Перейти к содержимому
Noroxi

CWE-341 · 14 записей

Predictable from Observable State

CVE этого класса

14 записей

  • CVE-2019-6563
    40В плане

    Moxa IKS and EDS generate a predictable cookie calculated with an MD5 hash, allowing an attacker to capture the administrator's password, wh

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    moxa · iks-g6824a firmware5 мар. 2019 г.

  • CVE-2020-1731
    39Наблюдать

    A flaw was found in all versions of the Keycloak operator, before version 8.0.2,(community only) where the operator generates a random admin

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    redhat · keycloak operator2 мар. 2020 г.

  • CVE-2026-38968
    39Наблюдать

    ntopng through 6.6 is vulnerable to Predictable Session Identifier which can lead to Session Hijacking.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    ntop · ntopng2 июл. 2026 г.

  • CVE-2025-40780
    34Наблюдать

    Cache poisoning due to weak PRNG

    ВысокаяCVSS 8,6Эксплойта нетEPSS 0 %

    isc · bind 922 окт. 2025 г.

  • CVE-2020-5365
    30Наблюдать

    Dell EMC Isilon versions 8.2.2 and earlier contain a remotesupport vulnerability.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    dell · emc isilon onefs20 мая 2020 г.

  • CVE-2026-42365
    30Наблюдать

    GeoVision LPC2011/LPC2211 Web Interface guessable session cookie vulnerability

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    geovision · gv-lpc2011 firmware3 мая 2026 г.

  • CVE-2023-49259
    30Наблюдать

    Bruteforcing authentication cookie for a given user

    ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %

    hongdian · h8951-4g-esp firmware12 янв. 2024 г.

  • CVE-2026-15571
    29Наблюдать

    Keycloak-services: keycloak-services: predictable account-linking hash enables account takeover via malicious oidc client

    ВысокаяCVSS 7,3Эксплойта нетEPSS 0 %

    red hat · red hat build of keycloak 26.618 авг. 2026 г.

  • CVE-2024-10141
    25Наблюдать

    jsbroks COCO Annotator Session predictable state

    СредняяCVSS 6,3Эксплойта нетEPSS 1 %

    jsbroks · coco annotator19 окт. 2024 г.

  • CVE-2018-17917
    21Наблюдать

    All versions of Hangzhou Xiongmai Technology Co., Ltd XMeye P2P Cloud Server may allow an attacker to use MAC addresses to enumerate potenti

    СредняяCVSS 5,3Эксплойта нетEPSS 1 %

    xiongmaitech · xmeye p2p cloud server10 окт. 2018 г.

  • CVE-2021-4277
    21Наблюдать

    fredsmith utils Filename screenshot_sync predictable state

    СредняяCVSS 5,3Эксплойта нетEPSS 0 %

    utils project · utils25 дек. 2022 г.

  • CVE-2025-48461
    20Наблюдать

    Weak Session Cookie Entropy

    СредняяCVSS 5,0Proof of conceptEPSS 0 %

    advantech · wise-4060lan firmware23 июн. 2025 г.

  • CVE-2025-42925
    17Наблюдать

    Predictable Object Identifier vulnerability in SAP NetWeaver AS Java (IIOP Service)

    СредняяCVSS 4,3Эксплойта нетEPSS 0 %

    sap_se · sap netweaver as java (iiop service)8 сент. 2025 г.

  • CVE-2026-19565
    14Наблюдать

    Apache::AppSamurai::Util versions through 1.01 for Perl generate predictable session authentication keys from the clock and process id in CreateSessionAuthKey

    НизкаяCVSS 3,7Эксплойта нетEPSS 0 %

    23 авг. 2026 г.

Все классы уязвимостей