A Pseudo-Random Number Generator (PRNG) is initialized from a predictable seed, such as the process ID or system time.
Volume of CVEs assigned to CWE-337 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-26852CRITICAL Dell PowerScale OneFS, versions 8.2.x-9.3.x, contain a predictable seed in pseudo-random number generator. A remote unauthenticated attacker could potentially exploit this vulnerab | Apr 8, 2022 | 9.8 | 31 | NO | NO |
CVE-2026-26018HIGH CoreDNS is a DNS server that chains plugins. Prior to version 1.14.2, a denial of service vulnerability exists in CoreDNS's loop detection plugin that allows an attacker to crash t | Mar 6, 2026 | 7.5 | 29 | NO | NO |
CVE-2022-40267CRITICAL Predictable Seed in Pseudo-Random Number Generator (PRNG) vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series FX5U-xMy/z (x=32,64,80, y=T,R, z=ES,DS,ESS,DSS) with s | Jan 20, 2023 | 9.1 | 29 | NO | NO |
CVE-2025-7770HIGH Tigo Energy's CCA device is vulnerable to insecure session ID generation in their remote API. The session IDs are generated using a predictable method based on the current timestam | Aug 6, 2025 | 8.7 | 27 | NO | NO |
CVE-2025-55069HIGH A predictable seed in pseudo-random number generator vulnerability has been discovered in firmware version 3.60 of the Click Plus PLC. The vulnerability relies on the fact that the | Sep 23, 2025 | 8.3 | 25 | NO | NO |
CVE-2020-28597HIGH A predictable seed vulnerability exists in the password reset functionality of Epignosis EfrontPro 5.2.21. By predicting the seed it is possible to generate the correct password re | Mar 3, 2021 | 7.5 | 24 | NO | NO |
CVE-2024-7558HIGH JUJU_CONTEXT_ID is a predictable authentication secret. On a Juju machine (non-Kubernetes) or Juju charm container (on Kubernetes), an unprivileged user in the same network namespa | Oct 2, 2024 | 8.0 | 23 | NO | NO |
CVE-2026-25235HIGH PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, predictable verification hashes may allow attackers to guess verification tokens a | Feb 3, 2026 | 7.5 | 22 | NO | NO |
CVE-2025-62710MEDIUM Sakai is a Collaboration and Learning Environment. Prior to versions 23.5 and 25.0, EncryptionUtilityServiceImpl initialized an AES256TextEncryptor password (serverSecretKey) using | Oct 22, 2025 | 5.9 | 21 | NO | NO |
CVE-2023-49343HIGH Temporary data passed between application components by Budgie Extras Dropby applet could potentially be viewed or manipulated. The data is stored in a location that is accessible | Dec 14, 2023 | 7.8 | 21 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.