CWE-330Class

Use of Insufficiently Random Values

Stable in the CWE catalog · 152 CVEs mapped

152
CVEs mapped
6.5
Median CVSS
What it is

The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.

Recent examples
5.9cvss
CVE-2026-86187

CVE-2026-86187 - MEDIUM Severity Vulnerability

WWBN AVideo generates passwords for external-login accounts using rand() instead of a cryptographic generator, producing only 31-bit integers. Attackers with access to password hashes can recover plaintext passwords in minutes through offline brute-force attacks due to unsalted MD5-based hashing.

MEDIUMno explanation yet
epss
5.4cvss
CVE-2026-17274

CVE-2026-17274 - MEDIUM Severity Vulnerability

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to predictable server seeds.

MEDIUMno explanation yet
0%
epss
5.9cvss
CVE-2026-3416

CVE-2026-3416 - MEDIUM Severity Vulnerability

The API Publisher component previously used a non-cryptographic pseudorandom number generator (PRNG) to create shared secrets for Webhook HMAC validation. This PRNG lacks sufficient entropy for security-sensitive operations, allowing a sophisticated attacker to predict future secrets. This enables malicious actors to forge event payloads with valid HMAC signatures, bypassing the API Gateway's authenticity verification. Successful exploitation could allow an attacker to predict shared secrets used for Webhook HMAC validation and forge event payloads with valid signatures. This may enable bypassing API Gateway authenticity checks, leading to unauthorized event injection, data manipulation, or downstream system compromise.

MEDIUMno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-330
Abstraction
Class
Structure
Simple
Status
Stable
References (3)