CWE-330

High likelihood

Use of Insufficiently Random Values

Parent: CWE-693 - Protection Mechanism Failure

The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.

381 vulnerabilities with CWE-330
CVE-2022-31008 MEDIUM
RabbitMQ 3.9.0-3.9.17 & VMware RabbitMQ <3.8.32 - Weak URI Obfuscation in Shovel/Federation
CVSS 5.5
CVE-2022-30935 CRITICAL
b2evolution < 7.2.5 - Unauthenticated Authorization Bypass via Predictable Password Reset Tokens
CVSS 9.1
CVE-2022-38970 MEDIUM
ieGeek IG20 hipcam RealServer V1.0 - Incorrect Access Control
CVSS 6.5
CVE-2022-36536 CRITICAL
Syncovery <9.47x - Privilege Escalation
CVSS 9.8
CVE-2022-40299 HIGH
Singular <4.3.1 - Privilege Escalation
CVSS 7.8
CVE-2022-1615 MEDIUM
Samba 4.1.0-4.16.9 - Use of Insufficiently Random Values via GnuTLS gnutls_rnd()
CVSS 5.5
CVE-2022-36045 CRITICAL
NodeBB Forum Software - Info Disclosure
CVSS 9.0
CVE-2022-37400 HIGH
Apache OpenOffice <4.1.13 - Info Disclosure
CVSS 8.8
CVE-2022-30629 LOW
Go <1.17.11, 1.18.3 - Info Disclosure
CVSS 3.1
CVE-2022-29808 HIGH
Quest KACE SMA <12.0 - Info Disclosure
CVSS 7.5
CVE-2022-24406 MEDIUM
OX App Suite <= 7.10.6 - Server-Side Request Forgery via Predictable Multipart Boundary
CVSS 6.5
CVE-2022-26306 HIGH
LibreOffice 7.2.0-7.2.6 and 7.3.0 - Inadequate Encryption Strength in Stored Passwords
CVSS 7.5
CVE-2022-31157 HIGH
LTI 1.3 Tool Library <5.0 - Info Disclosure
CVSS 7.5
CVE-2022-33707 MEDIUM
Find My Mobile <7.2.24.12 - Info Disclosure
CVSS 5.3
CVE-2022-26647 HIGH
SCALANCE X200-4P IRT < V5.5.2 - Unauthenticated Session Hijacking via Insecure Session ID Generation
CVSS 8.8
CVE-2022-25047 MEDIUM
Control WebPanel v0.9.8.1126 - Use of Insufficiently Random Values in Password Reset Token
CVSS 5.9
CVE-2022-32284 HIGH
YOKOGAWA AW810D < r12 - Denial of Service via Vnet/IP Communication Module VI461
CVSS 7.5
CVE-2022-31034 HIGH
Argo CD 0.11.0-2.1.16 - Insufficient Entropy in OAuth2/OIDC Login Flow Parameters
CVSS 8.3
CVE-2022-29330 MEDIUM
Telesoft VitalPBX <3.2.1 - Info Disclosure
CVSS 4.9
CVE-2022-34295 MEDIUM
totd < 1.5.3 - Use of Insufficiently Random Values in Message ID Generation
CVSS 6.5
CVE-2022-23138 HIGH
ZTE MF297D Firmware - Use of Insufficiently Random Values
CVSS 7.5
CVE-2022-32296 LOW
Linux kernel <5.17.9 - Info Disclosure
CVSS 3.3
CVE-2022-30782 HIGH
openmoney_api < 2020-06-29 - Use of Insufficiently Random Values via Math.random
CVSS 7.5
CVE-2022-29930 HIGH
JetBrains Ktor Native <2.0.0 - Info Disclosure
CVSS 8.7
CVE-2022-30295 MEDIUM
uClibc-ng <1.0.40, uClibc <0.9.33.2 - Info Disclosure
CVSS 6.5
Details
Vulnerabilities 381
Exploit Likelihood High