CWE-341 · 14 kayıt
Predictable from Observable State
Bu sınıftaki CVE’ler
14 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2019-6563İstismar yok | Moxa IKS and EDS generate a predictable cookie calculated with an MD5 hash, allowing an attacker to capture the administrator's password, whmoxa · iks-g6824a firmware · CWE-341 | Kritik9,8 | — | %1,7 | 5 Mar 2019 |
39İzleyin | CVE-2020-1731İstismar yok | A flaw was found in all versions of the Keycloak operator, before version 8.0.2,(community only) where the operator generates a random adminredhat · keycloak operator · CWE-341 | Kritik9,8 | — | %1,3 | 2 Mar 2020 |
39İzleyin | CVE-2026-38968İstismar yok | ntopng through 6.6 is vulnerable to Predictable Session Identifier which can lead to Session Hijacking.ntop · ntopng · CWE-341 | Kritik9,8 | — | %0,6 | 2 Tem 2026 |
34İzleyin | CVE-2025-40780İstismar yok | Cache poisoning due to weak PRNGisc · bind 9 · CWE-341 | Yüksek8,6 | — | %0,5 | 22 Eki 2025 |
30İzleyin | CVE-2020-5365İstismar yok | Dell EMC Isilon versions 8.2.2 and earlier contain a remotesupport vulnerability.dell · emc isilon onefs · CWE-341 | Yüksek7,5 | — | %1,0 | 20 May 2020 |
30İzleyin | CVE-2026-42365İstismar yok | GeoVision LPC2011/LPC2211 Web Interface guessable session cookie vulnerabilitygeovision · gv-lpc2011 firmware · CWE-341 | Yüksek7,5 | — | %0,6 | 3 May 2026 |
30İzleyin | CVE-2023-49259İstismar yok | Bruteforcing authentication cookie for a given userhongdian · h8951-4g-esp firmware · CWE-341 | Yüksek7,5 | — | %0,3 | 12 Oca 2024 |
29İzleyin | CVE-2026-15571İstismar yok | Keycloak-services: keycloak-services: predictable account-linking hash enables account takeover via malicious oidc clientred hat · red hat build of keycloak 26.6 · CWE-341 | Yüksek7,3 | — | %0,4 | 18 Ağu 2026 |
25İzleyin | CVE-2024-10141İstismar yok | jsbroks COCO Annotator Session predictable statejsbroks · coco annotator · CWE-341 | Orta6,3 | — | %0,8 | 19 Eki 2024 |
21İzleyin | CVE-2018-17917İstismar yok | All versions of Hangzhou Xiongmai Technology Co., Ltd XMeye P2P Cloud Server may allow an attacker to use MAC addresses to enumerate potentixiongmaitech · xmeye p2p cloud server · CWE-341 | Orta5,3 | — | %1,3 | 10 Eki 2018 |
21İzleyin | CVE-2021-4277İstismar yok | fredsmith utils Filename screenshot_sync predictable stateutils project · utils · CWE-341 | Orta5,3 | — | %0,5 | 25 Ara 2022 |
20İzleyin | CVE-2025-48461Kavram kanıtı | Weak Session Cookie Entropyadvantech · wise-4060lan firmware · CWE-341 | Orta5,0 | — | %0,5 | 23 Haz 2025 |
17İzleyin | CVE-2025-42925İstismar yok | Predictable Object Identifier vulnerability in SAP NetWeaver AS Java (IIOP Service)sap_se · sap netweaver as java (iiop service) · CWE-341 | Orta4,3 | — | %0,2 | 8 Eyl 2025 |
14İzleyin | CVE-2026-19565İstismar yok | Apache::AppSamurai::Util versions through 1.01 for Perl generate predictable session authentication keys from the clock and process id in CreateSessionAuthKeyCWE-341 | Düşük3,7 | — | %0,4 | 23 Ağu 2026 |
- CVE-2019-656340Planlayın
Moxa IKS and EDS generate a predictable cookie calculated with an MD5 hash, allowing an attacker to capture the administrator's password, wh
KritikCVSS 9,8İstismar yokEPSS %2moxa · iks-g6824a firmware5 Mar 2019
- CVE-2020-173139İzleyin
A flaw was found in all versions of the Keycloak operator, before version 8.0.2,(community only) where the operator generates a random admin
KritikCVSS 9,8İstismar yokEPSS %1redhat · keycloak operator2 Mar 2020
- CVE-2026-3896839İzleyin
ntopng through 6.6 is vulnerable to Predictable Session Identifier which can lead to Session Hijacking.
KritikCVSS 9,8İstismar yokEPSS %1ntop · ntopng2 Tem 2026
- CVE-2025-4078034İzleyin
Cache poisoning due to weak PRNG
YüksekCVSS 8,6İstismar yokEPSS %0isc · bind 922 Eki 2025
- CVE-2020-536530İzleyin
Dell EMC Isilon versions 8.2.2 and earlier contain a remotesupport vulnerability.
YüksekCVSS 7,5İstismar yokEPSS %1dell · emc isilon onefs20 May 2020
- CVE-2026-4236530İzleyin
GeoVision LPC2011/LPC2211 Web Interface guessable session cookie vulnerability
YüksekCVSS 7,5İstismar yokEPSS %1geovision · gv-lpc2011 firmware3 May 2026
- CVE-2023-4925930İzleyin
Bruteforcing authentication cookie for a given user
YüksekCVSS 7,5İstismar yokEPSS %0hongdian · h8951-4g-esp firmware12 Oca 2024
- CVE-2026-1557129İzleyin
Keycloak-services: keycloak-services: predictable account-linking hash enables account takeover via malicious oidc client
YüksekCVSS 7,3İstismar yokEPSS %0red hat · red hat build of keycloak 26.618 Ağu 2026
- CVE-2024-1014125İzleyin
jsbroks COCO Annotator Session predictable state
OrtaCVSS 6,3İstismar yokEPSS %1jsbroks · coco annotator19 Eki 2024
- CVE-2018-1791721İzleyin
All versions of Hangzhou Xiongmai Technology Co., Ltd XMeye P2P Cloud Server may allow an attacker to use MAC addresses to enumerate potenti
OrtaCVSS 5,3İstismar yokEPSS %1xiongmaitech · xmeye p2p cloud server10 Eki 2018
- CVE-2021-427721İzleyin
fredsmith utils Filename screenshot_sync predictable state
OrtaCVSS 5,3İstismar yokEPSS %0utils project · utils25 Ara 2022
- CVE-2025-4846120İzleyin
Weak Session Cookie Entropy
OrtaCVSS 5,0Kavram kanıtıEPSS %0advantech · wise-4060lan firmware23 Haz 2025
- CVE-2025-4292517İzleyin
Predictable Object Identifier vulnerability in SAP NetWeaver AS Java (IIOP Service)
OrtaCVSS 4,3İstismar yokEPSS %0sap_se · sap netweaver as java (iiop service)8 Eyl 2025
- CVE-2026-1956514İzleyin
Apache::AppSamurai::Util versions through 1.01 for Perl generate predictable session authentication keys from the clock and process id in CreateSessionAuthKey
DüşükCVSS 3,7İstismar yokEPSS %023 Ağu 2026