Skip to main content

CWE archive

CWE-338 CVEs

Programmatic archive

204 CVEs tagged with CWE-33848 Critical, 80 High, 68 Medium, 7 Low, 1 Unrated.

CVE-2024-7315

Published Oct 2, 2024

The Migration, Backup, Staging WordPress plugin before 0.9.106 does not use sufficient randomness in the filename that is created when generating a backup, which could be brutefo…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-47126

Published Sep 26, 2024

The goTenna Pro App does not use SecureRandom when generating passwords for sharing cryptographic keys. The random function in use makes it easier for attackers to brute force t…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-45723

Published Sep 26, 2024

The goTenna Pro ATAK Plugin does not use SecureRandom when generating passwords for sharing cryptographic keys. The random function in use makes it easier for attackers to brute…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-45751

Published Sep 6, 2024

tgt (aka Linux target framework) before 1.0.93 attempts to achieve entropy by calling rand without srand. The PRNG seed is always 1, and thus the sequence of challenges is always…

CVSS 5.9 · Medium

CVE-2023-31305

Published Aug 13, 2024

Generation of weak and predictable Initialization Vector (IV) in PMFW (Power Management Firmware) may allow an attacker with privileges to reuse IV values to reverse-engineer debu…

CVSS 1.9 · Low

CVE-2024-38353

Published Jul 10, 2024

CodiMD allows realtime collaborative markdown notes on all platforms. CodiMD before 2.5.4 is missing authentication and access control vulnerability allowing an unauthenticated at…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-29868

Published Jun 24, 2024

Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) vulnerability in Apache StreamPipes user self-registration and password recovery mechanism. This allows an atta…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-24554

Published Jun 24, 2024

Bludit uses predictable methods in combination with the MD5 hashing algorithm to generate sensitive tokens such as the API token and the user token. This allows attackers to authe…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-5264

Published May 23, 2024

Network Transfer with AES KHT in Thales Luna EFT 2.1 and above allows a user with administrative console access to access backups taken via offline analysis

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-4772

Published May 14, 2024

An HTTP digest authentication nonce value was generated using `rand()` which could lead to predictable values. This vulnerability affects Firefox < 126.

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-34538

Published May 6, 2024

Mateso PasswordSafe through 8.13.9.26689 has Weak Cryptography.

CVSS 7.5 · High

CVE-2023-50059

Published Apr 30, 2024

An issue ingalxe.com Galxe platform 1.0 allows a remote attacker to obtain sensitive information via the Web3 authentication process of Galxe, the signed message lacks a nonce (ra…

CVSS 5.3 · Medium

CVE-2024-25389

Published Mar 27, 2024

RT-Thread through 5.0.2 generates random numbers with a weak algorithm of "seed = 214013L * seed + 2531011L; return (seed >> 16) & 0x7FFF;" in calc_random in drivers/misc/rt_rando…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-23660

Published Feb 8, 2024

The Binance Trust Wallet app for iOS in commit 3cd6e8f647fbba8b5d8844fcd144365a086b629f, git tag 0.0.4 misuses the trezor-crypto library and consequently generates mnemonic words…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-45237

Published Jan 16, 2024

EDK2's Network Package is susceptible to a predictable TCP Initial Sequence Number. This vulnerability can be exploited by an attacker to gain unauthorized access and potentiall…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2023-45236

Published Jan 16, 2024

EDK2's Network Package is susceptible to a predictable TCP Initial Sequence Number. This vulnerability can be exploited by an attacker to gain unauthorized access and potentiall…

CVSS 5.8 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2023-48224

Published Nov 15, 2023

Fides is an open-source privacy engineering platform for managing the fulfillment of data privacy requests in a runtime environment, and the enforcement of privacy regulations in…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-27791

Published Oct 19, 2023

An issue found in IXP Data Easy Install 6.6.148840 allows a remote attacker to escalate privileges via insecure PRNG.

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2023-39910

Published Aug 9, 2023

The cryptocurrency wallet entropy seeding mechanism used in Libbitcoin Explorer 3.0.0 through 3.6.0 is weak, aka the Milk Sad issue. The use of an mt19937 Mersenne Twister PRNG re…

CVSS 7.5 · High
evidence mentions
1
Buzz score
16.5
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2023-36993

Published Jul 7, 2023

The cryptographically insecure random number generator being used in TravianZ 8.3.4 and 8.3.3 in the password reset function allows an attacker to guess the password reset.paramet…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-48506

Published Jun 19, 2023

A flawed pseudorandom number generator in Dominion Voting Systems ImageCast Precinct (ICP and ICP2) and ImageCast Evolution (ICE) scanners allows anyone to determine the order in…

CVSS 2.4 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-32549

Published Jun 6, 2023

Landscape cryptographic keys were insecurely generated with a weak pseudo-random generator.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 101-125 of 204 CVEsPage 5 of 9