CWE-331 · 138 records
Insufficient Entropy
CVEs in this class
138 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
56Plan | CVE-2008-1447Weaponized | The DNS protocol, as implemented in (1) BIND 8 and 9 before 9.5.0-P1, 9.4.2-P1, and 9.3.5-P1; (2) Microsoft DNS in Windows 2000 SP4, XP SP2 microsoft · windows 2000 · CWE-331 | Medium6.8 | — | 95.2% | Jul 8, 2008 |
46Plan | CVE-2018-18326Weaponized | DNN (aka DotNetNuke) 9.2 through 9.2.2 incorrectly converts encryption key source values, resulting in lower than expected entropy.dnnsoftware · dotnetnuke · CWE-331 | High7.5 | — | 54.3% | Jul 3, 2019 |
44Plan | CVE-2018-15812Weaponized | DNN (aka DotNetNuke) 9.2 through 9.2.1 incorrectly converts encryption key source values, resulting in lower than expected entropy.dnnsoftware · dotnetnuke · CWE-331 | High7.5 | — | 47.2% | Jul 3, 2019 |
40Plan | CVE-2008-2108No exploit | The GENERATE_SEED macro in PHP 4.x before 4.4.8 and 5.x before 5.2.5, when running on 64-bit systems, performs a multiplication that generatphp · php · CWE-331 | Critical9.8 | — | 4.3% | May 7, 2008 |
40Plan | CVE-2013-2260No exploit | Cryptocat before 2.0.22: Cryptocat.random() Function Array Key has Entropy Weaknesscryptocat project · cryptocat · CWE-331 | Critical9.8 | — | 2.2% | Nov 4, 2019 |
40Plan | CVE-2022-34294No exploit | totd 1.5.3 uses a fixed UDP source port in upstream queries sent to DNS resolvers.totd project · totd · CWE-331 | Critical9.8 | — | 1.8% | Aug 15, 2022 |
40Plan | CVE-2022-43755No exploit | Rancher: Non-random authentication tokensuse · rancher · CWE-331 | Critical9.8 | — | 1.7% | Feb 7, 2023 |
40Plan | CVE-2020-12735No exploit | reset.php in DomainMOD 4.13.0 uses insufficient entropy for password reset requests, leading to account takeover.domainmod · domainmod · CWE-331 | Critical9.8 | — | 1.7% | May 8, 2020 |
40Plan | CVE-2018-1000620No exploit | Eran Hammer cryptiles version 4.1.1 earlier contains a CWE-331: Insufficient Entropy vulnerability in randomDigits() method that can result cryptiles project · cryptiles · CWE-331 | Critical9.8 | — | 1.7% | Jul 9, 2018 |
39Monitor | CVE-2021-36294No exploit | Dell VNX2 OE for File versions 8.1.21.266 and earlier, contain an authentication bypass vulnerability.dell · emc unity operating environment · CWE-331 | Critical9.8 | — | 1.6% | Jan 25, 2022 |
39Monitor | CVE-2021-22727No exploit | A CWE-331: Insufficient Entropy vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parkingschneider-electric · evlink city evc1s22p4 firmware · CWE-331 | Critical9.8 | — | 1.4% | Jul 21, 2021 |
39Monitor | CVE-2021-41615No exploit | websda.c in GoAhead WebServer 2.1.8 has insufficient nonce entropy because the nonce calculation relies on the hardcoded onceuponatimeinparaembedthis · goahead · CWE-331 | Critical9.8 | — | 1.4% | Aug 8, 2022 |
39Monitor | CVE-2021-33027No exploit | Sylabs Singularity Enterprise through 1.6.2 has Insufficient Entropy in a nonce.sylabs · singularity · CWE-331 | Critical9.8 | — | 1.3% | Jul 19, 2021 |
39Monitor | CVE-2021-36320No exploit | Dell Networking X-Series firmware versions prior to 3.0.1.8 contain an authentication bypass vulnerability.dell · x1008p firmware · CWE-331 | Critical9.8 | — | 1.2% | Nov 19, 2021 |
39Monitor | CVE-2020-29508No exploit | Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Improper Inputdell · bsafe crypto-c-micro-edition · CWE-331 | Critical9.8 | — | 1.2% | Jul 11, 2022 |
