CWE-330
High likelihoodUse of Insufficiently Random Values
The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.
375 vulnerabilities with CWE-330
CVE-2022-36045
CRITICAL
NodeBB Forum Software - Info Disclosure
CVSS 9.0
CVE-2022-37400
HIGH
Apache OpenOffice <4.1.13 - Info Disclosure
CVSS 8.8
CVE-2022-30629
LOW
Go <1.17.11, 1.18.3 - Info Disclosure
CVSS 3.1
CVE-2022-29808
HIGH
Quest KACE SMA <12.0 - Info Disclosure
CVSS 7.5
CVE-2022-24406
MEDIUM
OX App Suite <= 7.10.6 - Server-Side Request Forgery via Predictable Multipart Boundary
CVSS 6.5
CVE-2022-26306
HIGH
LibreOffice 7.2.0-7.2.6 and 7.3.0 - Inadequate Encryption Strength in Stored Passwords
CVSS 7.5
CVE-2022-31157
HIGH
LTI 1.3 Tool Library <5.0 - Info Disclosure
CVSS 7.5
CVE-2022-33707
MEDIUM
Find My Mobile <7.2.24.12 - Info Disclosure
CVSS 5.3
CVE-2022-26647
HIGH
SCALANCE X200-4P IRT < V5.5.2 - Unauthenticated Session Hijacking via Insecure Session ID Generation
CVSS 8.8
CVE-2022-25047
MEDIUM
Control WebPanel v0.9.8.1126 - Use of Insufficiently Random Values in Password Reset Token
CVSS 5.9
CVE-2022-32284
HIGH
YOKOGAWA AW810D < r12 - Denial of Service via Vnet/IP Communication Module VI461
CVSS 7.5
CVE-2022-31034
HIGH
Argo CD 0.11.0-2.1.16 - Insufficient Entropy in OAuth2/OIDC Login Flow Parameters
CVSS 8.3
CVE-2022-29330
MEDIUM
Telesoft VitalPBX <3.2.1 - Info Disclosure
CVSS 4.9
CVE-2022-34295
MEDIUM
totd < 1.5.3 - Use of Insufficiently Random Values in Message ID Generation
CVSS 6.5
CVE-2022-23138
HIGH
ZTE MF297D Firmware - Use of Insufficiently Random Values
CVSS 7.5
CVE-2022-32296
LOW
Linux kernel <5.17.9 - Info Disclosure
CVSS 3.3
CVE-2022-30782
HIGH
openmoney_api < 2020-06-29 - Use of Insufficiently Random Values via Math.random
CVSS 7.5
CVE-2022-29930
HIGH
JetBrains Ktor Native <2.0.0 - Info Disclosure
CVSS 8.7
CVE-2022-30295
MEDIUM
uClibc-ng <1.0.40, uClibc <0.9.33.2 - Info Disclosure
CVSS 6.5
CVE-2022-26071
HIGH
F5 BIG-IP <16.1.2.2, <15.1.5.1, <14.1.4.6, <13.1.5, <=11.6.x - DoS
CVSS 7.4
CVE-2022-25752
CRITICAL
Siemens SCALANCE X Series - Session Hijacking via Insecure Session ID Generation
CVSS 9.8
CVE-2022-27577
CRITICAL
SICK MSC800 Firmware < 4.15 - TCP Sequence Number Prediction
CVSS 9.1
CVE-2022-29035
LOW
JetBrains Ktor Native <2.0.0 - Info Disclosure
CVSS 3.3
CVE-2022-26851
CRITICAL
Dell PowerScale OneFS <9.3 - Info Disclosure
CVSS 9.1
CVE-2022-22517
HIGH
CODESYS Control Runtime Toolkit < 3.5.18.0 - Unauthenticated Denial of Service via Channel ID Guessing
CVSS 7.5
Details
Vulnerabilities
375
Exploit Likelihood
High