CWE-331 · 138 kayıt
Insufficient Entropy
Bu sınıftaki CVE’ler
138 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
56Planlayın | CVE-2008-1447Silahlaştırılmış | The DNS protocol, as implemented in (1) BIND 8 and 9 before 9.5.0-P1, 9.4.2-P1, and 9.3.5-P1; (2) Microsoft DNS in Windows 2000 SP4, XP SP2 microsoft · windows 2000 · CWE-331 | Orta6,8 | — | %95,2 | 8 Tem 2008 |
46Planlayın | CVE-2018-18326Silahlaştırılmış | DNN (aka DotNetNuke) 9.2 through 9.2.2 incorrectly converts encryption key source values, resulting in lower than expected entropy.dnnsoftware · dotnetnuke · CWE-331 | Yüksek7,5 | — | %54,3 | 3 Tem 2019 |
44Planlayın | CVE-2018-15812Silahlaştırılmış | DNN (aka DotNetNuke) 9.2 through 9.2.1 incorrectly converts encryption key source values, resulting in lower than expected entropy.dnnsoftware · dotnetnuke · CWE-331 | Yüksek7,5 | — | %47,2 | 3 Tem 2019 |
40Planlayın | CVE-2008-2108İstismar yok | The GENERATE_SEED macro in PHP 4.x before 4.4.8 and 5.x before 5.2.5, when running on 64-bit systems, performs a multiplication that generatphp · php · CWE-331 | Kritik9,8 | — | %4,3 | 7 May 2008 |
40Planlayın | CVE-2013-2260İstismar yok | Cryptocat before 2.0.22: Cryptocat.random() Function Array Key has Entropy Weaknesscryptocat project · cryptocat · CWE-331 | Kritik9,8 | — | %2,2 | 4 Kas 2019 |
40Planlayın | CVE-2022-34294İstismar yok | totd 1.5.3 uses a fixed UDP source port in upstream queries sent to DNS resolvers.totd project · totd · CWE-331 | Kritik9,8 | — | %1,8 | 15 Ağu 2022 |
40Planlayın | CVE-2022-43755İstismar yok | Rancher: Non-random authentication tokensuse · rancher · CWE-331 | Kritik9,8 | — | %1,7 | 7 Şub 2023 |
40Planlayın | CVE-2020-12735İstismar yok | reset.php in DomainMOD 4.13.0 uses insufficient entropy for password reset requests, leading to account takeover.domainmod · domainmod · CWE-331 | Kritik9,8 | — | %1,7 | 8 May 2020 |
40Planlayın | CVE-2018-1000620İstismar yok | Eran Hammer cryptiles version 4.1.1 earlier contains a CWE-331: Insufficient Entropy vulnerability in randomDigits() method that can result cryptiles project · cryptiles · CWE-331 | Kritik9,8 | — | %1,7 | 9 Tem 2018 |
39İzleyin | CVE-2021-36294İstismar yok | Dell VNX2 OE for File versions 8.1.21.266 and earlier, contain an authentication bypass vulnerability.dell · emc unity operating environment · CWE-331 | Kritik9,8 | — | %1,6 | 25 Oca 2022 |
39İzleyin | CVE-2021-22727İstismar yok | A CWE-331: Insufficient Entropy vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parkingschneider-electric · evlink city evc1s22p4 firmware · CWE-331 | Kritik9,8 | — | %1,4 | 21 Tem 2021 |
39İzleyin | CVE-2021-41615İstismar yok | websda.c in GoAhead WebServer 2.1.8 has insufficient nonce entropy because the nonce calculation relies on the hardcoded onceuponatimeinparaembedthis · goahead · CWE-331 | Kritik9,8 | — | %1,4 | 8 Ağu 2022 |
39İzleyin | CVE-2021-33027İstismar yok | Sylabs Singularity Enterprise through 1.6.2 has Insufficient Entropy in a nonce.sylabs · singularity · CWE-331 | Kritik9,8 | — | %1,3 | 19 Tem 2021 |
39İzleyin | CVE-2021-36320İstismar yok | Dell Networking X-Series firmware versions prior to 3.0.1.8 contain an authentication bypass vulnerability.dell · x1008p firmware · CWE-331 | Kritik9,8 | — | %1,2 | 19 Kas 2021 |
