Skip to main content

CWE archive

CWE-330 CVEs

Programmatic archive

380 CVEs tagged with CWE-33075 Critical, 129 High, 147 Medium, 29 Low, 0 Unrated.

CVE-2021-23451

Published Jul 25, 2022

The package otp-generator before 3.0.0 are vulnerable to Insecure Randomness due to insecure generation of random one-time passwords, which may allow a brute-force attack.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-31157

Published Jul 15, 2022

LTI 1.3 Tool Library is a library used for building IMS-certified LTI 1.3 tool providers in PHP. Prior to version 5.0, the function used to generate random nonces was not sufficie…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-32284

Published Jul 4, 2022

Use of insufficiently random values vulnerability exists in Vnet/IP communication module VI461 of YOKOGAWA Wide Area Communication Router (WAC Router) AW810D, which may allow a re…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-31034

Published Jun 27, 2022

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All versions of Argo CD starting with v0.11.0 are vulnerable to a variety of attacks when an SSO login is…

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2022-29330

Published Jun 24, 2022

Missing access control in the backup system of Telesoft VitalPBX before 3.2.1 allows attackers to access the PJSIP and SIP extension credentials, cryptographic keys and voicemails…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-23138

Published Jun 9, 2022

ZTE's MF297D product has cryptographic issues vulnerability. Due to the use of weak random values, the security of the device is reduced, and it may face the risk of attack.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-32296

Published Jun 5, 2022

The Linux kernel before 5.17.9 allows TCP servers to identify clients by observing what source ports are used. This occurs because of use of Algorithm 4 ("Double-Hash Port Selecti…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-29930

Published May 12, 2022

SHA1 implementation in JetBrains Ktor Native 2.0.0 was returning the same value. The issue was fixed in Ktor version 2.0.1.

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2022-30295

Published May 6, 2022

uClibc-ng through 1.0.40 and uClibc through 0.9.33.2 use predictable DNS transaction IDs that may lead to DNS cache poisoning. This is related to a reset of a value to 0x2.

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-27577

Published Apr 11, 2022

The vulnerability in the MSC800 in all versions before 4.15 allows for an attacker to predict the TCP initial sequence number. When the TCP sequence is predictable, an attacker ca…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-29035

Published Apr 11, 2022

In JetBrains Ktor Native before version 2.0.0 random values used for nonce generation weren't using SecureRandom implementations

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-26851

Published Apr 8, 2022

Dell PowerScale OneFS, 8.2.2-9.3.x, contains a predictable file name from observable state vulnerability. An unprivileged network attacker could potentially exploit this vulnerabi…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort
Showing 151-175 of 380 CVEsPage 7 of 16