CWE-330

High likelihood

Use of Insufficiently Random Values

Parent: CWE-693 - Protection Mechanism Failure

The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.

381 vulnerabilities with CWE-330
CVE-2021-36294 CRITICAL
Dell VNX2 OE for File <8.1.21.266 - Auth Bypass
CVSS 9.8
CVE-2021-45458 HIGH
Apache Kylin <2.6.6, <3.1.2 - Info Disclosure
CVSS 7.5
CVE-2021-24998 HIGH
Simple JWT Login WP <3.3.0 - Info Disclosure
CVSS 7.5
CVE-2021-45488 HIGH
NetBSD < 9.2 - Information Leak via TCP ISN Generation Algorithm
CVSS 7.5
CVE-2021-45487 HIGH
NetBSD < 9.2 - Use of Insufficiently Random Values in IPv4 ID Generation
CVSS 7.5
CVE-2021-44151 HIGH
Reprise License Manager 14.2-<15.1 - Session Hijacking via Weak Session Cookie
CVSS 7.5
CVE-2021-41694 CRITICAL
Premiumdatingscript 4.2.7.7 - Info Disclosure
CVSS 9.8
CVE-2021-38377 MEDIUM
OX App Suite <= 7.10.5 - Cross-Site Scripting via Predictable UUID in Truncated Email
CVSS 6.1
CVE-2021-22968 HIGH
Concrete CMS < 8.5.7 - Authenticated Remote Code Execution via File Upload Bypass
CVSS 7.2
CVE-2021-26322 HIGH
AMD EPYC Firmware - Information Disclosure via Weak IV
CVSS 7.5
CVE-2021-28024 CRITICAL
ServiceTonic Helpdesk <9.0.35937 - Privilege Escalation
CVSS 9.8
CVE-2021-22038 HIGH
Windows Uninstaller - Privilege Escalation
CVSS 8.8
CVE-2021-41829 HIGH
Zoho ManageEngine Remote Access Plus <10.1.2121.1 - RCE
CVSS 7.5
CVE-2021-41061 MEDIUM
RIOT-OS 2021.01 - Nonce Reuse in 802.15.4 Encryption
CVSS 5.5
CVE-2021-37186 MEDIUM
Siemens LOGO! CMR2020/CMR2040 < 2.2 & SIMATIC RTU3010C/RTU3030C/RTU3031C/RTU3041C < 4.0.9 - Predictable TCP ISN
CVSS 5.4
CVE-2021-34646 CRITICAL
Booster for WooCommerce <= 5.4.3 - Authentication Bypass via Email Verification Token Weakness
CVSS 9.8
CVE-2021-31228 HIGH
HCC embedded InterNiche 4.0.1 - SSRF
CVSS 7.5
CVE-2021-0417 MEDIUM
Android - Denial of Service in Memory Management Driver
CVSS 5.5
CVE-2021-39249 MEDIUM
Invision Power Board < 4.6.5.1 - Reflected Cross-Site Scripting via Predictable Uploaded Filename
CVSS 6.1
CVE-2021-38606 CRITICAL
reNgine < 0.5 - Predictable Directory Name
CVSS 9.8
CVE-2021-3692 MEDIUM
Yii 2.0.0-2.0.42 - Use of Predictable Algorithm in Random Number Generator
CVSS 5.3
CVE-2021-3689 HIGH
Yii 2.0.0-2.0.42 - Use of Predictable Algorithm in Random Number Generator
CVSS 7.5
CVE-2021-25444 MEDIUM
keymaster <SMR AUG-2021 Release 1 - Info Disclosure
CVSS 5.5
CVE-2021-26098 MEDIUM
FortiSandbox <4.0.0 - Info Disclosure
CVSS 5.3
CVE-2021-27499 MEDIUM
Ypsomed mylife <1.7.2-1.7.5 - Info Disclosure
CVSS 5.9
Details
Vulnerabilities 381
Exploit Likelihood High