Перейти к содержимому
Noroxi

CWE-340 · 28 записей

Generation of Predictable Numbers or Identifiers

CVE этого класса

28 записей

  • CVE-2024-47945
    39Наблюдать

    Predictable Session ID

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    rittal · iot interface firmware15 окт. 2024 г.

  • CVE-2026-75106
    37Наблюдать

    OpnForm Editable Submission Secret Derivation via Empty Hashids Salt

    КритическаяCVSS 9,3Эксплойта нетEPSS 0 %

    opnform · opnform17 авг. 2026 г.

  • CVE-2026-5081
    36Наблюдать

    Apache::Session::Generate::ModUniqueId versions from 1.54 through 1.94 for Perl session ids are insecure

    КритическаяCVSS 9,1Эксплойта нетEPSS 0 %

    chorny · apache\6 мая 2026 г.

  • CVE-2025-69286
    35Наблюдать

    RAGFlow has Predictable Token Generation Leading to Authentication Bypass Vulnerability

    ВысокаяCVSS 8,9Proof of conceptEPSS 1 %

    infiniflow · ragflow31 дек. 2025 г.

  • CVE-2026-95653
    34Наблюдать

    Concrete CMS Community Store before 2.7.8 Predictable Digital Download Token

    ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %

    concretecms-community-store · community_store22 сент. 2026 г.

  • CVE-2025-62294
    34Наблюдать

    Predictable Generation of Password Recovery Token

    ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %

    soplanning · soplanning20 нояб. 2025 г.

  • CVE-2026-9219
    33Наблюдать

    Setracker2 Children's Smartwatch Ecosystem Generation of Predictable Numbers or Identifiers

    ВысокаяCVSS 8,3Эксплойта нетEPSS 0 %

    shenzhen i365-tech co. ltd. · setracker2 parental control app (android) package com.tgelec.setracker25 июн. 2026 г.

  • CVE-2024-12274
    30Наблюдать

    BookingPress < 1.1.23 - Unauthenticated Export File Download

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    codepeople · appointment booking calendar13 янв. 2025 г.

  • CVE-2024-6477
    30Наблюдать

    UsersWP < 1.2.12 - Users Information Disclosure

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    ayecode · userswp3 авг. 2024 г.

  • CVE-2024-52299
    30Наблюдать

    The PDF viewer macro allows accessing any attachment without access right checks

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    xwiki · pdf viewer macro13 нояб. 2024 г.

  • CVE-2026-2473
    30Наблюдать

    Bucket Squatting in Vertex AI Experiments leads to RCE and Model Theft.

    ВысокаяCVSS 7,7Эксплойта нетEPSS 0 %

    google cloud · vertex ai experiments20 февр. 2026 г.

  • CVE-2026-85496
    30Наблюдать

    Botslab G980H Dashcams Generation of Predictable Numbers or Identifiers

    ВысокаяCVSS 7,7Эксплойта нетEPSS 0 %

    botslab · g980h6 дней назад

  • CVE-2025-0218
    28Наблюдать

    pgAgent scheduled batch job scripts are created in a predictable temporary directory potentially allowing a denial of service

    ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %

    pgadmin · pgagent7 янв. 2025 г.

  • CVE-2026-42932
    27Наблюдать

    Naxclow IoT Platform Generation of Predictable Numbers or Identifiers

    СредняяCVSS 6,9Эксплойта нетEPSS 0 %

    naxclow · smart doorbell x312 июн. 2026 г.

  • CVE-2026-28810
    25Наблюдать

    Predictable DNS Transaction IDs Enable Cache Poisoning in Built-in Resolver

    СредняяCVSS 6,3Эксплойта нетEPSS 0 %

    erlang · erlang\/otp7 апр. 2026 г.

  • CVE-2026-64964
    25Наблюдать

    Generation of Predictable Email Confirmation Token in ATutor

    СредняяCVSS 6,3Эксплойта нетEPSS 0 %

    atutor · atutor20 авг. 2026 г.

  • CVE-2024-10603
    25Наблюдать

    Weaknesses in the generation of TCP/UDP source ports and some other header values in Google's gVisor allowed them to be predicted by an exte

    СредняяCVSS 6,3Эксплойта нетEPSS 0 %

    google · gvisor30 янв. 2025 г.

  • CVE-2025-58424
    25Наблюдать

    BIG-IP TMM vulnerability

    СредняяCVSS 6,3Эксплойта нетEPSS 0 %

    f5 · big-ip access policy manager15 окт. 2025 г.

  • CVE-2025-13044
    24Наблюдать

    Multiple Vulnerabilities in IBM Concert Software

    СредняяCVSS 6,2Эксплойта нетEPSS 0 %

    ibm · concert6 апр. 2026 г.

  • CVE-2025-59452
    23Наблюдать

    The YoSmart YoLink API through 2025-10-02 uses an endpoint URL that is derived from a device's MAC address along with an MD5 hash of non-sec

    СредняяCVSS 5,8Эксплойта нетEPSS 0 %

    yosmart · yolink api6 окт. 2025 г.

  • CVE-2024-28957
    21Наблюдать

    Generation of predictable identifiers issue exists in Cente middleware TCP/IP Network Series.

    СредняяCVSS 5,3Эксплойта нетEPSS 1 %

    nxtech · cente ipv615 апр. 2024 г.

  • CVE-2025-10148
    21Наблюдать

    predictable WebSocket mask

    СредняяCVSS 5,3Эксплойта нетEPSS 0 %

    haxx · curl12 сент. 2025 г.

  • CVE-2025-14602
    21Наблюдать

    Weak File Name Generation in vsDesk

    СредняяCVSS 5,3Эксплойта нетEPSS 0 %

    vsdesk · vsdesk20 авг. 2026 г.

  • CVE-2024-12034
    21Наблюдать

    Advanced Google reCAPTCHA <= 1.25 - Brute Force Protection IP Unblock

    СредняяCVSS 5,3Эксплойта нетEPSS 0 %

    webfactory · advanced google recaptcha24 дек. 2024 г.

  • CVE-2026-47085
    16Наблюдать

    An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2.

    СредняяCVSS 4,0Эксплойта нетEPSS 0 %

    cyrusimap · cyrus imap16 июл. 2026 г.

Все классы уязвимостей