CWE-330

High likelihood

Use of Insufficiently Random Values

Parent: CWE-693 - Protection Mechanism Failure

The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.

381 vulnerabilities with CWE-330
CVE-2026-27755 CRITICAL
SODOLA SL902-SWTGW124AS <200.1.20 - Auth Bypass
CVSS 9.8
CVE-2026-23999 MEDIUM
Fleet <4.80.1 - Predictable PIN Generation
CVSS 5.5
CVE-2026-27637 CRITICAL
FreeScout < 1.8.206 - Predictable Token Authentication Bypass via MD5 Token
CVSS 9.8
CVE-2026-27515 CRITICAL
Binardat 10G08-0800GSM <V300SP10260209 - Auth Bypass
CVSS 9.1
CVE-2026-2966 LOW
Cesanta Mongoose <=7.20 - DNS Transaction ID Weakness
CVSS 3.7
CVE-2026-21444 MEDIUM
libtpms 0.10.0-0.10.1 - Use of Insufficiently Random Values in IV Generation
CVSS 5.5
CVE-2025-15574 MEDIUM
Solax Cloud MQTT - Authentication Bypass
CVSS 6.5
CVE-2025-64097 CRITICAL
NervesHub 1.0.0-2.2.9 - Predictable API Token Generation via Insufficiently Random Values
CVSS 9.8
CVE-2025-68704 HIGH
Jervis < 2.2 - Use of Insufficiently Random Values
CVSS 7.5
CVE-2025-11723 MEDIUM
Simply Schedule Appointments Booking Plugin <1.6.9.5 - Info Disclosure
CVSS 6.5
CVE-2025-11707 MEDIUM
Login Lockdown & Protection <2.14 - Auth Bypass
CVSS 5.3
CVE-2025-13955 CRITICAL
EZCast Pro II <1.17478.146 - Info Disclosure
CVE-2025-66511 MEDIUM
Nextcloud Calendar <6.0.3 - Info Disclosure
CVSS 4.8
CVE-2025-13353 MEDIUM
gokey < 0.2.0 - Use of Insufficiently Random Values via Seed File Entropy Reduction
CVSS 5.5
CVE-2025-59371 HIGH
ASUS Router - Authentication Bypass via IFTTT Integration
CVE-2025-13470 HIGH
RNP 0.18.0 - Confidentiality Compromise
CVSS 7.5
CVE-2025-12787 MEDIUM
Hydra Booking - Appointment Scheduling & Booking Calendar <1.1.27 -...
CVSS 5.3
CVE-2025-6515 MEDIUM
oatpp-mcp SSE Endpoint - Predictable Session ID Hijacking
CVSS 6.8
CVE-2025-10745 MEDIUM
Banhammer <= 3.4.8 - Unauthenticated Blocking Bypass via Predictable Secret Key
CVSS 5.3
CVE-2025-10671 LOW
youth-is-as-pale-as-poetry e-learning 1.0 - Info Disclosure
CVSS 3.7
CVE-2025-7783 CRITICAL
form-data <2.5.4, 3.0.0-3.0.3, 4.0.0-4.0.3 - HPP
CVE-2025-6931 LOW
D-Link DCS-6517/7517 <2.02.0 - Insufficient Entropy
CVSS 3.7
CVE-2025-43866 HIGH
vantage6 < 4.11.0 - Use of Insufficiently Random Values for JWT Secret Key
CVSS 7.5
CVE-2025-49198 LOW
SICK Media Server - Use of Insufficiently Random Values in Authorization Tokens
CVSS 3.1
CVE-2025-4607 CRITICAL
PSW Front-end Login & Registration <1.12 - Privilege Escalation
CVSS 9.8
Details
Vulnerabilities 381
Exploit Likelihood High