CWE-330
High likelihoodUse of Insufficiently Random Values
The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.
381 vulnerabilities with CWE-330
CVE-2018-16239
CRITICAL
damicms 6.0.1 - Session Hijacking via Predictable Cookie Generation
CVSS 9.8
CVE-2018-15807
HIGH
POSIM EVO 15.13 - Unauthenticated Bypass via Emergency Override Code Prediction
CVSS 7.8
CVE-2018-13280
HIGH
Synology DSM <6.2-23739 - Info Disclosure
CVSS 7.4
CVE-2018-11045
MEDIUM
Pivotal Operations Manager <2.1.6, <2.0.15, <1.12.22 - Info Disclosure
CVSS 5.9
CVE-2018-1108
MEDIUM
kernel drivers <4.17-rc1 - Info Disclosure
CVSS 5.9
CVE-2018-1266
HIGH
Cloudfoundry Capi-release < 1.52.0 - Path Traversal
CVSS 8.1
CVE-2017-5242
HIGH
Nexpose & InsightVM - Info Disclosure
CVSS 7.7
CVE-2017-16031
HIGH
socket.io < 0.9.6 - Predictable Socket ID via Math.random()
CVSS 7.5
CVE-2017-16028
MEDIUM
react-native-meteor-oauth - Info Disclosure
CVSS 5.3
CVE-2017-16924
CRITICAL
ManageEngine Desktop Central MSP <10.0.137 - Info Disclosure
CVSS 9.8
CVE-2017-15654
HIGH
Asus asuswrt <= 3.0.0.4.380.7743 - Info Disclosure
CVSS 8.3
CVE-2017-17704
HIGH
Software House iStar Ultra <6.5.2.20569 - Replay Attack
CVSS 7.4
CVE-2017-17910
MEDIUM
Hoermann BiSecur <2018 - Info Disclosure
CVSS 6.5
CVE-2017-17091
HIGH
WordPress < 4.9.1 - Use of Insufficiently Random Values in User ID Key Generation
CVSS 8.8
CVE-2017-10874
HIGH
PWR-Q200 Firmware - DNS Cache Poisoning via Predictable Source Ports
CVSS 7.5
CVE-2017-12361
MEDIUM
Cisco Jabber for Windows - Info Disclosure
CVSS 4.0
CVE-2017-1000246
MEDIUM
Python pysaml2 <4.4.0 - Info Disclosure
CVSS 5.3
CVE-2017-13088
MEDIUM
WPA/WPA2 - Reinstallation
CVSS 5.3
CVE-2017-13087
MEDIUM
hostapd - Use of Insufficiently Random Values in WPA/WPA2 GTK Reinstallation
CVSS 5.3
CVE-2017-13086
MEDIUM
WPA/WPA2 - Reinstallation
CVSS 6.8
CVE-2017-13084
MEDIUM
Wi-Fi Protected Access - Replay Attack
CVSS 6.8
CVE-2017-13082
HIGH
WPA/WPA2 - Reinstallation
CVSS 8.1
CVE-2017-13081
MEDIUM
WPA/WPA2 - Reinstallation
CVSS 5.3
CVE-2017-13080
MEDIUM
WPA/WPA2 - Reinstallation
CVSS 5.3
CVE-2017-13079
MEDIUM
Wi-Fi Protected Access - Reinstallation
CVSS 5.3
Details
Vulnerabilities
381
Exploit Likelihood
High