CWE-330
High likelihoodUse of Insufficiently Random Values
The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.
375 vulnerabilities with CWE-330
CVE-2021-29499
HIGH
SIF - Info Disclosure
CVSS 7.5
CVE-2021-26909
LOW
Automox Agent < 31 - Unauthenticated Sensitive Information Exposure via S3 Bucket Endpoint
CVSS 3.7
CVE-2021-27393
MEDIUM
Nucleus NET, ReadyStart V3 <V2013.08, Source Code - Info Disclosure
CVSS 5.3
CVE-2021-25677
MEDIUM
APOGEE PXC Compact/BACnet, Modular/BACnet, Nucleus NET, ReadyStart ...
CVSS 5.3
CVE-2021-28055
MEDIUM
Centreon 20.10.0-20.10.6 - Predictable Anti-CSRF Token Generation
CVSS 6.5
CVE-2021-21729
MEDIUM
ZTE ZXHN H168N and H108N Firmware - Cross-Site Request Forgery via Missing CSRF Token
CVSS 6.5
CVE-2021-25375
MEDIUM
Samsung Email <6.1.41.0 - Info Disclosure
CVSS 6.5
CVE-2021-3446
MEDIUM
libtpms < 0.8.2 - Weak Cryptographic IV Handling in OpenSSL Integration
CVSS 5.5
CVE-2021-28099
MEDIUM
Netflix OSS Hollow - Info Disclosure
CVSS 4.4
CVE-2021-22309
HIGH
Huawei USG9500/USG9520/USG9560/USG9580 Firmware Information Leak via Insecure Algorithm
CVSS 7.5
CVE-2021-0375
MEDIUM
Android 11 - Local Privilege Escalation via Insecure Default Value in VoiceInteractionManagerService
CVSS 5.5
CVE-2021-21352
MEDIUM
Anuko Time Tracker <1.19.24.5415 - Info Disclosure
CVSS 6.8
CVE-2021-27884
MEDIUM
YMFE YApi < 1.9.2 - Weak JWT Token Generation via Math.random
CVSS 5.1
CVE-2020-27636
CRITICAL
Microchip MPLAB Net <3.6.1 - Info Disclosure
CVSS 9.1
CVE-2020-27635
CRITICAL
PicoTCP 1.7.0 - Use of Insufficiently Random Values in TCP ISN Generation
CVSS 9.1
CVE-2020-27634
CRITICAL
Contiki 4.5 - Use of Insufficiently Random Values in TCP ISN Generation
CVSS 9.1
CVE-2020-27633
CRITICAL
FNET 4.6.3 - Use of Insufficiently Random Values in TCP ISN Generation
CVSS 9.1
CVE-2020-27631
CRITICAL
Oryx CycloneTCP <1.9.6 - Info Disclosure
CVSS 9.8
CVE-2020-27630
CRITICAL
Silicon Labs uC/TCP-IP <3.6.0 - Info Disclosure
CVSS 9.8
CVE-2020-27213
HIGH
Ethernut Nut/OS 5.1 - Info Disclosure
CVSS 7.5
CVE-2020-36732
MEDIUM
crypto-js < 3.2.1 - Insufficient Entropy in Random Number Generation
CVSS 5.3
CVE-2020-35163
MEDIUM
Dell BSAFE <4.1.5-4.6 - Use of Insufficiently Random Values
CVSS 5.3
CVE-2020-35685
CRITICAL
HCC Nichestack 3.0 - Info Disclosure
CVSS 9.1
CVE-2020-10729
MEDIUM
Ansible Engine < 2.9.6 - Use of Insufficiently Random Values in Password Lookup
CVSS 5.5
CVE-2020-36252
MEDIUM
ownCloud Server <10.3.1 - Info Disclosure
CVSS 6.8
Details
Vulnerabilities
375
Exploit Likelihood
High