CWE-340 · 28 kayıt
Generation of Predictable Numbers or Identifiers
Bu sınıftaki CVE’ler
28 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2024-47945İstismar yok | Predictable Session IDrittal · iot interface firmware · CWE-340 | Kritik9,8 | — | %0,9 | 15 Eki 2024 |
37İzleyin | CVE-2026-75106İstismar yok | OpnForm Editable Submission Secret Derivation via Empty Hashids Saltopnform · opnform · CWE-340 | Kritik9,3 | — | %0,4 | 17 Ağu 2026 |
36İzleyin | CVE-2026-5081İstismar yok | Apache::Session::Generate::ModUniqueId versions from 1.54 through 1.94 for Perl session ids are insecurechorny · apache\ · CWE-340 | Kritik9,1 | — | %0,5 | 6 May 2026 |
35İzleyin | CVE-2025-69286Kavram kanıtı | RAGFlow has Predictable Token Generation Leading to Authentication Bypass Vulnerabilityinfiniflow · ragflow · CWE-340 | Yüksek8,9 | — | %0,8 | 31 Ara 2025 |
34İzleyin | CVE-2026-95653İstismar yok | Concrete CMS Community Store before 2.7.8 Predictable Digital Download Tokenconcretecms-community-store · community_store · CWE-340 | Yüksek8,7 | — | %0,6 | 22 Eyl 2026 |
34İzleyin | CVE-2025-62294İstismar yok | Predictable Generation of Password Recovery Tokensoplanning · soplanning · CWE-340 | Yüksek8,7 | — | %0,3 | 20 Kas 2025 |
33İzleyin | CVE-2026-9219İstismar yok | Setracker2 Children's Smartwatch Ecosystem Generation of Predictable Numbers or Identifiersshenzhen i365-tech co. ltd. · setracker2 parental control app (android) package com.tgelec.setracker · CWE-340 | Yüksek8,3 | — | %0,3 | 25 Haz 2026 |
30İzleyin | CVE-2024-12274İstismar yok | BookingPress < 1.1.23 - Unauthenticated Export File Downloadcodepeople · appointment booking calendar · CWE-340 | Yüksek7,5 | — | %0,6 | 13 Oca 2025 |
30İzleyin | CVE-2024-6477İstismar yok | UsersWP < 1.2.12 - Users Information Disclosureayecode · userswp · CWE-340 | Yüksek7,5 | — | %0,6 | 3 Ağu 2024 |
30İzleyin | CVE-2024-52299İstismar yok | The PDF viewer macro allows accessing any attachment without access right checksxwiki · pdf viewer macro · CWE-340 | Yüksek7,5 | — | %0,5 | 13 Kas 2024 |
30İzleyin | CVE-2026-2473İstismar yok | Bucket Squatting in Vertex AI Experiments leads to RCE and Model Theft.google cloud · vertex ai experiments · CWE-340 | Yüksek7,7 | — | %0,5 | 20 Şub 2026 |
30İzleyin | CVE-2026-85496İstismar yok | Botslab G980H Dashcams Generation of Predictable Numbers or Identifiersbotslab · g980h · CWE-340 | Yüksek7,7 | — | %0,3 | 6 gün önce |
28İzleyin | CVE-2025-0218İstismar yok | pgAgent scheduled batch job scripts are created in a predictable temporary directory potentially allowing a denial of servicepgadmin · pgagent · CWE-340 | Yüksek7,1 | — | %0,2 | 7 Oca 2025 |
27İzleyin | CVE-2026-42932İstismar yok | Naxclow IoT Platform Generation of Predictable Numbers or Identifiersnaxclow · smart doorbell x3 · CWE-340 | Orta6,9 | — | %0,3 | 12 Haz 2026 |
25İzleyin | CVE-2026-28810İstismar yok | Predictable DNS Transaction IDs Enable Cache Poisoning in Built-in Resolvererlang · erlang\/otp · CWE-340 | Orta6,3 | — | %0,4 | 7 Nis 2026 |
25İzleyin | CVE-2026-64964İstismar yok | Generation of Predictable Email Confirmation Token in ATutoratutor · atutor · CWE-340 | Orta6,3 | — | %0,4 | 20 Ağu 2026 |
25İzleyin | CVE-2024-10603İstismar yok | Weaknesses in the generation of TCP/UDP source ports and some other header values in Google's gVisor allowed them to be predicted by an extegoogle · gvisor · CWE-340 | Orta6,3 | — | %0,3 | 30 Oca 2025 |
