The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.
Volume of CVEs assigned to CWE-330 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
380 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-5420CRITICAL A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess the automatically generated development mode secret token. Thi | Mar 27, 2019 | 9.8 | 90 | NO | YES |
CVE-2021-34646CRITICAL Versions up to, and including, 5.4.3, of the Booster for WooCommerce WordPress plugin are vulnerable to authentication bypass via the process_email_verification function due to a r | Aug 30, 2021 | 9.8 | 71 | NO | YES |
CVE-2018-17888CRITICAL NUUO CMS all versions 3.1 and prior, The application uses a session identification mechanism that could allow attackers to obtain the active session ID, which could allow arbitrary | Oct 12, 2018 | 9.8 | 59 | NO | YES |
CVE-2017-6026CRITICAL A Use of Insufficiently Random Values issue was discovered in Schneider Electric Modicon PLCs Modicon M241, firmware versions prior to Version 4.0.5.11, and Modicon M251, firmware | Jun 30, 2017 | 9.1 | 51 | NO | YES |
CVE-2022-36536CRITICAL An issue in the component post_applogin.php of Super Flexible Software GmbH & Co. KG Syncovery 9 for Linux v9.47x and below allows attackers to escalate privileges via creating cra | Sep 16, 2022 | 9.8 | 46 | NO | YES |
CVE-2026-11374CRITICAL In ManageEngine ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus, the SSO tickets generated to authenticate that session could be predicted
by an unau | Jun 23, 2026 | 9.0 | 43 | NO | NO |
CVE-2020-11901CRITICAL The Treck TCP/IP stack before 6.0.1.66 allows Remote Code execution via a single invalid DNS response. | Jun 17, 2020 | 9.0 | 41 | NO | NO |
CVE-2008-0087HIGH The DNS client in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, and Vista uses predictable DNS transaction IDs, which allows remote attackers to spoof DNS responses. | Apr 8, 2008 | 7.5 | 41 | NO | NO |
CVE-2026-50208CRITICAL High-risk TrustAllCerts routines disable standard TLS certificate validation. Combined with hard-coded DES symmetric encryption keys, a Man-in-the-Middle (MITM) actor could decrypt | Jun 4, 2026 | 9.4 | 35 | NO | NO |
CVE-2026-40975HIGH Values produced by ${random.value} are not suitable for use as secrets. ${random.uuid} is not affected. ${random.int} and ${random.long} should never be used for secrets as they ar | Apr 28, 2026 | 7.5 | 35 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.