VulnSea

CWE-331

CVEs classified under CWE-331, newest first.

11 CVEsRSS

CVE-2026-13639Critical· 9.8
4d ago

An insufficient entropy vulnerability in login logic in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to read or write arbitrary files and conduct denial-of-s…

An insufficient entropy vulnerability in login logic in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to read or write arbitrary files and conduct denial-of-s…

MidnightSynology · DiskStation Manager (DSM)EPSS 0.51%via NVD
CVE-2026-90562High· 8.1PoC
1w ago

LangBot before 4.10.11 generates password recovery keys with only 24 bits of entropy and applies no rate limiting to the unauthenticated reset-password endpoint

LangBot before 4.10.11 generates password recovery keys with only 24 bits of entropy and applies no rate limiting to the unauthenticated reset-password endpoint. Remote attackers knowing the administrator email can exhaust the keyspace t…

Midnightlangbot-app · LangBotEPSS 0.42%via NVD
CVE-2026-80171Medium· 4.7
1w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insufficient Entropy in PRNG vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insufficient Entropy in PRNG vulnerability. A low privileged attacker with local access could potentially exploit …

Sunlitdell · secure_connect_gatewayEPSS 0.08%via NVD
CVE-2026-62646High· 7.4
2w ago

A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70)

A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). A session identifier is generated using an algorithm with insufficient randomness, resulting in a token with low entropy that can be predicted or brute-forced w…

TwilightSiemens · Reyrolle 7SR5EPSS 0.32%via NVD
CVE-2026-27490High· 7.5
1mo ago

Combodo iTop is a web based IT service management tool

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, inline images that are accessible without being authenticated are protected by a weak 24-bit pseudo-random secret. This issue has been fixed in version 3.2.3.

TwilightEPSS 0.31%via NVD
CVE-2026-76956Medium· 5.9
1mo ago

In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, which results in being vulnerable to hash flooding attacks, causing a denial of service via crafted XML content.

In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, which results in being vulnerable to hash flooding attacks, causing a denial of service via crafted XML content.

Sunlitlibexpat_project · libexpatEPSS 0.29%via NVD
CVE-2026-19906Low· 3.7
1mo ago

A weakness has been identified in pkp pkp-lib 3.3.0/3.4.0/3.5.0

A weakness has been identified in pkp pkp-lib 3.3.0/3.4.0/3.5.0. This vulnerability affects the function setData of the file classes/user/form/APIProfileForm.php of the component API Key Generation. Executing a manipulation of the argume…

SunlitEPSS 0.33%via NVD
CVE-2026-71851Critical· 9.0PoC
1mo ago

crypto-js is a JavaScript library of crypto standards

crypto-js is a JavaScript library of crypto standards. Versions of crypto-js prior to 4.0.0 generate randomness in CryptoJS.lib.WordArray.random() using a custom variation of the Multiply-With-Carry pseudorandom number generator, seeded …

Abyssalcrypto-js · crypto-jsEPSS 0.34%via NVD
CVE-2026-7210High· 7.5⚖ disputed
4mo ago

`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\r\n\r\nFully mitigating this vulnerability requires both updating …

`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\r\n\r\nFully mitigating this vulnerability requires both updating …

Twilightpython · pythonEPSS 0.67%via NVD
CVE-2026-2336High· 8.8
5mo ago

A privilege escalation vulnerability in Microchip IStaX allows an authenticated low-privileged user to recover a shared per-device cookie secret from their own webstax_auth session cookie and forge a new cookie with administrative privil…

A privilege escalation vulnerability in Microchip IStaX allows an authenticated low-privileged user to recover a shared per-device cookie secret from their own webstax_auth session cookie and forge a new cookie with administrative privil…

Twilightmicrochip · istaxEPSS 0.23%via NVD
CVE-2024-6508High· 8.0
2y ago

An insufficient entropy vulnerability was found in the Openshift Console

An insufficient entropy vulnerability was found in the Openshift Console. In the authorization code type and implicit grant type, the OAuth2 protocol is vulnerable to a Cross-Site Request Forgery (CSRF) attack if the state parameter is u…

TwilightEPSS 0.67%via NVD
CWE-331 vulnerabilities (CVEs) · VulnSea