39Monitor | CVE-2023-49599No exploit | An insufficient entropy vulnerability exists in the salt generation functionality of WWBN AVideo dev master commit 15fed957fb.wwbn · avideo · CWE-331 | Critical9.8 | — | 1.0% | Jan 10, 2024 |
39Monitor | CVE-2023-31176No exploit | Insufficient entropy vulnerability could lead to authentication bypassselinc · sel-451 firmware · CWE-331 | Critical9.8 | — | 0.9% | Nov 30, 2023 |
39Monitor | CVE-2024-25730No exploit | Hitron CODA-4582 and CODA-4589 devices have default PSKs that are generated from 5-digit hex values concatenated with a "Hitron" substring, hitrontech · coda-4582u firmware · CWE-331 | Critical9.8 | — | 0.9% | Feb 23, 2024 |
39Monitor | CVE-2024-36400No exploit | nano-id is unable to generate the correct character setviz · nano id · CWE-331 | Critical9.8 | — | 0.8% | Jun 4, 2024 |
39Monitor | CVE-2023-4344No exploit | Broadcom RAID Controller web interface is vulnerable to insufficient randomness due to improper use of ssl.rnd to setup CIM connectionbroadcom · raid controller web interface · CWE-331 | Critical9.8 | — | 0.7% | Aug 15, 2023 |
39Monitor | CVE-2026-38447No exploit | osTicket 1.18.3 generates API keys using a predictable construction based on MD5 hashing.CWE-331 | Critical9.8 | — | 0.7% | Aug 3, 2026 |
39Monitor | CVE-2026-13639No exploit | An insufficient entropy vulnerability in login logic in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009synology · diskstation manager (dsm) · CWE-331 | Critical9.8 | — | 0.7% | Sep 18, 2026 |
39Monitor | CVE-2025-47781No exploit | Rallly Insufficient Password Login Token Entropy Leads to Account Takeoverrallly · rallly · CWE-331 | Critical9.8 | — | 0.6% | May 14, 2025 |
39Monitor | CVE-2025-67504No exploit | WBCE CMS has Weak Random Number Generator in Password Generation Functionwbce · wbce cms · CWE-331 | Critical9.8 | — | 0.5% | Dec 9, 2025 |
39Monitor | CVE-2026-34236No exploit | Auth0 PHP SDK Insufficient Entropy in Cookie Encryptionauth0 · auth0-php · CWE-331 | Critical9.8 | — | 0.3% | Apr 1, 2026 |
- CVE-2008-144756Plan
The DNS protocol, as implemented in (1) BIND 8 and 9 before 9.5.0-P1, 9.4.2-P1, and 9.3.5-P1; (2) Microsoft DNS in Windows 2000 SP4, XP SP2
MediumCVSS 6.8WeaponizedEPSS 95%microsoft · windows 2000Jul 8, 2008
- CVE-2018-1832646Plan
DNN (aka DotNetNuke) 9.2 through 9.2.2 incorrectly converts encryption key source values, resulting in lower than expected entropy.
HighCVSS 7.5WeaponizedEPSS 54%dnnsoftware · dotnetnukeJul 3, 2019
- CVE-2018-1581244Plan
DNN (aka DotNetNuke) 9.2 through 9.2.1 incorrectly converts encryption key source values, resulting in lower than expected entropy.
HighCVSS 7.5WeaponizedEPSS 47%dnnsoftware · dotnetnukeJul 3, 2019
- CVE-2008-210840Plan
The GENERATE_SEED macro in PHP 4.x before 4.4.8 and 5.x before 5.2.5, when running on 64-bit systems, performs a multiplication that generat
CriticalCVSS 9.8No exploitEPSS 4%php · phpMay 7, 2008
- CVE-2013-226040Plan
Cryptocat before 2.0.22: Cryptocat.random() Function Array Key has Entropy Weakness
CriticalCVSS 9.8No exploitEPSS 2%cryptocat project · cryptocatNov 4, 2019
- CVE-2022-3429440Plan
totd 1.5.3 uses a fixed UDP source port in upstream queries sent to DNS resolvers.
CriticalCVSS 9.8No exploitEPSS 2%totd project · totdAug 15, 2022
- CVE-2022-4375540Plan
Rancher: Non-random authentication token
CriticalCVSS 9.8No exploitEPSS 2%suse · rancherFeb 7, 2023
- CVE-2020-1273540Plan
reset.php in DomainMOD 4.13.0 uses insufficient entropy for password reset requests, leading to account takeover.
