The product uses an algorithm or scheme that produces insufficient entropy, leaving patterns or clusters of values that are more likely to occur than others.
Volume of CVEs assigned to CWE-331 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
134 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-1447MEDIUM The DNS protocol, as implemented in (1) BIND 8 and 9 before 9.5.0-P1, 9.4.2-P1, and 9.3.5-P1; (2) Microsoft DNS in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2; an | Jul 8, 2008 | 6.8 | 87 | NO | YES |
CVE-2018-18326HIGH DNN (aka DotNetNuke) 9.2 through 9.2.2 incorrectly converts encryption key source values, resulting in lower than expected entropy. NOTE: this issue exists because of an incomplete | Jul 3, 2019 | 7.5 | 71 | NO | YES |
CVE-2018-15812HIGH DNN (aka DotNetNuke) 9.2 through 9.2.1 incorrectly converts encryption key source values, resulting in lower than expected entropy. | Jul 3, 2019 | 7.5 | 69 | NO | YES |
CVE-2026-11403HIGH A vulnerability in Sonatype Nexus Repository Manager's format-specific API key generation may allow a remote attacker to gain unauthorized access to repository operations as a targ | Jul 14, 2026 | 8.7 | 35 | NO | NO |
CVE-2026-42155CRITICAL Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platform with a high level of backwar | May 15, 2026 | 9.3 | 34 | NO | NO |
CVE-2020-36925CRITICAL Arteco Web Client DVR/NVR contains a session hijacking vulnerability with insufficient session ID complexity that allows remote attackers to bypass authentication. Attackers can br | Jan 6, 2026 | 9.8 | 34 | NO | NO |
CVE-2025-67504CRITICAL WBCE CMS is a content management system. Versions 1.6.4 and below use function GenerateRandomPassword() to create passwords using PHP's rand(). rand() is not cryptographically secu | Dec 9, 2025 | 9.8 | 34 | NO | NO |
CVE-2026-46473HIGH Authen::TOTP versions before 0.1.1 for Perl generate secrets using rand.
Secrets were generated using Perl's built-in rand function, which is predictable and unsuitable for securi | May 21, 2026 | 7.5 | 33 | NO | NO |
CVE-2026-4827HIGH CWE‑331: Insufficient Entropy vulnerability exists that could lead to unauthorized access when an attacker on the network can exploit weaknesses in session‑management protections. | May 12, 2026 | 8.7 | 33 | NO | NO |
CVE-2026-7210HIGH `xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\r\n\r\nFu | May 11, 2026 | 7.5 | 32 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.