CWE-330: Use of Insufficiently Random Values
The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.
151 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-27755 — SODOLA SL902-SWTGW124AS <= 200.1.20 Predictable Session ID
- CVE-2024-36389 — MileSight DeviceHub - CWE-330 Use of Insufficiently Random Values
- CVE-2025-64097 — NervesHub has Insufficient Token Entropy that Allows Authentication Bypass via Brute Force
- CVE-2025-7783 — Usage of unsafe random function in form-data for choosing boundary
- CVE-2024-1631 — agent-js: Insecure Key Generation in `Ed25519KeyIdentity.generate`
- CVE-2024-10082 — CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy.
- CVE-2026-20101 — A vulnerability in the SAML 2.0 single sign-on (SSO) feature of Cisco Secure Firewall ASA Software and Secure FTD Softwa
- CVE-2025-4607 — PSW Front-end Login & Registration <= 1.12 - Insufficiently Random Values to Unauthenticated Account Takeover/Privilege Escalation via customer_registration Function
- CVE-2025-68704 — Jervis has a Weak Random for Timing Attack Mitigation
- CVE-2026-42155 — Magento LTS: Weak API Session ID — Predictable MD5 of Time-Derived Inputs
- CVE-2026-19485 — Bucket Squatting in Vertex AI Search for Commerce
- CVE-2025-13955 — Predictable Default Wi-Fi Password in EZCast Pro II Dongle
- CVE-2026-66047 — ProfilePress WordPress Plugin < 4.17.2 Unauthenticated Arbitrary Plugin Installation RCE
- CVE-2025-13470 — RNP 0.18.0 Vulnerable PKESK session keys
- CVE-2026-50208 — Permissive TrustAllCerts TLS Verification
- CVE-2026-11374 — Account Takeover via Predictable SSO Ticket Generation
- CVE-2026-62862 — TypeBot: Account takeover via brute-forceable 6-digit magic-link code
- CVE-2026-53939 — OpenIDC/cjose uses all-zero Content Encryption Key for AES-CBC-HMAC JWE encryption
- CVE-2025-59371 — An authentication bypass vulnerability has been identified in the IFTTT integration feature. A remote, authenticated att
- CVE-2024-47188 — Suricata http/byte-ranges: missing hashtable random seed leads to potential DoS
Recently published
- CVE-2026-53939 — OpenIDC/cjose uses all-zero Content Encryption Key for AES-CBC-HMAC JWE encryption
- CVE-2026-86187 — WWBN AVideo Weak PRNG Password Generation via External Login
- CVE-2026-17274 — IBM i is Affected By Multiple Vulnerabilities in Debug Server
- CVE-2026-3416 — Predictable Pseudorandom Number Generation via Webhook HMAC Secret Generation in Multiple WSO2 Products Allows Forged Event Payloads
- CVE-2026-66047 — ProfilePress WordPress Plugin < 4.17.2 Unauthenticated Arbitrary Plugin Installation RCE
- CVE-2026-81852 — AshAdmin ships a hardcoded CSP nonce, allowing nonce-based CSP bypass
- CVE-2026-82555 — TOTOLINK N600R Authentication cstecgi.cgi loginAuth random values
- CVE-2026-19485 — Bucket Squatting in Vertex AI Search for Commerce
- CVE-2026-62862 — TypeBot: Account takeover via brute-forceable 6-digit magic-link code
- CVE-2026-56706 — Adminer before 5.4.3 CSRF Token Secret Recovery via XOR Masking
- CVE-2026-27490 — Combodo iTop: Weak secret generation for inline image
- CVE-2026-19906 — pkp pkp-lib API Key Generation APIProfileForm.php setData entropy
- CVE-2026-19896 — mangroup dtale Flask Session Cookie app.py build_secret_key random values
- CVE-2026-19748 — Tenda CH7 Kylin Web Service CWebSessionManager_ParseSession entropy
- CVE-2026-18531 — IBM MAS uses axios-1.15.2, protobufjs-8.0.1 and undici-7.26 which is vulnerable to multiple CVEs, and contains vulnerabilities related to missing Secure attribute on mas-redirect-uri cookie and weak HMAC Session Secret
- CVE-2026-71225 — Libkcapi: iv reuse in libkcapi one-shot symmetric cipher chunking causes cipher state reset across chunk boundaries
- CVE-2026-66391 — Apache Wicket: leaked and missing CSP headers
- CVE-2026-46351 — BigBlueButton: Insecure Randomness allows to guess user's conference session token and impersonate them
- CVE-2026-47703 — AdGuard Home: DoQ-to-UDP State Reduction and Source-Port Oracle
- CVE-2026-14702 — zcaceres markdownify-mcp webpage-to-markdown Markdownify.ts saveToTempFile random values