CriticalCVSS 9.8No exploitEPSS 2%domainmod · domainmodMay 8, 2020
- CVE-2018-100062040Plan
Eran Hammer cryptiles version 4.1.1 earlier contains a CWE-331: Insufficient Entropy vulnerability in randomDigits() method that can result
CriticalCVSS 9.8No exploitEPSS 2%cryptiles project · cryptilesJul 9, 2018
- CVE-2021-3629439Monitor
Dell VNX2 OE for File versions 8.1.21.266 and earlier, contain an authentication bypass vulnerability.
CriticalCVSS 9.8No exploitEPSS 2%dell · emc unity operating environmentJan 25, 2022
- CVE-2021-2272739Monitor
A CWE-331: Insufficient Entropy vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking
CriticalCVSS 9.8No exploitEPSS 1%schneider-electric · evlink city evc1s22p4 firmwareJul 21, 2021
- CVE-2021-4161539Monitor
websda.c in GoAhead WebServer 2.1.8 has insufficient nonce entropy because the nonce calculation relies on the hardcoded onceuponatimeinpara
CriticalCVSS 9.8No exploitEPSS 1%embedthis · goaheadAug 8, 2022
- CVE-2021-3302739Monitor
Sylabs Singularity Enterprise through 1.6.2 has Insufficient Entropy in a nonce.
CriticalCVSS 9.8No exploitEPSS 1%sylabs · singularityJul 19, 2021
- CVE-2021-3632039Monitor
Dell Networking X-Series firmware versions prior to 3.0.1.8 contain an authentication bypass vulnerability.
CriticalCVSS 9.8No exploitEPSS 1%dell · x1008p firmwareNov 19, 2021
- CVE-2020-2950839Monitor
Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Improper Input
CriticalCVSS 9.8No exploitEPSS 1%dell · bsafe crypto-c-micro-editionJul 11, 2022
- CVE-2023-4959939Monitor
An insufficient entropy vulnerability exists in the salt generation functionality of WWBN AVideo dev master commit 15fed957fb.
CriticalCVSS 9.8No exploitEPSS 1%wwbn · avideoJan 10, 2024
- CVE-2023-3117639Monitor
Insufficient entropy vulnerability could lead to authentication bypass
CriticalCVSS 9.8No exploitEPSS 1%selinc · sel-451 firmwareNov 30, 2023
- CVE-2024-2573039Monitor
Hitron CODA-4582 and CODA-4589 devices have default PSKs that are generated from 5-digit hex values concatenated with a "Hitron" substring,
CriticalCVSS 9.8No exploitEPSS 1%hitrontech · coda-4582u firmwareFeb 23, 2024
- CVE-2024-3640039Monitor
nano-id is unable to generate the correct character set
CriticalCVSS 9.8No exploitEPSS 1%viz · nano idJun 4, 2024
- CVE-2023-434439Monitor
Broadcom RAID Controller web interface is vulnerable to insufficient randomness due to improper use of ssl.rnd to setup CIM connection
CriticalCVSS 9.8No exploitEPSS 1%broadcom · raid controller web interfaceAug 15, 2023
- CVE-2026-3844739Monitor
osTicket 1.18.3 generates API keys using a predictable construction based on MD5 hashing.
CriticalCVSS 9.8No exploitEPSS 1%Aug 3, 2026
- CVE-2026-1363939Monitor
An insufficient entropy vulnerability in login logic in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009
CriticalCVSS 9.8No exploitEPSS 1%synology · diskstation manager (dsm)Sep 18, 2026
- CVE-2025-4778139Monitor
Rallly Insufficient Password Login Token Entropy Leads to Account Takeover
CriticalCVSS 9.8No exploitEPSS 1%rallly · ralllyMay 14, 2025
- CVE-2025-6750439Monitor
WBCE CMS has Weak Random Number Generator in Password Generation Function
CriticalCVSS 9.8No exploitEPSS 1%wbce · wbce cmsDec 9, 2025
- CVE-2026-3423639Monitor
Auth0 PHP SDK Insufficient Entropy in Cookie Encryption
CriticalCVSS 9.8No exploitEPSS 0%auth0 · auth0-phpApr 1, 2026