CWE-341 · 14 records
Predictable from Observable State
CVEs in this class
14 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2019-6563No exploit | Moxa IKS and EDS generate a predictable cookie calculated with an MD5 hash, allowing an attacker to capture the administrator's password, whmoxa · iks-g6824a firmware · CWE-341 | Critical9.8 | — | 1.7% | Mar 5, 2019 |
39Monitor | CVE-2020-1731No exploit | A flaw was found in all versions of the Keycloak operator, before version 8.0.2,(community only) where the operator generates a random adminredhat · keycloak operator · CWE-341 | Critical9.8 | — | 1.3% | Mar 2, 2020 |
39Monitor | CVE-2026-38968No exploit | ntopng through 6.6 is vulnerable to Predictable Session Identifier which can lead to Session Hijacking.ntop · ntopng · CWE-341 | Critical9.8 | — | 0.6% | Jul 2, 2026 |
34Monitor | CVE-2025-40780No exploit | Cache poisoning due to weak PRNGisc · bind 9 · CWE-341 | High8.6 | — | 0.5% | Oct 22, 2025 |
30Monitor | CVE-2020-5365No exploit | Dell EMC Isilon versions 8.2.2 and earlier contain a remotesupport vulnerability.dell · emc isilon onefs · CWE-341 | High7.5 | — | 1.0% | May 20, 2020 |
30Monitor | CVE-2026-42365No exploit | GeoVision LPC2011/LPC2211 Web Interface guessable session cookie vulnerabilitygeovision · gv-lpc2011 firmware · CWE-341 | High7.5 | — | 0.6% | May 3, 2026 |
30Monitor | CVE-2023-49259No exploit | Bruteforcing authentication cookie for a given userhongdian · h8951-4g-esp firmware · CWE-341 | High7.5 | — | 0.3% | Jan 12, 2024 |
29Monitor | CVE-2026-15571No exploit | Keycloak-services: keycloak-services: predictable account-linking hash enables account takeover via malicious oidc clientred hat · red hat build of keycloak 26.6 · CWE-341 | High7.3 | — | 0.4% | Aug 18, 2026 |
25Monitor | CVE-2024-10141No exploit | jsbroks COCO Annotator Session predictable statejsbroks · coco annotator · CWE-341 | Medium6.3 | — | 0.8% | Oct 19, 2024 |
21Monitor | CVE-2018-17917No exploit | All versions of Hangzhou Xiongmai Technology Co., Ltd XMeye P2P Cloud Server may allow an attacker to use MAC addresses to enumerate potentixiongmaitech · xmeye p2p cloud server · CWE-341 | Medium5.3 | — | 1.3% | Oct 10, 2018 |
21Monitor | CVE-2021-4277No exploit | fredsmith utils Filename screenshot_sync predictable stateutils project · utils · CWE-341 | Medium5.3 | — | 0.5% | Dec 25, 2022 |
20Monitor | CVE-2025-48461Proof of concept | Weak Session Cookie Entropyadvantech · wise-4060lan firmware · CWE-341 | Medium5.0 | — | 0.5% | Jun 23, 2025 |
17Monitor | CVE-2025-42925No exploit | Predictable Object Identifier vulnerability in SAP NetWeaver AS Java (IIOP Service)sap_se · sap netweaver as java (iiop service) · CWE-341 | Medium4.3 | — | 0.2% | Sep 8, 2025 |
14Monitor | CVE-2026-19565No exploit | Apache::AppSamurai::Util versions through 1.01 for Perl generate predictable session authentication keys from the clock and process id in CreateSessionAuthKeyCWE-341 | Low3.7 | — | 0.4% | Aug 23, 2026 |
- CVE-2019-656340Plan
Moxa IKS and EDS generate a predictable cookie calculated with an MD5 hash, allowing an attacker to capture the administrator's password, wh
CriticalCVSS 9.8No exploitEPSS 2%moxa · iks-g6824a firmwareMar 5, 2019
- CVE-2020-173139Monitor
A flaw was found in all versions of the Keycloak operator, before version 8.0.2,(community only) where the operator generates a random admin
CriticalCVSS 9.8No exploitEPSS 1%redhat · keycloak operatorMar 2, 2020
- CVE-2026-3896839Monitor
ntopng through 6.6 is vulnerable to Predictable Session Identifier which can lead to Session Hijacking.
CriticalCVSS 9.8No exploitEPSS 1%ntop · ntopngJul 2, 2026
- CVE-2025-4078034Monitor
Cache poisoning due to weak PRNG
HighCVSS 8.6No exploitEPSS 0%isc · bind 9Oct 22, 2025
- CVE-2020-536530Monitor
Dell EMC Isilon versions 8.2.2 and earlier contain a remotesupport vulnerability.
HighCVSS 7.5No exploitEPSS 1%dell · emc isilon onefsMay 20, 2020
- CVE-2026-4236530Monitor
GeoVision LPC2011/LPC2211 Web Interface guessable session cookie vulnerability
HighCVSS 7.5No exploitEPSS 1%geovision · gv-lpc2011 firmwareMay 3, 2026
- CVE-2023-4925930Monitor
Bruteforcing authentication cookie for a given user
HighCVSS 7.5No exploitEPSS 0%hongdian · h8951-4g-esp firmwareJan 12, 2024
- CVE-2026-1557129Monitor
Keycloak-services: keycloak-services: predictable account-linking hash enables account takeover via malicious oidc client
HighCVSS 7.3No exploitEPSS 0%red hat · red hat build of keycloak 26.6Aug 18, 2026
- CVE-2024-1014125Monitor
jsbroks COCO Annotator Session predictable state
MediumCVSS 6.3No exploitEPSS 1%jsbroks · coco annotatorOct 19, 2024
- CVE-2018-1791721Monitor
All versions of Hangzhou Xiongmai Technology Co., Ltd XMeye P2P Cloud Server may allow an attacker to use MAC addresses to enumerate potenti
MediumCVSS 5.3No exploitEPSS 1%xiongmaitech · xmeye p2p cloud serverOct 10, 2018
- CVE-2021-427721Monitor
fredsmith utils Filename screenshot_sync predictable state
MediumCVSS 5.3No exploitEPSS 0%utils project · utilsDec 25, 2022
- CVE-2025-4846120Monitor
Weak Session Cookie Entropy
MediumCVSS 5.0Proof of conceptEPSS 0%advantech · wise-4060lan firmwareJun 23, 2025
- CVE-2025-4292517Monitor
Predictable Object Identifier vulnerability in SAP NetWeaver AS Java (IIOP Service)
MediumCVSS 4.3No exploitEPSS 0%sap_se · sap netweaver as java (iiop service)Sep 8, 2025
- CVE-2026-1956514Monitor
Apache::AppSamurai::Util versions through 1.01 for Perl generate predictable session authentication keys from the clock and process id in CreateSessionAuthKey
LowCVSS 3.7No exploitEPSS 0%Aug 23, 2026