25İzleyin | CVE-2025-58424İstismar yok | BIG-IP TMM vulnerabilityf5 · big-ip access policy manager · CWE-340 | Orta6,3 | — | %0,2 | 15 Eki 2025 |
24İzleyin | CVE-2025-13044İstismar yok | Multiple Vulnerabilities in IBM Concert Softwareibm · concert · CWE-340 | Orta6,2 | — | %0,1 | 6 Nis 2026 |
23İzleyin | CVE-2025-59452İstismar yok | The YoSmart YoLink API through 2025-10-02 uses an endpoint URL that is derived from a device's MAC address along with an MD5 hash of non-secyosmart · yolink api · CWE-340 | Orta5,8 | — | %0,4 | 6 Eki 2025 |
21İzleyin | CVE-2024-28957İstismar yok | Generation of predictable identifiers issue exists in Cente middleware TCP/IP Network Series.nxtech · cente ipv6 · CWE-340 | Orta5,3 | — | %0,8 | 15 Nis 2024 |
21İzleyin | CVE-2025-10148İstismar yok | predictable WebSocket maskhaxx · curl · CWE-340 | Orta5,3 | — | %0,5 | 12 Eyl 2025 |
21İzleyin | CVE-2025-14602İstismar yok | Weak File Name Generation in vsDeskvsdesk · vsdesk · CWE-340 | Orta5,3 | — | %0,5 | 20 Ağu 2026 |
21İzleyin | CVE-2024-12034İstismar yok | Advanced Google reCAPTCHA <= 1.25 - Brute Force Protection IP Unblockwebfactory · advanced google recaptcha · CWE-340 | Orta5,3 | — | %0,3 | 24 Ara 2024 |
16İzleyin | CVE-2026-47085İstismar yok | An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2.cyrusimap · cyrus imap · CWE-340 | Orta4,0 | — | %0,3 | 16 Tem 2026 |
- CVE-2024-4794539İzleyin
Predictable Session ID
KritikCVSS 9,8İstismar yokEPSS %1rittal · iot interface firmware15 Eki 2024
- CVE-2026-7510637İzleyin
OpnForm Editable Submission Secret Derivation via Empty Hashids Salt
KritikCVSS 9,3İstismar yokEPSS %0opnform · opnform17 Ağu 2026
- CVE-2026-508136İzleyin
Apache::Session::Generate::ModUniqueId versions from 1.54 through 1.94 for Perl session ids are insecure
KritikCVSS 9,1İstismar yokEPSS %0chorny · apache\6 May 2026
- CVE-2025-6928635İzleyin
RAGFlow has Predictable Token Generation Leading to Authentication Bypass Vulnerability
YüksekCVSS 8,9Kavram kanıtıEPSS %1infiniflow · ragflow31 Ara 2025
- CVE-2026-9565334İzleyin
Concrete CMS Community Store before 2.7.8 Predictable Digital Download Token
YüksekCVSS 8,7İstismar yokEPSS %1concretecms-community-store · community_store22 Eyl 2026
- CVE-2025-6229434İzleyin
Predictable Generation of Password Recovery Token
YüksekCVSS 8,7İstismar yokEPSS %0soplanning · soplanning20 Kas 2025
- CVE-2026-921933İzleyin
Setracker2 Children's Smartwatch Ecosystem Generation of Predictable Numbers or Identifiers
YüksekCVSS 8,3İstismar yokEPSS %0shenzhen i365-tech co. ltd. · setracker2 parental control app (android) package com.tgelec.setracker25 Haz 2026
- CVE-2024-1227430İzleyin
BookingPress < 1.1.23 - Unauthenticated Export File Download
YüksekCVSS 7,5İstismar yokEPSS %1codepeople · appointment booking calendar13 Oca 2025
- CVE-2024-647730İzleyin
UsersWP < 1.2.12 - Users Information Disclosure
YüksekCVSS 7,5İstismar yokEPSS %1ayecode · userswp3 Ağu 2024
- CVE-2024-5229930İzleyin
The PDF viewer macro allows accessing any attachment without access right checks
YüksekCVSS 7,5İstismar yokEPSS %1xwiki · pdf viewer macro13 Kas 2024
- CVE-2026-247330İzleyin
Bucket Squatting in Vertex AI Experiments leads to RCE and Model Theft.
