CWE-330

High likelihood

Use of Insufficiently Random Values

Parent: CWE-693 - Protection Mechanism Failure

The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.

381 vulnerabilities with CWE-330
CVE-2021-28674 MEDIUM
SolarWinds Orion Platform < 2020.2.5 - Authenticated Node Creation and Deletion via Predictable Node IDs
CVSS 5.4
CVE-2021-32791 MEDIUM
Apache mod_auth_openidc <2.4.9 - Cryptographic Issue
CVSS 5.9
CVE-2021-29480 MEDIUM
Ratpack < 1.9.0 - Predictable Session Signing Key
CVSS 4.4
CVE-2021-27200 CRITICAL
WoWonder 3.0.4 - Account Takeover via Weak Cryptographic Algorithm in recover.php
CVSS 9.8
CVE-2021-0466 HIGH
Android 10 - Remote Information Disclosure via ClientModeImpl Identifier Tracking
CVSS 7.5
CVE-2021-23020 MEDIUM
F5 NGINX Controller 3.0.0-3.9.9 - Use of Insufficiently Random Values in API Key Generation
CVSS 5.5
CVE-2021-29499 HIGH
SIF - Info Disclosure
CVSS 7.5
CVE-2021-26909 LOW
Automox Agent < 31 - Unauthenticated Sensitive Information Exposure via S3 Bucket Endpoint
CVSS 3.7
CVE-2021-27393 MEDIUM
Nucleus NET, ReadyStart V3 <V2013.08, Source Code - Info Disclosure
CVSS 5.3
CVE-2021-25677 MEDIUM
APOGEE PXC Compact/BACnet, Modular/BACnet, Nucleus NET, ReadyStart ...
CVSS 5.3
CVE-2021-28055 MEDIUM
Centreon 20.10.0-20.10.6 - Predictable Anti-CSRF Token Generation
CVSS 6.5
CVE-2021-21729 MEDIUM
ZTE ZXHN H168N and H108N Firmware - Cross-Site Request Forgery via Missing CSRF Token
CVSS 6.5
CVE-2021-25375 MEDIUM
Samsung Email <6.1.41.0 - Info Disclosure
CVSS 6.5
CVE-2021-3446 MEDIUM
libtpms < 0.8.2 - Weak Cryptographic IV Handling in OpenSSL Integration
CVSS 5.5
CVE-2021-28099 MEDIUM
Netflix OSS Hollow - Info Disclosure
CVSS 4.4
CVE-2021-22309 HIGH
Huawei USG9500/USG9520/USG9560/USG9580 Firmware Information Leak via Insecure Algorithm
CVSS 7.5
CVE-2021-0375 MEDIUM
Android 11 - Local Privilege Escalation via Insecure Default Value in VoiceInteractionManagerService
CVSS 5.5
CVE-2021-21352 MEDIUM
Anuko Time Tracker <1.19.24.5415 - Info Disclosure
CVSS 6.8
CVE-2021-27884 MEDIUM
YMFE YApi < 1.9.2 - Weak JWT Token Generation via Math.random
CVSS 5.1
CVE-2020-27636 CRITICAL
Microchip MPLAB Net <3.6.1 - Info Disclosure
CVSS 9.1
CVE-2020-27635 CRITICAL
PicoTCP 1.7.0 - Use of Insufficiently Random Values in TCP ISN Generation
CVSS 9.1
CVE-2020-27634 CRITICAL
Contiki 4.5 - Use of Insufficiently Random Values in TCP ISN Generation
CVSS 9.1
CVE-2020-27633 CRITICAL
FNET 4.6.3 - Use of Insufficiently Random Values in TCP ISN Generation
CVSS 9.1
CVE-2020-27631 CRITICAL
Oryx CycloneTCP <1.9.6 - Info Disclosure
CVSS 9.8
CVE-2020-27630 CRITICAL
Silicon Labs uC/TCP-IP <3.6.0 - Info Disclosure
CVSS 9.8
Details
Vulnerabilities 381
Exploit Likelihood High