The device uses an algorithm that is predictable and generates a pseudo-random number.
Volume of CVEs assigned to CWE-1241 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-57869HIGH Broken object-level access controls and the use of a deterministic pattern during random ID generation in MicroRealEstate allows attackers to access documents uploaded by landlords | Jul 7, 2026 | 7.1 | 31 | NO | NO |
CVE-2026-26018HIGH CoreDNS is a DNS server that chains plugins. Prior to version 1.14.2, a denial of service vulnerability exists in CoreDNS's loop detection plugin that allows an attacker to crash t | Mar 6, 2026 | 7.5 | 29 | NO | NO |
CVE-2026-6420MEDIUM A flaw was found in Keylime. An attacker with root access on an enrolled monitored machine, where the Keylime agent runs, can exploit a vulnerability in the Keylime verifier. The v | May 6, 2026 | 6.3 | 28 | NO | NO |
CVE-2016-10180HIGH An issue was discovered on the D-Link DWR-932B router. WPS PIN generation is based on srand(time(0)) seeding. | Jan 30, 2017 | 7.5 | 26 | NO | NO |
CVE-2021-3689HIGH yii2 is vulnerable to Use of Predictable Algorithm in Random Number Generator | Aug 10, 2021 | 7.5 | 24 | NO | NO |
CVE-2025-32056MEDIUM The anti-theft protection mechanism can be bypassed by attackers due to weak response generation algorithms for the head unit. It is possible to reveal all 32 corresponding respons | Jan 22, 2026 | 4.0 | 20 | NO | NO |
CVE-2023-4695HIGH Use of Predictable Algorithm in Random Number Generator in GitHub repository pkp/pkp-lib prior to 3.3.0-16. | Sep 1, 2023 | 8.1 | 20 | NO | NO |
CVE-2025-13079MEDIUM The Popup Builder – Create highly converting, mobile friendly marketing popups. plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.4 | Feb 19, 2026 | 5.3 | 19 | NO | NO |
CVE-2021-3692MEDIUM yii2 is vulnerable to Use of Predictable Algorithm in Random Number Generator | Aug 10, 2021 | 5.3 | 19 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.