VulnSea

CWE-330

CVEs classified under CWE-330, newest first.

30 CVEsRSS

CVE-2026-92912Medium· 6.5PoC
4d ago

AVideo through c3edcc274c389816d434acadac07ee78eaf330c1 uses cryptographically weak uniqid() values for RTMP publish keys in LiveTransmition, reducing key entropy to approximately one million possibilities per creation second

AVideo through c3edcc274c389816d434acadac07ee78eaf330c1 uses cryptographically weak uniqid() values for RTMP publish keys in LiveTransmition, reducing key entropy to approximately one million possibilities per creation second. Attackers …

TwilightWWBN · AVideoEPSS 0.23%via NVD
CVE-2026-92913High· 7.4PoC
4d ago

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 uses a cryptographically weak pseudo-random number generator when creating account activation / login pairing codes

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 uses a cryptographically weak pseudo-random number generator when creating account activation / login pairing codes. getRandomCode() in objects/functions.php derives the code…

MidnightWWBN · AVideoEPSS 0.51%via NVD
CVE-2026-19407High· 7.7
6d ago

Bucket Squatting in Google Cloud Gemini Enterprise Agent Platform SDK for Python versions prior to 1.166.1 allows an attacker to achieve Remote Code Execution (RCE) and tenant-project token theft.

Bucket Squatting in Google Cloud Gemini Enterprise Agent Platform SDK for Python versions prior to 1.166.1 allows an attacker to achieve Remote Code Execution (RCE) and tenant-project token theft.

TwilightGoogle Cloud · Gemini Enterprise Agent Platform SDK for PythonEPSS 0.52%via NVD
CVE-2026-84606High· 7.5
1w ago

A privacy issue was addressed with improved handling of identifiers

A privacy issue was addressed with improved handling of identifiers. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, visionOS 27. An app may be able to identify a user across reinstalls.

Twilightapple · ipadosEPSS 0.30%via NVD
CVE-2026-53939Critical· 9.1PoC
1w ago

OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE)

OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE). In versions 0.6.1 through 0.6.2.5, when cjose encrypts a JWE using an AES-CBC-HMAC content-encryption algorithm (`A128CBC-HS256`, `A192CBC-HS3…

AbyssalOpenIDC · cjoseEPSS 0.20%via NVD
CVE-2026-79575High· 7.5
1w ago

The JWT signing secret in yfexam-exam v2.0 is derived from the username and the current month instead of a random server-side key, making the secret key easily obtainable via a bruteforce attack.

The JWT signing secret in yfexam-exam v2.0 is derived from the username and the current month instead of a random server-side key, making the secret key easily obtainable via a bruteforce attack.

TwilightEPSS 0.24%via NVD
CVE-2026-86187Medium· 5.9
2w ago

WWBN AVideo generates passwords for external-login accounts using rand() instead of a cryptographic generator, producing only 31-bit integers

WWBN AVideo generates passwords for external-login accounts using rand() instead of a cryptographic generator, producing only 31-bit integers. Attackers with access to password hashes can recover plaintext passwords in minutes through of…

SunlitWWBN · AVideoEPSS 0.22%via NVD
CVE-2026-17274Medium· 5.4
2w ago

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to predictable server seeds.

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to predictable server seeds.

Sunlitibm · iEPSS 0.24%via NVD
CVE-2026-3416Medium· 5.9
2w ago

The API Publisher component previously used a non-cryptographic pseudorandom number generator (PRNG) to create shared secrets for Webhook HMAC validation

The API Publisher component previously used a non-cryptographic pseudorandom number generator (PRNG) to create shared secrets for Webhook HMAC validation. This PRNG lacks sufficient entropy for security-sensitive operations, allowing a s…

Sunlitwso2 · api_control_planeEPSS 0.26%via NVD
CVE-2026-66047High· 8.1
3w ago

ProfilePress (wp-user-avatar) WordPress plugin before 4.17.2 contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to install and activate arbitrary plugins by brute-forcing a weak 32-bit c…

ProfilePress (wp-user-avatar) WordPress plugin before 4.17.2 contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to install and activate arbitrary plugins by brute-forcing a weak 32-bit c…

