CWE-330

High likelihood

Use of Insufficiently Random Values

Parent: CWE-693 - Protection Mechanism Failure

The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.

381 vulnerabilities with CWE-330
CVE-2023-20185 HIGH
Cisco NX-OS - Inadequate Encryption Strength in CloudSec Feature
CVSS 7.4
CVE-2023-1898 CRITICAL
Atlas Copco Power Focus 6000 - Info Disclosure
CVSS 9.4
CVE-2023-31147 MEDIUM
c-ares < 1.19.1 - Use of Insufficiently Random Values for DNS Query IDs
CVSS 5.9
CVE-2023-31124 LOW
c-ares < 1.19.1 - Use of Insufficiently Random Values via rand() Fallback
CVSS 3.7
CVE-2023-2884 CRITICAL
CBOT Chatbot <4.0.3.4-4.0.3.7 - Signature Spoofing
CVSS 9.8
CVE-2023-1385 HIGH
Amazon Fire TV Stick <6.2.9.5 - Auth Bypass
CVSS 7.1
CVE-2023-2418 LOW
Konga 2.8.3 - Insufficiently Random Values
CVSS 3.1
CVE-2023-30797 HIGH
Netflix Lemur <1.3.2 - Info Disclosure
CVSS 7.5
CVE-2023-26855 HIGH
ChurchCRM v4.5.3 - Use of Insufficiently Random Values in Password Hashing
CVSS 7.5
CVE-2023-0343 MEDIUM
Akuvox E11 - Use of Insufficiently Random Values in Message Encryption
CVSS 6.5
CVE-2023-20016 MEDIUM
Cisco UCS Central <4.2(3c) & FXOS <2.6.1 - Unauthenticated Sensitive Info Disclosure via Hard-coded Key
CVSS 6.3
CVE-2023-22746 HIGH
CKAN < 2.8.12 - Use of Insufficiently Random Values in Default Secret Key
CVSS 8.6
CVE-2023-22912 MEDIUM
MediaWiki <1.35.9, <1.38.5, <1.39.1 - Info Disclosure
CVSS 5.3
CVE-2023-22601 CRITICAL
InHand Networks IR302 <V3.5.56 & InRouter6XX-S <V2.3.0.r5542 - Info...
CVSS 10.0
CVE-2022-43485 MEDIUM
Honeywell OneWireless <322.1 - JWT Token Manipulation
CVSS 6.2
CVE-2022-43636 HIGH
TP-Link TL-WR940N <6_211111 3.20.1(US) - Auth Bypass
CVSS 8.8
CVE-2022-26080 MEDIUM
ABB Pulsar Plus System Controller NE843_S - Insufficiently Random V...
CVSS 6.3
CVE-2022-39216 HIGH
Combodo iTop <2.7.8 & <3.0.2-1 - Info Disclosure
CVSS 7.4
CVE-2022-43501 CRITICAL
Zuken Elmic KASAGO - Info Disclosure
CVSS 9.1
CVE-2022-46353 CRITICAL
SCALANCE X204RNA - Info Disclosure
CVSS 9.8
CVE-2022-44938 CRITICAL
SeedDMS 6.0.20 and 5.1.7 - Account Takeover via Weak Password Reset Token
CVSS 9.8
CVE-2022-3959 LOW
drogon < 1.8.2 - Insufficiently Random Session Hash Values
CVSS 3.1
CVE-2022-36022 MEDIUM
Deeplearning4J <1.0.0-M2.1 - Info Disclosure
CVSS 5.3
CVE-2022-42787 HIGH
W&T Comserver Series - Info Disclosure
CVSS 8.8
CVE-2022-44795 MEDIUM
Object First Ootbi < 1.0.13.1611 - Authenticated Information Disclosure via Predictable Support Bundle URL
CVSS 6.5
Details
Vulnerabilities 381
Exploit Likelihood High