39İzleyin | CVE-2020-29508İstismar yok | Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Improper Inputdell · bsafe crypto-c-micro-edition · CWE-331 | Kritik9,8 | — | %1,2 | 11 Tem 2022 |
39İzleyin | CVE-2023-49599İstismar yok | An insufficient entropy vulnerability exists in the salt generation functionality of WWBN AVideo dev master commit 15fed957fb.wwbn · avideo · CWE-331 | Kritik9,8 | — | %1,0 | 10 Oca 2024 |
39İzleyin | CVE-2023-31176İstismar yok | Insufficient entropy vulnerability could lead to authentication bypassselinc · sel-451 firmware · CWE-331 | Kritik9,8 | — | %0,9 | 30 Kas 2023 |
39İzleyin | CVE-2024-25730İstismar yok | Hitron CODA-4582 and CODA-4589 devices have default PSKs that are generated from 5-digit hex values concatenated with a "Hitron" substring, hitrontech · coda-4582u firmware · CWE-331 | Kritik9,8 | — | %0,9 | 23 Şub 2024 |
39İzleyin | CVE-2024-36400İstismar yok | nano-id is unable to generate the correct character setviz · nano id · CWE-331 | Kritik9,8 | — | %0,8 | 4 Haz 2024 |
39İzleyin | CVE-2023-4344İstismar yok | Broadcom RAID Controller web interface is vulnerable to insufficient randomness due to improper use of ssl.rnd to setup CIM connectionbroadcom · raid controller web interface · CWE-331 | Kritik9,8 | — | %0,7 | 15 Ağu 2023 |
39İzleyin | CVE-2026-38447İstismar yok | osTicket 1.18.3 generates API keys using a predictable construction based on MD5 hashing.CWE-331 | Kritik9,8 | — | %0,7 | 3 Ağu 2026 |
39İzleyin | CVE-2026-13639İstismar yok | An insufficient entropy vulnerability in login logic in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009synology · diskstation manager (dsm) · CWE-331 | Kritik9,8 | — | %0,7 | 18 Eyl 2026 |
39İzleyin | CVE-2025-47781İstismar yok | Rallly Insufficient Password Login Token Entropy Leads to Account Takeoverrallly · rallly · CWE-331 | Kritik9,8 | — | %0,6 | 14 May 2025 |
39İzleyin | CVE-2025-67504İstismar yok | WBCE CMS has Weak Random Number Generator in Password Generation Functionwbce · wbce cms · CWE-331 | Kritik9,8 | — | %0,5 | 9 Ara 2025 |
39İzleyin | CVE-2026-34236İstismar yok | Auth0 PHP SDK Insufficient Entropy in Cookie Encryptionauth0 · auth0-php · CWE-331 | Kritik9,8 | — | %0,3 | 1 Nis 2026 |
- CVE-2008-144756Planlayın
The DNS protocol, as implemented in (1) BIND 8 and 9 before 9.5.0-P1, 9.4.2-P1, and 9.3.5-P1; (2) Microsoft DNS in Windows 2000 SP4, XP SP2
OrtaCVSS 6,8SilahlaştırılmışEPSS %95microsoft · windows 20008 Tem 2008
- CVE-2018-1832646Planlayın
DNN (aka DotNetNuke) 9.2 through 9.2.2 incorrectly converts encryption key source values, resulting in lower than expected entropy.
YüksekCVSS 7,5SilahlaştırılmışEPSS %54dnnsoftware · dotnetnuke3 Tem 2019
- CVE-2018-1581244Planlayın
DNN (aka DotNetNuke) 9.2 through 9.2.1 incorrectly converts encryption key source values, resulting in lower than expected entropy.
YüksekCVSS 7,5SilahlaştırılmışEPSS %47dnnsoftware · dotnetnuke3 Tem 2019
- CVE-2008-210840Planlayın
The GENERATE_SEED macro in PHP 4.x before 4.4.8 and 5.x before 5.2.5, when running on 64-bit systems, performs a multiplication that generat
KritikCVSS 9,8İstismar yokEPSS %4php · php7 May 2008
- CVE-2013-226040Planlayın
Cryptocat before 2.0.22: Cryptocat.random() Function Array Key has Entropy Weakness
KritikCVSS 9,8İstismar yokEPSS %2cryptocat project · cryptocat4 Kas 2019
- CVE-2022-3429440Planlayın
totd 1.5.3 uses a fixed UDP source port in upstream queries sent to DNS resolvers.
