CWE-331

Insufficient Entropy

Parent: CWE-330 - Use of Insufficiently Random Values

The product uses an algorithm or scheme that produces insufficient entropy, leaving patterns or clusters of values that are more likely to occur than others.

135 vulnerabilities with CWE-331
CVE-2025-32898 MEDIUM
KDE Connect <2025-04-18 - Info Disclosure
CVSS 4.7
CVE-2025-62774 LOW
Mercku M6a <2.1.0 - Info Disclosure
CVSS 3.1
CVE-2025-59015 MEDIUM
TYPO3 CMS <13.4.17 - Info Disclosure
CVSS 6.5
CVE-2025-54885 MEDIUM
Thinbus Javascript Secure Remote Password <2.0.0 - Info Disclosure
CVE-2025-50122 HIGH
EcoStruxure IT Data Center Expert >=8.3 - Insufficient Entropy in Password Generation
CVE-2025-6931 LOW
D-Link DCS-6517/7517 <2.02.0 - Insufficient Entropy
CVSS 3.7
CVE-2025-52464 HIGH
Meshtastic <2.6.11 - Info Disclosure
CVSS 8.3
CVE-2025-47781 CRITICAL
rallly <= 3.22.1 - Unauthenticated Account Takeover via Weak Email Token Brute Force
CVSS 9.8
CVE-2025-2814 MEDIUM
Crypt::CBC 1.21-3.05 - Weak Cryptographic IV Generation via rand() Fallback
CVSS 4.0
CVE-2025-1860 HIGH
Data::Entropy <0.008 - Info Disclosure
CVSS 7.7
CVE-2025-27552 MEDIUM
DBIx::Class::EncodedColumn <0.00032 - Info Disclosure
CVSS 4.0
CVE-2025-27551 MEDIUM
DBIx::Class::EncodedColumn <0.00032 - Info Disclosure
CVSS 4.0
CVE-2025-29311 HIGH
ONOS 2.7.0 - Insufficient Entropy in LLDP Packet Private Key
CVSS 7.5
CVE-2025-1828 HIGH
Crypt::Random Perl <1.56 - Info Disclosure
CVSS 8.8
CVE-2024-58040 CRITICAL
Crypt::RandomEncryption 0.01 - Insecure RNG
CVSS 9.1
CVE-2024-58134 HIGH
Mojolicious <0.999922 - Info Disclosure
CVSS 8.1
CVE-2024-56370 MEDIUM
Net::Xero <= 0.44 - Insufficient Entropy via rand() Function
CVSS 6.5
CVE-2024-52322 MEDIUM
WebService::Xero <0.11 - Info Disclosure
CVSS 5.5
CVE-2024-58036 MEDIUM
Net::Dropbox::API <1.9 - Info Disclosure
CVSS 5.5
CVE-2024-57868 MEDIUM
Web::API < 2.8 - Insufficient Entropy via rand() Function
CVSS 5.5
CVE-2024-9055 MEDIUM
Silicon Labs Series 2 - Info Disclosure
CVSS 4.2
CVE-2024-53522 HIGH
Bangkok Medical Software HOSxP XE <4.64.11.3 - Info Disclosure
CVSS 7.5
CVE-2024-20331 MEDIUM
Cisco Adaptive Security Appliance Software - Unauthenticated Denial of Service via Session Authentication Handle
CVSS 6.8
CVE-2024-47945 CRITICAL
Session Hijacking - Info Disclosure
CVSS 9.8
CVE-2024-8796 MEDIUM
Devise-Two-Factor >=2.2.0 <6.0.0 - Info Disclosure
CVSS 5.3
Details
Vulnerabilities 135