CWE-340 · 28 records
Generation of Predictable Numbers or Identifiers
CVEs in this class
28 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2024-47945No exploit | Predictable Session IDrittal · iot interface firmware · CWE-340 | Critical9.8 | — | 0.9% | Oct 15, 2024 |
37Monitor | CVE-2026-75106No exploit | OpnForm Editable Submission Secret Derivation via Empty Hashids Saltopnform · opnform · CWE-340 | Critical9.3 | — | 0.4% | Aug 17, 2026 |
36Monitor | CVE-2026-5081No exploit | Apache::Session::Generate::ModUniqueId versions from 1.54 through 1.94 for Perl session ids are insecurechorny · apache\ · CWE-340 | Critical9.1 | — | 0.5% | May 6, 2026 |
35Monitor | CVE-2025-69286Proof of concept | RAGFlow has Predictable Token Generation Leading to Authentication Bypass Vulnerabilityinfiniflow · ragflow · CWE-340 | High8.9 | — | 0.8% | Dec 31, 2025 |
34Monitor | CVE-2026-95653No exploit | Concrete CMS Community Store before 2.7.8 Predictable Digital Download Tokenconcretecms-community-store · community_store · CWE-340 | High8.7 | — | 0.6% | Sep 22, 2026 |
34Monitor | CVE-2025-62294No exploit | Predictable Generation of Password Recovery Tokensoplanning · soplanning · CWE-340 | High8.7 | — | 0.3% | Nov 20, 2025 |
33Monitor | CVE-2026-9219No exploit | Setracker2 Children's Smartwatch Ecosystem Generation of Predictable Numbers or Identifiersshenzhen i365-tech co. ltd. · setracker2 parental control app (android) package com.tgelec.setracker · CWE-340 | High8.3 | — | 0.3% | Jun 25, 2026 |
30Monitor | CVE-2024-12274No exploit | BookingPress < 1.1.23 - Unauthenticated Export File Downloadcodepeople · appointment booking calendar · CWE-340 | High7.5 | — | 0.6% | Jan 13, 2025 |
30Monitor | CVE-2024-6477No exploit | UsersWP < 1.2.12 - Users Information Disclosureayecode · userswp · CWE-340 | High7.5 | — | 0.6% | Aug 3, 2024 |
30Monitor | CVE-2024-52299No exploit | The PDF viewer macro allows accessing any attachment without access right checksxwiki · pdf viewer macro · CWE-340 | High7.5 | — | 0.5% | Nov 13, 2024 |
30Monitor | CVE-2026-2473No exploit | Bucket Squatting in Vertex AI Experiments leads to RCE and Model Theft.google cloud · vertex ai experiments · CWE-340 | High7.7 | — | 0.5% | Feb 20, 2026 |
30Monitor | CVE-2026-85496No exploit | Botslab G980H Dashcams Generation of Predictable Numbers or Identifiersbotslab · g980h · CWE-340 | High7.7 | — | 0.3% | Sep 24, 2026 |
28Monitor | CVE-2025-0218No exploit | pgAgent scheduled batch job scripts are created in a predictable temporary directory potentially allowing a denial of servicepgadmin · pgagent · CWE-340 | High7.1 | — | 0.2% | Jan 7, 2025 |
27Monitor | CVE-2026-42932No exploit | Naxclow IoT Platform Generation of Predictable Numbers or Identifiersnaxclow · smart doorbell x3 · CWE-340 | Medium6.9 | — | 0.3% | Jun 12, 2026 |
25Monitor | CVE-2026-28810No exploit | Predictable DNS Transaction IDs Enable Cache Poisoning in Built-in Resolvererlang · erlang\/otp · CWE-340 | Medium6.3 | — | 0.4% | Apr 7, 2026 |
25Monitor | CVE-2026-64964No exploit | Generation of Predictable Email Confirmation Token in ATutoratutor · atutor · CWE-340 | Medium6.3 | — | 0.4% | Aug 20, 2026 |
25Monitor | CVE-2024-10603No exploit | Weaknesses in the generation of TCP/UDP source ports and some other header values in Google's gVisor allowed them to be predicted by an extegoogle · gvisor · CWE-340 | Medium6.3 | — | 0.3% | Jan 30, 2025 |
25Monitor | CVE-2025-58424No exploit | BIG-IP TMM vulnerabilityf5 · big-ip access policy manager · CWE-340 | Medium6.3 | — | 0.2% | Oct 15, 2025 |
24Monitor | CVE-2025-13044No exploit | Multiple Vulnerabilities in IBM Concert Softwareibm · concert · CWE-340 | Medium6.2 | — | 0.1% | Apr 6, 2026 |
23Monitor | CVE-2025-59452No exploit | The YoSmart YoLink API through 2025-10-02 uses an endpoint URL that is derived from a device's MAC address along with an MD5 hash of non-secyosmart · yolink api · CWE-340 | Medium5.8 | — | 0.4% | Oct 6, 2025 |
21Monitor | CVE-2024-28957No exploit | Generation of predictable identifiers issue exists in Cente middleware TCP/IP Network Series.nxtech · cente ipv6 · CWE-340 | Medium5.3 | — | 0.8% | Apr 15, 2024 |
21Monitor | CVE-2025-10148No exploit | predictable WebSocket maskhaxx · curl · CWE-340 | Medium5.3 | — | 0.5% | Sep 12, 2025 |
21Monitor | CVE-2025-14602No exploit | Weak File Name Generation in vsDeskvsdesk · vsdesk · CWE-340 | Medium5.3 | — | 0.5% | Aug 20, 2026 |
