Skip to content
Noroxi

CWE-340 · 28 records

Generation of Predictable Numbers or Identifiers

CVEs in this class

28 records

  • Predictable Session ID

    CriticalCVSS 9.8No exploitEPSS 1%

    rittal · iot interface firmwareOct 15, 2024

  • OpnForm Editable Submission Secret Derivation via Empty Hashids Salt

    CriticalCVSS 9.3No exploitEPSS 0%

    opnform · opnformAug 17, 2026

  • CVE-2026-5081
    36Monitor

    Apache::Session::Generate::ModUniqueId versions from 1.54 through 1.94 for Perl session ids are insecure

    CriticalCVSS 9.1No exploitEPSS 0%

    chorny · apache\May 6, 2026

  • RAGFlow has Predictable Token Generation Leading to Authentication Bypass Vulnerability

    HighCVSS 8.9Proof of conceptEPSS 1%

    infiniflow · ragflowDec 31, 2025

  • Concrete CMS Community Store before 2.7.8 Predictable Digital Download Token

    HighCVSS 8.7No exploitEPSS 1%

    concretecms-community-store · community_storeSep 22, 2026

  • Predictable Generation of Password Recovery Token

    HighCVSS 8.7No exploitEPSS 0%

    soplanning · soplanningNov 20, 2025

  • CVE-2026-9219
    33Monitor

    Setracker2 Children's Smartwatch Ecosystem Generation of Predictable Numbers or Identifiers

    HighCVSS 8.3No exploitEPSS 0%

    shenzhen i365-tech co. ltd. · setracker2 parental control app (android) package com.tgelec.setrackerJun 25, 2026

  • BookingPress < 1.1.23 - Unauthenticated Export File Download

    HighCVSS 7.5No exploitEPSS 1%

    codepeople · appointment booking calendarJan 13, 2025

  • CVE-2024-6477
    30Monitor

    UsersWP < 1.2.12 - Users Information Disclosure

    HighCVSS 7.5No exploitEPSS 1%

    ayecode · userswpAug 3, 2024

  • The PDF viewer macro allows accessing any attachment without access right checks

    HighCVSS 7.5No exploitEPSS 1%

    xwiki · pdf viewer macroNov 13, 2024

  • CVE-2026-2473
    30Monitor

    Bucket Squatting in Vertex AI Experiments leads to RCE and Model Theft.

    HighCVSS 7.7No exploitEPSS 0%

    google cloud · vertex ai experimentsFeb 20, 2026

  • Botslab G980H Dashcams Generation of Predictable Numbers or Identifiers

    HighCVSS 7.7No exploitEPSS 0%

    botslab · g980hSep 24, 2026

  • CVE-2025-0218
    28Monitor

    pgAgent scheduled batch job scripts are created in a predictable temporary directory potentially allowing a denial of service

    HighCVSS 7.1No exploitEPSS 0%

    pgadmin · pgagentJan 7, 2025

  • Naxclow IoT Platform Generation of Predictable Numbers or Identifiers

    MediumCVSS 6.9No exploitEPSS 0%

    naxclow · smart doorbell x3Jun 12, 2026

  • Predictable DNS Transaction IDs Enable Cache Poisoning in Built-in Resolver

    MediumCVSS 6.3No exploitEPSS 0%

    erlang · erlang\/otpApr 7, 2026

  • Generation of Predictable Email Confirmation Token in ATutor

    MediumCVSS 6.3No exploitEPSS 0%

    atutor · atutorAug 20, 2026

  • Weaknesses in the generation of TCP/UDP source ports and some other header values in Google's gVisor allowed them to be predicted by an exte

    MediumCVSS 6.3No exploitEPSS 0%

    google · gvisorJan 30, 2025

  • BIG-IP TMM vulnerability

    MediumCVSS 6.3No exploitEPSS 0%

    f5 · big-ip access policy managerOct 15, 2025

  • Multiple Vulnerabilities in IBM Concert Software

    MediumCVSS 6.2No exploitEPSS 0%

    ibm · concertApr 6, 2026

  • The YoSmart YoLink API through 2025-10-02 uses an endpoint URL that is derived from a device's MAC address along with an MD5 hash of non-sec

    MediumCVSS 5.8No exploitEPSS 0%

    yosmart · yolink apiOct 6, 2025

  • Generation of predictable identifiers issue exists in Cente middleware TCP/IP Network Series.

    MediumCVSS 5.3No exploitEPSS 1%

    nxtech · cente ipv6Apr 15, 2024

  • predictable WebSocket mask

    MediumCVSS 5.3No exploitEPSS 0%

    haxx · curlSep 12, 2025

  • Weak File Name Generation in vsDesk

    MediumCVSS 5.3No exploitEPSS 0%

    vsdesk · vsdeskAug 20, 2026

  • Advanced Google reCAPTCHA <= 1.25 - Brute Force Protection IP Unblock

    MediumCVSS 5.3No exploitEPSS 0%

    webfactory · advanced google recaptchaDec 24, 2024

  • An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2.

    MediumCVSS 4.0No exploitEPSS 0%

    cyrusimap · cyrus imapJul 16, 2026

All vulnerability classes