - Info Disclosure
CVSS 5.3
CVE-2019-16674 CRITICAL
Weidmueller IE-SW-VL05M <3.6.6 - Info Disclosure
CVSS 9.8
CVE-2019-18850 HIGH
TrevorC2 <1.1/1.2 - Info Disclosure
CVSS 7.5
CVE-2019-5232 HIGH
Huawei ViewPoint VP9630 VP9650 VP9660 Firmware - Unauthenticated Information Leak via Insufficiently Random Values
CVSS 7.5
CVE-2019-4411 MEDIUM
IBM Cognos Controller <10.5 - Info Disclosure
CVSS 4.3
CVE-2019-16205 HIGH
Brocade SANnav < 2.0 - Session ID Brute-Force via Insufficiently Random Values
CVSS 8.8
CVE-2019-10084 HIGH
Apache Impala 2.7.0-3.2.0 - Auth Bypass
CVSS 7.5
CVE-2019-13929 MEDIUM
SIMATIC IT UADM < V1.3 - Info Disclosure
CVSS 6.5
CVE-2019-17105 MEDIUM
Centreon Web <2.8.27 - Info Disclosure
CVSS 5.3
CVE-2019-2294 CRITICAL
Qualcomm Snapdragon - Memory Corruption
CVSS 9.8
CVE-2019-1549 MEDIUM
OpenSSL 1.1.1-1.1.1c - Use of Insufficiently Random Values
CVSS 5.3
CVE-2019-15955 MEDIUM
Total.js CMS 12.0.0 - Info Disclosure
CVSS 6.5
CVE-2019-15130 CRITICAL
Humanica Humatrix 7 <=1.0.0.681 - Unauthenticated Arbitrary File Upload RCE via Recruitment Module
CVSS 9.8
CVE-2019-7886 HIGH
Magento <2.1.18-2.3.2 - Info Disclosure
CVSS 7.5
CVE-2019-12821 MEDIUM
Shenzhen Jisiwei i3 - Privilege Escalation
CVSS 4.8
CVE-2019-13603 MEDIUM
HID Global DigitalPersona <5.0.0.5 - Info Disclosure
CVSS 5.9
CVE-2019-1010025 MEDIUM
glibc - Use of Insufficiently Random Values
CVSS 5.3
CVE-2019-6632 MEDIUM
BIG-IP 12.1.0-12.1.4 - Insufficient Randomness in vCMP Configuration Unit Key
CVSS 5.5
CVE-2019-7667 CRITICAL
Prima Systems FlexAir <2.3.38 - Info Disclosure
CVSS 9.8
CVE-2019-6821 MEDIUM
Modicon M580 <V2.30 - Use After Free
CVSS 6.5
Details
Vulnerabilities 381
Exploit Likelihood High