TwilightEPSS 0.54%via NVD
CVE-2026-82555Low· 3.7
3w ago

A vulnerability has been found in TOTOLINK N600R 4.3.0cu.7866_B20220506

A vulnerability has been found in TOTOLINK N600R 4.3.0cu.7866_B20220506. This vulnerability affects the function loginAuth of the file /web_cste/cgi-bin/cstecgi.cgi of the component Authentication Handler. Such manipulation leads to insu…

SunlitEPSS 0.43%via NVD
CVE-2026-62862Critical· 9.1PoC
3w ago

Typebot is an open-source chatbot builder

Typebot is an open-source chatbot builder. In self-hosted versions up to and including 3.17.1, the default passwordless email magic-link authentication is vulnerable to login-code brute forcing that leads to account takeover. The email p…

AbyssalbaptisteArno · typebot.ioEPSS 0.51%via NVD
CVE-2026-56706Medium· 6.8
3w ago

Adminer before 5.4.3 uses a CSRF token scheme that transmits both the XOR mask and the masked value in every token (format (rand XOR secret):rand), allowing anyone who observes a single CSRF token (e.g., via network sniffing, log files, …

Adminer before 5.4.3 uses a CSRF token scheme that transmits both the XOR mask and the masked value in every token (format (rand XOR secret):rand), allowing anyone who observes a single CSRF token (e.g., via network sniffing, log files, …

SunlitEPSS 0.29%via NVD
CVE-2026-27490High· 7.5
1mo ago

Combodo iTop is a web based IT service management tool

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, inline images that are accessible without being authenticated are protected by a weak 24-bit pseudo-random secret. This issue has been fixed in version 3.2.3.

TwilightEPSS 0.31%via NVD
GHSA-92hr-gmr6-h8cpMedium
1mo ago

Etherpad addressed weak token RNG, login timing, plugin path handling, API request handling

Etherpad addressed weak token RNG, login timing, plugin path handling, API request handling

Sunlitep_etherpad-lite · ep_etherpad-litevia GHSA
CVE-2026-19906Low· 3.7
1mo ago

A weakness has been identified in pkp pkp-lib 3.3.0/3.4.0/3.5.0

A weakness has been identified in pkp pkp-lib 3.3.0/3.4.0/3.5.0. This vulnerability affects the function setData of the file classes/user/form/APIProfileForm.php of the component API Key Generation. Executing a manipulation of the argume…

SunlitEPSS 0.33%via NVD
CVE-2026-19896Low· 3.7
1mo ago

A flaw has been found in mangroup dtale up to 3.22.0

A flaw has been found in mangroup dtale up to 3.22.0. This vulnerability affects the function build_secret_key of the file dtale/app.py of the component Flask Session Cookie. This manipulation causes insufficiently random values. Remote …

SunlitEPSS 0.31%via NVD
CVE-2026-71225Medium· 6.5
1mo ago

A flaw was found in libkcapi

A flaw was found in libkcapi. When performing one-shot symmetric cipher operations on large inputs (over 64 KiB) in stateful modes such as Counter (CTR) or Cipher Block Chaining (CBC), the library improperly reuses the Initialization Vec…

Sunlitredhat · hardened_imagesEPSS 0.33%via NVD
GHSA-gq4g-fpc9-vjfqLow
2mo ago

Webauthn: SimpleFakeCredentialGenerator with an empty secret produces predictable fake credentials, weakening username enumeration protection

Webauthn: SimpleFakeCredentialGenerator with an empty secret produces predictable fake credentials, weakening username enumeration protection

Sunlitweb-auth · web-auth/webauthn-libvia GHSA
CVE-2026-57082Medium· 5.9
2mo ago

Net::BitTorrent versions before 2.1.0 for Perl generate the MSE Diffie-Hellman private key with a non-cryptographic PRNG. The MSE (Message Stream Encryption) handshake derives its 160-bit Diffie-Hellman private key from Perl's rand(), a…

Net::BitTorrent versions before 2.1.0 for Perl generate the MSE Diffie-Hellman private key with a non-cryptographic PRNG. The MSE (Message Stream Encryption) handshake derives its 160-bit Diffie-Hellman private key from Perl's rand(), a…

SunlitEPSS 0.23%via NVD
CVE-2022-31008Medium· 5.5
2mo ago

RabbitMQ has predictable credential obfuscation seed value used in Shovel and Federation plugins

RabbitMQ has predictable credential obfuscation seed value used in Shovel and Federation plugins

