İçeriğe atla
Noroxi

CWE-340 · 28 kayıt

Generation of Predictable Numbers or Identifiers

Bu sınıftaki CVE’ler

28 kayıt

  • CVE-2024-47945
    39İzleyin

    Predictable Session ID

    KritikCVSS 9,8İstismar yokEPSS %1

    rittal · iot interface firmware15 Eki 2024

  • CVE-2026-75106
    37İzleyin

    OpnForm Editable Submission Secret Derivation via Empty Hashids Salt

    KritikCVSS 9,3İstismar yokEPSS %0

    opnform · opnform17 Ağu 2026

  • CVE-2026-5081
    36İzleyin

    Apache::Session::Generate::ModUniqueId versions from 1.54 through 1.94 for Perl session ids are insecure

    KritikCVSS 9,1İstismar yokEPSS %0

    chorny · apache\6 May 2026

  • CVE-2025-69286
    35İzleyin

    RAGFlow has Predictable Token Generation Leading to Authentication Bypass Vulnerability

    YüksekCVSS 8,9Kavram kanıtıEPSS %1

    infiniflow · ragflow31 Ara 2025

  • CVE-2026-95653
    34İzleyin

    Concrete CMS Community Store before 2.7.8 Predictable Digital Download Token

    YüksekCVSS 8,7İstismar yokEPSS %1

    concretecms-community-store · community_store22 Eyl 2026

  • CVE-2025-62294
    34İzleyin

    Predictable Generation of Password Recovery Token

    YüksekCVSS 8,7İstismar yokEPSS %0

    soplanning · soplanning20 Kas 2025

  • CVE-2026-9219
    33İzleyin

    Setracker2 Children's Smartwatch Ecosystem Generation of Predictable Numbers or Identifiers

    YüksekCVSS 8,3İstismar yokEPSS %0

    shenzhen i365-tech co. ltd. · setracker2 parental control app (android) package com.tgelec.setracker25 Haz 2026

  • CVE-2024-12274
    30İzleyin

    BookingPress < 1.1.23 - Unauthenticated Export File Download

    YüksekCVSS 7,5İstismar yokEPSS %1

    codepeople · appointment booking calendar13 Oca 2025

  • CVE-2024-6477
    30İzleyin

    UsersWP < 1.2.12 - Users Information Disclosure

    YüksekCVSS 7,5İstismar yokEPSS %1

    ayecode · userswp3 Ağu 2024

  • CVE-2024-52299
    30İzleyin

    The PDF viewer macro allows accessing any attachment without access right checks

    YüksekCVSS 7,5İstismar yokEPSS %1

    xwiki · pdf viewer macro13 Kas 2024

  • CVE-2026-2473
    30İzleyin

    Bucket Squatting in Vertex AI Experiments leads to RCE and Model Theft.

    YüksekCVSS 7,7İstismar yokEPSS %0

    google cloud · vertex ai experiments20 Şub 2026

  • CVE-2026-85496
    30İzleyin

    Botslab G980H Dashcams Generation of Predictable Numbers or Identifiers

    YüksekCVSS 7,7İstismar yokEPSS %0

    botslab · g980h6 gün önce

  • CVE-2025-0218
    28İzleyin

    pgAgent scheduled batch job scripts are created in a predictable temporary directory potentially allowing a denial of service

    YüksekCVSS 7,1İstismar yokEPSS %0

    pgadmin · pgagent7 Oca 2025

  • CVE-2026-42932
    27İzleyin

    Naxclow IoT Platform Generation of Predictable Numbers or Identifiers

    OrtaCVSS 6,9İstismar yokEPSS %0

    naxclow · smart doorbell x312 Haz 2026

  • CVE-2026-28810
    25İzleyin

    Predictable DNS Transaction IDs Enable Cache Poisoning in Built-in Resolver

    OrtaCVSS 6,3İstismar yokEPSS %0

    erlang · erlang\/otp7 Nis 2026

  • CVE-2026-64964
    25İzleyin

    Generation of Predictable Email Confirmation Token in ATutor

    OrtaCVSS 6,3İstismar yokEPSS %0

    atutor · atutor20 Ağu 2026

  • CVE-2024-10603
    25İzleyin

    Weaknesses in the generation of TCP/UDP source ports and some other header values in Google's gVisor allowed them to be predicted by an exte

    OrtaCVSS 6,3İstismar yokEPSS %0

    google · gvisor30 Oca 2025

  • CVE-2025-58424
    25İzleyin

    BIG-IP TMM vulnerability

    OrtaCVSS 6,3İstismar yokEPSS %0

    f5 · big-ip access policy manager15 Eki 2025

  • CVE-2025-13044
    24İzleyin

    Multiple Vulnerabilities in IBM Concert Software

    OrtaCVSS 6,2İstismar yokEPSS %0

    ibm · concert6 Nis 2026

  • CVE-2025-59452
    23İzleyin

    The YoSmart YoLink API through 2025-10-02 uses an endpoint URL that is derived from a device's MAC address along with an MD5 hash of non-sec

    OrtaCVSS 5,8İstismar yokEPSS %0

    yosmart · yolink api6 Eki 2025

  • CVE-2024-28957
    21İzleyin

    Generation of predictable identifiers issue exists in Cente middleware TCP/IP Network Series.

    OrtaCVSS 5,3İstismar yokEPSS %1

    nxtech · cente ipv615 Nis 2024

  • CVE-2025-10148
    21İzleyin

    predictable WebSocket mask

    OrtaCVSS 5,3İstismar yokEPSS %0

    haxx · curl12 Eyl 2025

  • CVE-2025-14602
    21İzleyin

    Weak File Name Generation in vsDesk

    OrtaCVSS 5,3İstismar yokEPSS %0

    vsdesk · vsdesk20 Ağu 2026

  • CVE-2024-12034
    21İzleyin

    Advanced Google reCAPTCHA <= 1.25 - Brute Force Protection IP Unblock

    OrtaCVSS 5,3İstismar yokEPSS %0

    webfactory · advanced google recaptcha24 Ara 2024

  • CVE-2026-47085
    16İzleyin

    An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2.

    OrtaCVSS 4,0İstismar yokEPSS %0

    cyrusimap · cyrus imap16 Tem 2026

Tüm zafiyet sınıfları