Skip to content
Noroxi

CWE-341 · 14 records

Predictable from Observable State

CVEs in this class

14 records

  • Moxa IKS and EDS generate a predictable cookie calculated with an MD5 hash, allowing an attacker to capture the administrator's password, wh

    CriticalCVSS 9.8No exploitEPSS 2%

    moxa · iks-g6824a firmwareMar 5, 2019

  • CVE-2020-1731
    39Monitor

    A flaw was found in all versions of the Keycloak operator, before version 8.0.2,(community only) where the operator generates a random admin

    CriticalCVSS 9.8No exploitEPSS 1%

    redhat · keycloak operatorMar 2, 2020

  • ntopng through 6.6 is vulnerable to Predictable Session Identifier which can lead to Session Hijacking.

    CriticalCVSS 9.8No exploitEPSS 1%

    ntop · ntopngJul 2, 2026

  • Cache poisoning due to weak PRNG

    HighCVSS 8.6No exploitEPSS 0%

    isc · bind 9Oct 22, 2025

  • CVE-2020-5365
    30Monitor

    Dell EMC Isilon versions 8.2.2 and earlier contain a remotesupport vulnerability.

    HighCVSS 7.5No exploitEPSS 1%

    dell · emc isilon onefsMay 20, 2020

  • GeoVision LPC2011/LPC2211 Web Interface guessable session cookie vulnerability

    HighCVSS 7.5No exploitEPSS 1%

    geovision · gv-lpc2011 firmwareMay 3, 2026

  • Bruteforcing authentication cookie for a given user

    HighCVSS 7.5No exploitEPSS 0%

    hongdian · h8951-4g-esp firmwareJan 12, 2024

  • Keycloak-services: keycloak-services: predictable account-linking hash enables account takeover via malicious oidc client

    HighCVSS 7.3No exploitEPSS 0%

    red hat · red hat build of keycloak 26.6Aug 18, 2026

  • jsbroks COCO Annotator Session predictable state

    MediumCVSS 6.3No exploitEPSS 1%

    jsbroks · coco annotatorOct 19, 2024

  • All versions of Hangzhou Xiongmai Technology Co., Ltd XMeye P2P Cloud Server may allow an attacker to use MAC addresses to enumerate potenti

    MediumCVSS 5.3No exploitEPSS 1%

    xiongmaitech · xmeye p2p cloud serverOct 10, 2018

  • CVE-2021-4277
    21Monitor

    fredsmith utils Filename screenshot_sync predictable state

    MediumCVSS 5.3No exploitEPSS 0%

    utils project · utilsDec 25, 2022

  • Weak Session Cookie Entropy

    MediumCVSS 5.0Proof of conceptEPSS 0%

    advantech · wise-4060lan firmwareJun 23, 2025

  • Predictable Object Identifier vulnerability in SAP NetWeaver AS Java (IIOP Service)

    MediumCVSS 4.3No exploitEPSS 0%

    sap_se · sap netweaver as java (iiop service)Sep 8, 2025

  • Apache::AppSamurai::Util versions through 1.01 for Perl generate predictable session authentication keys from the clock and process id in CreateSessionAuthKey

    LowCVSS 3.7No exploitEPSS 0%

    Aug 23, 2026

All vulnerability classes