Sunlitrabbit_common · rabbit_commonEPSS 0.34%via GHSA
CVE-2026-50009Medium· 4.8
3mo ago

Netty: QUIC stateless reset token material exposed through header-visible connection IDs

Netty: QUIC stateless reset token material exposed through header-visible connection IDs

Sunlitnetty · io.netty:netty-codec-classes-quicEPSS 0.20%via GHSA
CVE-2026-45673Medium· 6.8
3mo ago

netty-resolver-dns: Netty DNS resolver: DNS Cache Poisoning via predictable transaction IDs (CVE-2026-45673)

A flaw was found in Netty's DNS resolver component. This vulnerability arises from the use of a predictable pseudo-random number generator (PRNG) for DNS transaction IDs and a static User Datagram Protocol (UDP) source port. This combinati…

SunlitRed Hat · OpenShift ServerlessEPSS 0.26%via CSAF
CVE-2026-41838Medium· 4.8
3mo ago

IDs for WebSocket sessions in the spring-websocket module are not cryptographically unpredictable, which may be possible to exploit in combination with inadequate authorization rules. Affected versions: Spring Framework 7.0.0 through 7.…

IDs for WebSocket sessions in the spring-websocket module are not cryptographically unpredictable, which may be possible to exploit in combination with inadequate authorization rules. Affected versions: Spring Framework 7.0.0 through 7.…

Sunlitvmware · spring_frameworkEPSS 0.17%via NVD
CVE-2026-34511Medium· 5.3
5mo ago

OpenClaw before 2026.4.2 reuses the PKCE verifier as the OAuth state parameter in the Gemini OAuth flow, exposing it through the redirect URL

OpenClaw before 2026.4.2 reuses the PKCE verifier as the OAuth state parameter in the Gemini OAuth flow, exposing it through the redirect URL. Attackers who capture the redirect URL can obtain both the authorization code and PKCE verifie…

Sunlitopenclaw · openclawEPSS 0.24%via NVD
CVE-2024-52615Medium· 5.3
1y ago

A flaw was found in Avahi-daemon, which relies on fixed source ports for wide-area DNS queries

A flaw was found in Avahi-daemon, which relies on fixed source ports for wide-area DNS queries. This issue simplifies attacks where malicious DNS responses are injected.

SunlitEPSS 0.56%via NVD
CVE-2024-23688Medium· 5.3
2y ago

Consensys Discovery versions less than 0.4.5 uses the same AES/GCM nonce for the entire session

Consensys Discovery versions less than 0.4.5 uses the same AES/GCM nonce for the entire session. which should ideally be unique for every message. The node's private key isn't compromised, only the session key generated for specific peer…

Sunlitconsensys · discoveryEPSS 0.49%via NVD
CVE-2022-29330Medium· 4.9
4y ago

Missing access control in the backup system of Telesoft VitalPBX before 3.2.1 allows attackers to access the PJSIP and SIP extension credentials, cryptographic keys and voicemails files via unspecified vectors.

Missing access control in the backup system of Telesoft VitalPBX before 3.2.1 allows attackers to access the PJSIP and SIP extension credentials, cryptographic keys and voicemails files via unspecified vectors.

Sunlitvitalpbx · vitalpbxEPSS 0.94%via NVD
CVE-2021-46010High· 8.8
4y ago

Totolink A3100R V5.9c.4577 suffers from Use of Insufficiently Random Values via the web configuration

Totolink A3100R V5.9c.4577 suffers from Use of Insufficiently Random Values via the web configuration. The SESSION_ID is predictable. An attacker can hijack a valid session and conduct further malicious operations.

Twilighttotolink · a3100r_firmwareEPSS 1.2%via NVD
CVE-2021-20322High· 7.4
4y ago

A flaw in the processing of received ICMP errors (ICMP fragment needed and ICMP redirect) in the Linux kernel functionality was found to allow the ability to quickly scan open UDP ports

A flaw in the processing of received ICMP errors (ICMP fragment needed and ICMP redirect) in the Linux kernel functionality was found to allow the ability to quickly scan open UDP ports. This flaw allows an off-path remote user to effect…

Twilightnetapp · active_iq_unified_managerEPSS 6.8%via NVD
CWE-330 vulnerabilities (CVEs) · VulnSea