CWE-340Class

Generation of Predictable Numbers or Identifiers

Incomplete in the CWE catalog · 52 CVEs mapped

52
CVEs mapped
6.8
Median CVSS
What it is

The product uses a scheme that generates numbers or identifiers that are more predictable than required.

Recent examples
none
CVE-2026-64964

CVE-2026-64964 - UNKNOWN Severity Vulnerability

ATutor generates predictable email confirmation tokens due to the use of insufficiently random values in the account confirmation functionality. Due to the use of predictable values related to user registration, an attacker who knows or can predict these values can guess valid account activation tokens. This allows an attacker to activate an unconfirmed account without access to the victim's email inbox. Product is no longer actively supported and the vulnerabilities have not been fixed. Only version 2.2.4 was tested and confirmed as vulnerable, other versions were not tested but might also be vulnerable.

no explanation yet
0%
epss
none
CVE-2025-14602

CVE-2025-14602 - UNKNOWN Severity Vulnerability

The application generates uploaded file names using a weak and predictable method based on the request timestamp. This allows a remote attacker to accurately guess or brute-force the generated filename within a short time window. An attacker can successfully locate and access uploaded files, which can be used to facilitate further attacks. Apply patch from vendor https://vsdesk.ru/ . Versions 14.0101 and on have the patch.

no explanation yet
0%
epss
9.1cvss
CVE-2026-75106

CVE-2026-75106 - CRITICAL Severity Vulnerability

OpnForm derives editable-submission secrets from sequential row identifiers using Hashids with an empty default salt, allowing unauthenticated attackers to compute hashes for any submission. Attackers can read other respondents' full submission data through the submission-fetch endpoint or overwrite submissions by supplying predicted hashes to the answer endpoint.

CRITICALno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-340
Abstraction
Class
Structure
Simple
Status
Incomplete