CWE-340: Generation of Predictable Numbers or Identifiers
The product uses a scheme that generates numbers or identifiers that are more predictable than required.
52 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-69286 — RAGFlow has Predictable Token Generation Leading to Authentication Bypass Vulnerability
- CVE-2025-68701 — Jervis has Deterministic AES IV Derivation from Passphrase
- CVE-2025-62294 — Predictable Generation of Password Recovery Token
- CVE-2025-40926 — Plack::Middleware::Session::Simple versions before 0.05 for Perl generates session ids insecurely
- CVE-2026-75106 — OpnForm Editable Submission Secret Derivation via Empty Hashids Salt
- CVE-2026-11374 — Account Takeover via Predictable SSO Ticket Generation
- CVE-2026-9733 — Mojolicious::Plugin::Web::Auth::OAuth2 versions through 0.17 for Perl have an insecure default state parameter
- CVE-2026-5085 — Solstice::Session versions through 1440 for Perl generates session ids insecurely
- CVE-2025-40931 — Apache::Session::Generate::MD5 versions through 1.94 for Perl create insecure session id
- CVE-2026-4269 — Improper S3 ownership verification in Bedrock AgentCore Starter Toolkit
- CVE-2024-52299 — The PDF viewer macro allows accessing any attachment without access right checks
- CVE-2026-40496 — FreeScout has Predictable Attachment Token that Allows Unauthenticated Private File Download via Brute Force
- CVE-2026-9219 — Setracker2 Children's Smartwatch Ecosystem Generation of Predictable Numbers or Identifiers
- CVE-2026-5081 — Apache::Session::Generate::ModUniqueId versions from 1.54 through 1.94 for Perl session ids are insecure
- CVE-2025-58424 — BIG-IP TMM vulnerability
- CVE-2024-10603 — Weaknesses in the generation of TCP/UDP source ports and some other header values in Google's gVisor allowed them to be
- CVE-2025-59452 — The YoSmart YoLink API through 2025-10-02 uses an endpoint URL that is derived from a device's MAC address along with an
- CVE-2026-42932 — Naxclow IoT Platform Generation of Predictable Numbers or Identifiers
- CVE-2026-45673 — Netty: DNS Cache Poisoning due to Predictable PRNG and Default Static Source Port
- CVE-2025-0218 — pgAgent scheduled batch job scripts are created in a predictable temporary directory potentially allowing a denial of service
Recently published
- CVE-2026-64964 — Generation of Predictable Email Confirmation Token in ATutor
- CVE-2025-14602 — Weak File Name Generation in vsDesk
- CVE-2026-75106 — OpnForm Editable Submission Secret Derivation via Empty Hashids Salt
- CVE-2026-13577 — Dancer2 versions through 2.1.0 for Perl generate insecure session ids when required CSPRNG modules are unavailable
- CVE-2026-47085 — An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. URLAUTH token forgery can occur via a missing mboxk
- CVE-2026-56016 — CGI::Session::ID::md5 versions before 4.49 for Perl generate predictable session ids from low-entropy sources
- CVE-2026-9219 — Setracker2 Children's Smartwatch Ecosystem Generation of Predictable Numbers or Identifiers
- CVE-2026-11374 — Account Takeover via Predictable SSO Ticket Generation
- CVE-2026-9733 — Mojolicious::Plugin::Web::Auth::OAuth2 versions through 0.17 for Perl have an insecure default state parameter
- CVE-2026-9692 — Mojolicious::Sessions::Storable versions through 0.05 for Perl generate session ids insecurely
- CVE-2026-42932 — Naxclow IoT Platform Generation of Predictable Numbers or Identifiers
- CVE-2026-45673 — Netty: DNS Cache Poisoning due to Predictable PRNG and Default Static Source Port
- CVE-2026-8503 — Apache::Session::Generate::SHA256 versions before 1.3.19 for Perl create insecure session ids
- CVE-2026-5084 — WebDyne::Session versions before 3.003_704 for Perl generate the session id insecurely
- CVE-2026-5081 — Apache::Session::Generate::ModUniqueId versions from 1.54 through 1.94 for Perl session ids are insecure
- CVE-2026-5080 — Dancer::Session::Abstract versions through 1.3522 for Perl generates session ids insecurely
- CVE-2026-40496 — FreeScout has Predictable Attachment Token that Allows Unauthenticated Private File Download via Brute Force
- CVE-2026-5085 — Solstice::Session versions through 1440 for Perl generates session ids insecurely
- CVE-2026-5083 — Ado::Sessions versions through 0.935 for Perl generates insecure session ids
- CVE-2026-5082 — Amon2::Plugin::Web::CSRFDefender versions from 7.00 through 7.03 for Perl generate an insecure session id