CWE-1241: Use of Predictable Algorithm in Random Number Generator
The device uses an algorithm that is predictable and generates a pseudo-random number.
8 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-57869 — Broken object-level access controls and the use of a deterministic pattern during random ID generation in MicroRealEstat
- CVE-2025-13079 — Popup Builder - Create highly converting, mobile friendly marketing popups. <= 4.4.2 - Improper Authorization to Unauthenticated Subscriber Removal via Predictable Tokens
- CVE-2026-6420 — Keylime: keylime: security bypass due to hardcoded tpm quote nonce
- CVE-2026-73576 — In Zimbra Collaboration (ZCS) before 10.1.17, weak cryptographic key generation vulnerability exists in the OnlyOffice i
- CVE-2025-32056 — Anti-Theft Bypass for Infotainment ECU
Recently published
- CVE-2026-73576 — In Zimbra Collaboration (ZCS) before 10.1.17, weak cryptographic key generation vulnerability exists in the OnlyOffice i
- CVE-2026-57869 — Broken object-level access controls and the use of a deterministic pattern during random ID generation in MicroRealEstat
- CVE-2026-6420 — Keylime: keylime: security bypass due to hardcoded tpm quote nonce
- CVE-2025-13079 — Popup Builder - Create highly converting, mobile friendly marketing popups. <= 4.4.2 - Improper Authorization to Unauthenticated Subscriber Removal via Predictable Tokens
- CVE-2025-32056 — Anti-Theft Bypass for Infotainment ECU