Skip to main content

CWE archive

CWE-338 CVEs

Programmatic archive

204 CVEs tagged with CWE-33848 Critical, 80 High, 68 Medium, 7 Low, 1 Unrated.

CVE-2023-2884

Published May 25, 2023

Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG), Use of Insufficiently Random Values vulnerability in CBOT Chatbot allows Signature Spoofing by Key Recreation.…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-28835

Published Mar 30, 2023

Nextcloud server is an open source home cloud implementation. In affected versions the generated fallback password when creating a share was using a weak complexity random number…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-24828

Published Feb 8, 2023

Onedev is a self-hosted Git Server with CI/CD and Kanban. In versions prior to 7.9.12 the algorithm used to generate access token and password reset keys was not cryptographically…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2022-45782

Published Feb 1, 2023

An issue was discovered in dotCMS core 5.3.8.5 through 5.3.8.15 and 21.03 through 22.10.1. A cryptographically insecure random generation algorithm for password-reset token genera…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-23472

Published Dec 6, 2022

Passeo is an open source python password generator. Versions prior to 1.0.5 rely on the python `random` library for random value selection. The python `random` library warns that…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-44796

Published Nov 7, 2022

An issue was discovered in Object First Ootbi BETA build 1.0.7.712. The authorization service has a flow that allows getting access to the Web UI without knowing credentials. For…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-41210

Published Oct 11, 2022

SAP Customer Data Cloud (Gigya mobile app for Android) - version 7.4, uses insecure random number generator program which makes it easy for the attacker to predict future random n…

CVSS 5.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-40769

Published Sep 18, 2022

profanity through 1.60 has only four billion possible RNG initializations. Thus, attackers can recover private keys from Ethereum vanity addresses and steal cryptocurrency, as exp…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-36045

Published Aug 31, 2022

NodeBB Forum Software is powered by Node.js and supports either Redis, MongoDB, or a PostgreSQL database. It utilizes web sockets for instant interactions and real-time notificati…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-29245

Published May 31, 2022

SSH.NET is a Secure Shell (SSH) library for .NET. In versions 2020.0.0 and 2020.0.1, during an `X25519` key exchange, the client’s private key is generated with `System.Random`. `…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-0828

Published Apr 11, 2022

The Download Manager WordPress plugin before 3.2.34 uses the uniqid php function to generate the master key for a download, allowing an attacker to brute force the key with reason…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-26779

Published Mar 15, 2022

Apache CloudStack prior to 4.16.1.0 used insecure random number generation for project invitation tokens. If a project invite is created based only on an email address, a random t…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-36171

Published Mar 1, 2022

The use of a cryptographically weak pseudo-random number generator in the password reset feature of FortiPortal before 6.0.6 may allow a remote unauthenticated attacker to predict…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2013-20003

Published Feb 4, 2022

Z-Wave devices from Sierra Designs (circa 2013) and Silicon Labs (using S0 security) may use a known, shared network key of all zeros, allowing an attacker within radio range to s…

CVSS 8.3 · High

CVE-2021-43799

Published Jan 25, 2022

Zulip is an open-source team collaboration tool. Zulip Server installs RabbitMQ for internal message passing. In versions of Zulip Server prior to 4.9, the initial installation (u…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2021-45489

Published Dec 25, 2021

In NetBSD through 9.2, the IPv6 Flow Label generation algorithm employs a weak cryptographic PRNG.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-45484

Published Dec 25, 2021

In NetBSD through 9.2, the IPv6 fragment ID generation algorithm employs a weak cryptographic PRNG.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-3990

Published Dec 1, 2021

showdoc is vulnerable to Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4574

Published Oct 27, 2021

PolarSSL versions prior to v1.1 use the HAVEGE random number generation algorithm. At its heart, this uses timing information based on the processor's high resolution timer (the R…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-22948

Published Sep 23, 2021

Vulnerability in the generation of session IDs in revive-adserver < 5.3.0, based on the cryptographically insecure uniqid() PHP function. Under some circumstances, an attacker cou…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort
Showing 126-150 of 204 CVEsPage 6 of 9