21Monitor | CVE-2024-12034No exploit | Advanced Google reCAPTCHA <= 1.25 - Brute Force Protection IP Unblockwebfactory · advanced google recaptcha · CWE-340 | Medium5.3 | — | 0.3% | Dec 24, 2024 |
16Monitor | CVE-2026-47085No exploit | An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2.cyrusimap · cyrus imap · CWE-340 | Medium4.0 | — | 0.3% | Jul 16, 2026 |
- CVE-2024-4794539Monitor
Predictable Session ID
CriticalCVSS 9.8No exploitEPSS 1%rittal · iot interface firmwareOct 15, 2024
- CVE-2026-7510637Monitor
OpnForm Editable Submission Secret Derivation via Empty Hashids Salt
CriticalCVSS 9.3No exploitEPSS 0%opnform · opnformAug 17, 2026
- CVE-2026-508136Monitor
Apache::Session::Generate::ModUniqueId versions from 1.54 through 1.94 for Perl session ids are insecure
CriticalCVSS 9.1No exploitEPSS 0%chorny · apache\May 6, 2026
- CVE-2025-6928635Monitor
RAGFlow has Predictable Token Generation Leading to Authentication Bypass Vulnerability
HighCVSS 8.9Proof of conceptEPSS 1%infiniflow · ragflowDec 31, 2025
- CVE-2026-9565334Monitor
Concrete CMS Community Store before 2.7.8 Predictable Digital Download Token
HighCVSS 8.7No exploitEPSS 1%concretecms-community-store · community_storeSep 22, 2026
- CVE-2025-6229434Monitor
Predictable Generation of Password Recovery Token
HighCVSS 8.7No exploitEPSS 0%soplanning · soplanningNov 20, 2025
- CVE-2026-921933Monitor
Setracker2 Children's Smartwatch Ecosystem Generation of Predictable Numbers or Identifiers
HighCVSS 8.3No exploitEPSS 0%shenzhen i365-tech co. ltd. · setracker2 parental control app (android) package com.tgelec.setrackerJun 25, 2026
- CVE-2024-1227430Monitor
BookingPress < 1.1.23 - Unauthenticated Export File Download
HighCVSS 7.5No exploitEPSS 1%codepeople · appointment booking calendarJan 13, 2025
- CVE-2024-647730Monitor
UsersWP < 1.2.12 - Users Information Disclosure
HighCVSS 7.5No exploitEPSS 1%ayecode · userswpAug 3, 2024
- CVE-2024-5229930Monitor
The PDF viewer macro allows accessing any attachment without access right checks
HighCVSS 7.5No exploitEPSS 1%xwiki · pdf viewer macroNov 13, 2024
- CVE-2026-247330Monitor
Bucket Squatting in Vertex AI Experiments leads to RCE and Model Theft.
HighCVSS 7.7No exploitEPSS 0%google cloud · vertex ai experimentsFeb 20, 2026
- CVE-2026-8549630Monitor
Botslab G980H Dashcams Generation of Predictable Numbers or Identifiers
HighCVSS 7.7No exploitEPSS 0%botslab · g980hSep 24, 2026
- CVE-2025-021828Monitor
pgAgent scheduled batch job scripts are created in a predictable temporary directory potentially allowing a denial of service
HighCVSS 7.1No exploitEPSS 0%pgadmin · pgagentJan 7, 2025
- CVE-2026-4293227Monitor
Naxclow IoT Platform Generation of Predictable Numbers or Identifiers
MediumCVSS 6.9No exploitEPSS 0%naxclow · smart doorbell x3Jun 12, 2026
- CVE-2026-2881025Monitor
Predictable DNS Transaction IDs Enable Cache Poisoning in Built-in Resolver
MediumCVSS 6.3No exploitEPSS 0%erlang · erlang\/otpApr 7, 2026
- CVE-2026-6496425Monitor
Generation of Predictable Email Confirmation Token in ATutor
MediumCVSS 6.3No exploitEPSS 0%atutor · atutorAug 20, 2026
- CVE-2024-1060325Monitor
Weaknesses in the generation of TCP/UDP source ports and some other header values in Google's gVisor allowed them to be predicted by an exte
MediumCVSS 6.3No exploitEPSS 0%google · gvisorJan 30, 2025
- CVE-2025-5842425Monitor
BIG-IP TMM vulnerability
MediumCVSS 6.3No exploitEPSS 0%f5 · big-ip access policy managerOct 15, 2025
- CVE-2025-1304424Monitor
Multiple Vulnerabilities in IBM Concert Software
MediumCVSS 6.2No exploitEPSS 0%ibm · concertApr 6, 2026
- CVE-2025-5945223Monitor
The YoSmart YoLink API through 2025-10-02 uses an endpoint URL that is derived from a device's MAC address along with an MD5 hash of non-sec
MediumCVSS 5.8No exploitEPSS 0%yosmart · yolink apiOct 6, 2025
- CVE-2024-2895721Monitor
Generation of predictable identifiers issue exists in Cente middleware TCP/IP Network Series.
MediumCVSS 5.3No exploitEPSS 1%nxtech · cente ipv6Apr 15, 2024
- CVE-2025-1014821Monitor
predictable WebSocket mask
MediumCVSS 5.3No exploitEPSS 0%haxx · curlSep 12, 2025
- CVE-2025-1460221Monitor
Weak File Name Generation in vsDesk
MediumCVSS 5.3No exploitEPSS 0%vsdesk · vsdeskAug 20, 2026
- CVE-2024-1203421Monitor
Advanced Google reCAPTCHA <= 1.25 - Brute Force Protection IP Unblock
MediumCVSS 5.3No exploitEPSS 0%webfactory · advanced google recaptchaDec 24, 2024
- CVE-2026-4708516Monitor
An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2.
MediumCVSS 4.0No exploitEPSS 0%cyrusimap · cyrus imapJul 16, 2026