İçeriğe atla
Noroxi

CWE-341 · 14 kayıt

Predictable from Observable State

Bu sınıftaki CVE’ler

14 kayıt

  • CVE-2019-6563
    40Planlayın

    Moxa IKS and EDS generate a predictable cookie calculated with an MD5 hash, allowing an attacker to capture the administrator's password, wh

    KritikCVSS 9,8İstismar yokEPSS %2

    moxa · iks-g6824a firmware5 Mar 2019

  • CVE-2020-1731
    39İzleyin

    A flaw was found in all versions of the Keycloak operator, before version 8.0.2,(community only) where the operator generates a random admin

    KritikCVSS 9,8İstismar yokEPSS %1

    redhat · keycloak operator2 Mar 2020

  • CVE-2026-38968
    39İzleyin

    ntopng through 6.6 is vulnerable to Predictable Session Identifier which can lead to Session Hijacking.

    KritikCVSS 9,8İstismar yokEPSS %1

    ntop · ntopng2 Tem 2026

  • CVE-2025-40780
    34İzleyin

    Cache poisoning due to weak PRNG

    YüksekCVSS 8,6İstismar yokEPSS %0

    isc · bind 922 Eki 2025

  • CVE-2020-5365
    30İzleyin

    Dell EMC Isilon versions 8.2.2 and earlier contain a remotesupport vulnerability.

    YüksekCVSS 7,5İstismar yokEPSS %1

    dell · emc isilon onefs20 May 2020

  • CVE-2026-42365
    30İzleyin

    GeoVision LPC2011/LPC2211 Web Interface guessable session cookie vulnerability

    YüksekCVSS 7,5İstismar yokEPSS %1

    geovision · gv-lpc2011 firmware3 May 2026

  • CVE-2023-49259
    30İzleyin

    Bruteforcing authentication cookie for a given user

    YüksekCVSS 7,5İstismar yokEPSS %0

    hongdian · h8951-4g-esp firmware12 Oca 2024

  • CVE-2026-15571
    29İzleyin

    Keycloak-services: keycloak-services: predictable account-linking hash enables account takeover via malicious oidc client

    YüksekCVSS 7,3İstismar yokEPSS %0

    red hat · red hat build of keycloak 26.618 Ağu 2026

  • CVE-2024-10141
    25İzleyin

    jsbroks COCO Annotator Session predictable state

    OrtaCVSS 6,3İstismar yokEPSS %1

    jsbroks · coco annotator19 Eki 2024

  • CVE-2018-17917
    21İzleyin

    All versions of Hangzhou Xiongmai Technology Co., Ltd XMeye P2P Cloud Server may allow an attacker to use MAC addresses to enumerate potenti

    OrtaCVSS 5,3İstismar yokEPSS %1

    xiongmaitech · xmeye p2p cloud server10 Eki 2018

  • CVE-2021-4277
    21İzleyin

    fredsmith utils Filename screenshot_sync predictable state

    OrtaCVSS 5,3İstismar yokEPSS %0

    utils project · utils25 Ara 2022

  • CVE-2025-48461
    20İzleyin

    Weak Session Cookie Entropy

    OrtaCVSS 5,0Kavram kanıtıEPSS %0

    advantech · wise-4060lan firmware23 Haz 2025

  • CVE-2025-42925
    17İzleyin

    Predictable Object Identifier vulnerability in SAP NetWeaver AS Java (IIOP Service)

    OrtaCVSS 4,3İstismar yokEPSS %0

    sap_se · sap netweaver as java (iiop service)8 Eyl 2025

  • CVE-2026-19565
    14İzleyin

    Apache::AppSamurai::Util versions through 1.01 for Perl generate predictable session authentication keys from the clock and process id in CreateSessionAuthKey

    DüşükCVSS 3,7İstismar yokEPSS %0

    23 Ağu 2026

Tüm zafiyet sınıfları