KritikCVSS 9,8İstismar yokEPSS %2totd project · totd15 Ağu 2022
- CVE-2022-4375540Planlayın
Rancher: Non-random authentication token
KritikCVSS 9,8İstismar yokEPSS %2suse · rancher7 Şub 2023
- CVE-2020-1273540Planlayın
reset.php in DomainMOD 4.13.0 uses insufficient entropy for password reset requests, leading to account takeover.
KritikCVSS 9,8İstismar yokEPSS %2domainmod · domainmod8 May 2020
- CVE-2018-100062040Planlayın
Eran Hammer cryptiles version 4.1.1 earlier contains a CWE-331: Insufficient Entropy vulnerability in randomDigits() method that can result
KritikCVSS 9,8İstismar yokEPSS %2cryptiles project · cryptiles9 Tem 2018
- CVE-2021-3629439İzleyin
Dell VNX2 OE for File versions 8.1.21.266 and earlier, contain an authentication bypass vulnerability.
KritikCVSS 9,8İstismar yokEPSS %2dell · emc unity operating environment25 Oca 2022
- CVE-2021-2272739İzleyin
A CWE-331: Insufficient Entropy vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking
KritikCVSS 9,8İstismar yokEPSS %1schneider-electric · evlink city evc1s22p4 firmware21 Tem 2021
- CVE-2021-4161539İzleyin
websda.c in GoAhead WebServer 2.1.8 has insufficient nonce entropy because the nonce calculation relies on the hardcoded onceuponatimeinpara
KritikCVSS 9,8İstismar yokEPSS %1embedthis · goahead8 Ağu 2022
- CVE-2021-3302739İzleyin
Sylabs Singularity Enterprise through 1.6.2 has Insufficient Entropy in a nonce.
KritikCVSS 9,8İstismar yokEPSS %1sylabs · singularity19 Tem 2021
- CVE-2021-3632039İzleyin
Dell Networking X-Series firmware versions prior to 3.0.1.8 contain an authentication bypass vulnerability.
KritikCVSS 9,8İstismar yokEPSS %1dell · x1008p firmware19 Kas 2021
- CVE-2020-2950839İzleyin
Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Improper Input
KritikCVSS 9,8İstismar yokEPSS %1dell · bsafe crypto-c-micro-edition11 Tem 2022
- CVE-2023-4959939İzleyin
An insufficient entropy vulnerability exists in the salt generation functionality of WWBN AVideo dev master commit 15fed957fb.
KritikCVSS 9,8İstismar yokEPSS %1wwbn · avideo10 Oca 2024
- CVE-2023-3117639İzleyin
Insufficient entropy vulnerability could lead to authentication bypass
KritikCVSS 9,8İstismar yokEPSS %1selinc · sel-451 firmware30 Kas 2023
- CVE-2024-2573039İzleyin
Hitron CODA-4582 and CODA-4589 devices have default PSKs that are generated from 5-digit hex values concatenated with a "Hitron" substring,
KritikCVSS 9,8İstismar yokEPSS %1hitrontech · coda-4582u firmware23 Şub 2024
- CVE-2024-3640039İzleyin
nano-id is unable to generate the correct character set
KritikCVSS 9,8İstismar yokEPSS %1viz · nano id4 Haz 2024
- CVE-2023-434439İzleyin
Broadcom RAID Controller web interface is vulnerable to insufficient randomness due to improper use of ssl.rnd to setup CIM connection
KritikCVSS 9,8İstismar yokEPSS %1broadcom · raid controller web interface15 Ağu 2023
- CVE-2026-3844739İzleyin
osTicket 1.18.3 generates API keys using a predictable construction based on MD5 hashing.
KritikCVSS 9,8İstismar yokEPSS %13 Ağu 2026
- CVE-2026-1363939İzleyin
An insufficient entropy vulnerability in login logic in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009
KritikCVSS 9,8İstismar yokEPSS %1synology · diskstation manager (dsm)18 Eyl 2026
- CVE-2025-4778139İzleyin
Rallly Insufficient Password Login Token Entropy Leads to Account Takeover
KritikCVSS 9,8İstismar yokEPSS %1rallly · rallly14 May 2025
- CVE-2025-6750439İzleyin
WBCE CMS has Weak Random Number Generator in Password Generation Function
KritikCVSS 9,8İstismar yokEPSS %1wbce · wbce cms9 Ara 2025
- CVE-2026-3423639İzleyin
Auth0 PHP SDK Insufficient Entropy in Cookie Encryption
KritikCVSS 9,8İstismar yokEPSS %0auth0 · auth0-php1 Nis 2026