YüksekCVSS 7,7İstismar yokEPSS %0google cloud · vertex ai experiments20 Şub 2026
- CVE-2026-8549630İzleyin
Botslab G980H Dashcams Generation of Predictable Numbers or Identifiers
YüksekCVSS 7,7İstismar yokEPSS %0botslab · g980h6 gün önce
- CVE-2025-021828İzleyin
pgAgent scheduled batch job scripts are created in a predictable temporary directory potentially allowing a denial of service
YüksekCVSS 7,1İstismar yokEPSS %0pgadmin · pgagent7 Oca 2025
- CVE-2026-4293227İzleyin
Naxclow IoT Platform Generation of Predictable Numbers or Identifiers
OrtaCVSS 6,9İstismar yokEPSS %0naxclow · smart doorbell x312 Haz 2026
- CVE-2026-2881025İzleyin
Predictable DNS Transaction IDs Enable Cache Poisoning in Built-in Resolver
OrtaCVSS 6,3İstismar yokEPSS %0erlang · erlang\/otp7 Nis 2026
- CVE-2026-6496425İzleyin
Generation of Predictable Email Confirmation Token in ATutor
OrtaCVSS 6,3İstismar yokEPSS %0atutor · atutor20 Ağu 2026
- CVE-2024-1060325İzleyin
Weaknesses in the generation of TCP/UDP source ports and some other header values in Google's gVisor allowed them to be predicted by an exte
OrtaCVSS 6,3İstismar yokEPSS %0google · gvisor30 Oca 2025
- CVE-2025-5842425İzleyin
BIG-IP TMM vulnerability
OrtaCVSS 6,3İstismar yokEPSS %0f5 · big-ip access policy manager15 Eki 2025
- CVE-2025-1304424İzleyin
Multiple Vulnerabilities in IBM Concert Software
OrtaCVSS 6,2İstismar yokEPSS %0ibm · concert6 Nis 2026
- CVE-2025-5945223İzleyin
The YoSmart YoLink API through 2025-10-02 uses an endpoint URL that is derived from a device's MAC address along with an MD5 hash of non-sec
OrtaCVSS 5,8İstismar yokEPSS %0yosmart · yolink api6 Eki 2025
- CVE-2024-2895721İzleyin
Generation of predictable identifiers issue exists in Cente middleware TCP/IP Network Series.
OrtaCVSS 5,3İstismar yokEPSS %1nxtech · cente ipv615 Nis 2024
- CVE-2025-1014821İzleyin
predictable WebSocket mask
OrtaCVSS 5,3İstismar yokEPSS %0haxx · curl12 Eyl 2025
- CVE-2025-1460221İzleyin
Weak File Name Generation in vsDesk
OrtaCVSS 5,3İstismar yokEPSS %0vsdesk · vsdesk20 Ağu 2026
- CVE-2024-1203421İzleyin
Advanced Google reCAPTCHA <= 1.25 - Brute Force Protection IP Unblock
OrtaCVSS 5,3İstismar yokEPSS %0webfactory · advanced google recaptcha24 Ara 2024
- CVE-2026-4708516İzleyin
An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2.
OrtaCVSS 4,0İstismar yokEPSS %0cyrusimap · cyrus imap16 Tem 2026