CWE-341 · 14 записей
Predictable from Observable State
CVE этого класса
14 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2019-6563Эксплойта нет | Moxa IKS and EDS generate a predictable cookie calculated with an MD5 hash, allowing an attacker to capture the administrator's password, whmoxa · iks-g6824a firmware · CWE-341 | Критическая9,8 | — | 1,7 % | 5 мар. 2019 г. |
39Наблюдать | CVE-2020-1731Эксплойта нет | A flaw was found in all versions of the Keycloak operator, before version 8.0.2,(community only) where the operator generates a random adminredhat · keycloak operator · CWE-341 | Критическая9,8 | — | 1,3 % | 2 мар. 2020 г. |
39Наблюдать | CVE-2026-38968Эксплойта нет | ntopng through 6.6 is vulnerable to Predictable Session Identifier which can lead to Session Hijacking.ntop · ntopng · CWE-341 | Критическая9,8 | — | 0,6 % | 2 июл. 2026 г. |
34Наблюдать | CVE-2025-40780Эксплойта нет | Cache poisoning due to weak PRNGisc · bind 9 · CWE-341 | Высокая8,6 | — | 0,5 % | 22 окт. 2025 г. |
30Наблюдать | CVE-2020-5365Эксплойта нет | Dell EMC Isilon versions 8.2.2 and earlier contain a remotesupport vulnerability.dell · emc isilon onefs · CWE-341 | Высокая7,5 | — | 1,0 % | 20 мая 2020 г. |
30Наблюдать | CVE-2026-42365Эксплойта нет | GeoVision LPC2011/LPC2211 Web Interface guessable session cookie vulnerabilitygeovision · gv-lpc2011 firmware · CWE-341 | Высокая7,5 | — | 0,6 % | 3 мая 2026 г. |
30Наблюдать | CVE-2023-49259Эксплойта нет | Bruteforcing authentication cookie for a given userhongdian · h8951-4g-esp firmware · CWE-341 | Высокая7,5 | — | 0,3 % | 12 янв. 2024 г. |
29Наблюдать | CVE-2026-15571Эксплойта нет | Keycloak-services: keycloak-services: predictable account-linking hash enables account takeover via malicious oidc clientred hat · red hat build of keycloak 26.6 · CWE-341 | Высокая7,3 | — | 0,4 % | 18 авг. 2026 г. |
25Наблюдать | CVE-2024-10141Эксплойта нет | jsbroks COCO Annotator Session predictable statejsbroks · coco annotator · CWE-341 | Средняя6,3 | — | 0,8 % | 19 окт. 2024 г. |
21Наблюдать | CVE-2018-17917Эксплойта нет | All versions of Hangzhou Xiongmai Technology Co., Ltd XMeye P2P Cloud Server may allow an attacker to use MAC addresses to enumerate potentixiongmaitech · xmeye p2p cloud server · CWE-341 | Средняя5,3 | — | 1,3 % | 10 окт. 2018 г. |
21Наблюдать | CVE-2021-4277Эксплойта нет | fredsmith utils Filename screenshot_sync predictable stateutils project · utils · CWE-341 | Средняя5,3 | — | 0,5 % | 25 дек. 2022 г. |
20Наблюдать | CVE-2025-48461Proof of concept | Weak Session Cookie Entropyadvantech · wise-4060lan firmware · CWE-341 | Средняя5,0 | — | 0,5 % | 23 июн. 2025 г. |
17Наблюдать | CVE-2025-42925Эксплойта нет | Predictable Object Identifier vulnerability in SAP NetWeaver AS Java (IIOP Service)sap_se · sap netweaver as java (iiop service) · CWE-341 | Средняя4,3 | — | 0,2 % | 8 сент. 2025 г. |
14Наблюдать | CVE-2026-19565Эксплойта нет | Apache::AppSamurai::Util versions through 1.01 for Perl generate predictable session authentication keys from the clock and process id in CreateSessionAuthKeyCWE-341 | Низкая3,7 | — | 0,4 % | 23 авг. 2026 г. |
- CVE-2019-656340В плане
Moxa IKS and EDS generate a predictable cookie calculated with an MD5 hash, allowing an attacker to capture the administrator's password, wh
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %moxa · iks-g6824a firmware5 мар. 2019 г.
- CVE-2020-173139Наблюдать
A flaw was found in all versions of the Keycloak operator, before version 8.0.2,(community only) where the operator generates a random admin
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %redhat · keycloak operator2 мар. 2020 г.
- CVE-2026-3896839Наблюдать
ntopng through 6.6 is vulnerable to Predictable Session Identifier which can lead to Session Hijacking.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %ntop · ntopng2 июл. 2026 г.
- CVE-2025-4078034Наблюдать
Cache poisoning due to weak PRNG
ВысокаяCVSS 8,6Эксплойта нетEPSS 0 %isc · bind 922 окт. 2025 г.
- CVE-2020-536530Наблюдать
Dell EMC Isilon versions 8.2.2 and earlier contain a remotesupport vulnerability.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %dell · emc isilon onefs20 мая 2020 г.
- CVE-2026-4236530Наблюдать
GeoVision LPC2011/LPC2211 Web Interface guessable session cookie vulnerability
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %geovision · gv-lpc2011 firmware3 мая 2026 г.
- CVE-2023-4925930Наблюдать
Bruteforcing authentication cookie for a given user
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %hongdian · h8951-4g-esp firmware12 янв. 2024 г.
- CVE-2026-1557129Наблюдать
Keycloak-services: keycloak-services: predictable account-linking hash enables account takeover via malicious oidc client
ВысокаяCVSS 7,3Эксплойта нетEPSS 0 %red hat · red hat build of keycloak 26.618 авг. 2026 г.
- CVE-2024-1014125Наблюдать
jsbroks COCO Annotator Session predictable state
СредняяCVSS 6,3Эксплойта нетEPSS 1 %jsbroks · coco annotator19 окт. 2024 г.
- CVE-2018-1791721Наблюдать
All versions of Hangzhou Xiongmai Technology Co., Ltd XMeye P2P Cloud Server may allow an attacker to use MAC addresses to enumerate potenti
СредняяCVSS 5,3Эксплойта нетEPSS 1 %xiongmaitech · xmeye p2p cloud server10 окт. 2018 г.
- CVE-2021-427721Наблюдать
fredsmith utils Filename screenshot_sync predictable state
СредняяCVSS 5,3Эксплойта нетEPSS 0 %utils project · utils25 дек. 2022 г.
- CVE-2025-4846120Наблюдать
Weak Session Cookie Entropy
СредняяCVSS 5,0Proof of conceptEPSS 0 %advantech · wise-4060lan firmware23 июн. 2025 г.
- CVE-2025-4292517Наблюдать
Predictable Object Identifier vulnerability in SAP NetWeaver AS Java (IIOP Service)
СредняяCVSS 4,3Эксплойта нетEPSS 0 %sap_se · sap netweaver as java (iiop service)8 сент. 2025 г.
- CVE-2026-1956514Наблюдать
Apache::AppSamurai::Util versions through 1.01 for Perl generate predictable session authentication keys from the clock and process id in CreateSessionAuthKey
НизкаяCVSS 3,7Эксплойта нетEPSS 0 %23 авг. 2026 г.