Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CWE-338

Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)

The product uses a Pseudo-Random Number Generator (PRNG) in a security context, but the PRNG's algorithm is not cryptographically strong.

204
Assigned CVEs
125th
Commonality Rank
7.4
Avg CVSS
0.0%
In CISA KEV

Volume and Severity of Assigned CVEs Over Time

Volume of CVEs assigned to CWE-338 and their average CVSS base score over time.

Volume of CVEsAvg CVSS Base Score
First CVE
May 13, 2008
18 years ago
Most Recent CVE
Jul 22, 2026
2 days ago

Top CVEs Assigned This CWE

Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.

204 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2008-0166HIGH
OpenSSL 0.9.8c-1 up to versions before 0.9.8g-9 on Debian-based operating systems uses a random number generator that generates predictable numbers, which makes it easier for remot
May 13, 20087.575NOYES
CVE-2009-2367CRITICAL
cgi-bin/makecgi-pro in Iomega StorCenter Pro generates predictable session IDs, which allows remote attackers to hijack active sessions and gain privileges via brute force guessing
Jul 8, 20099.848NOYES
CVE-2026-61500CRITICAL
Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs of the same generator to unauthentic
Jul 13, 20269.842NONO
CVE-2026-16235CRITICAL
Crypt::Password versions through 0.28 for Perl generate insecure random values for salts. These versions use the built-in rand function, which is predictable and unsuitable for cr
Jul 20, 20269.841NONO
CVE-2026-56141CRITICAL
In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 account takeover via predictable restore codes was possible
Jun 19, 20269.841NONO
CVE-2024-29868CRITICAL
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) vulnerability in Apache StreamPipes user self-registration and password recovery mechanism. This allows an attac
Jun 24, 20249.141NOYES
CVE-2026-63089CRITICAL
WireGuard Easy through 15.3.0, fixed in commit 66b292b, contains a cryptographically weak one-time link token generation vulnerability that allows unauthenticated network attackers
Jul 16, 20269.339NONO
CVE-2026-47372CRITICAL
Crypt::SaltedHash versions through 0.09 for Perl generate insecure random values for salts. These versions use the built-in rand function, which is predictable and unsuitable for
May 20, 20269.138NONO
CVE-2026-13577HIGH
Dancer2 versions through 2.1.0 for Perl generate insecure session ids when required CSPRNG modules are unavailable. Dancer2::Core::Role::SessionFactory::generate_id silently falls
Jul 20, 20268.237NONO
CVE-2026-9323HIGH
The urwid web display backend (urwid/display/web.py) generates web session identifiers (urwid_id) in Screen.start() by concatenating two random.randrange(10**9) calls that use Pyth
Jul 18, 20268.137NONO
View all 204 CVEs →

CVE Severity & Scoring

This CWEGlobal (All CVEs)
0.0-0.9
1.0-1.9
2.0-2.9
3.0-3.9
10%
4.0-4.9
20%
19%
5.0-5.9
16%
6.0-6.9
29%
26%
7.0-7.9
11%
11%
8.0-8.9
26%
14%
9.0-10.0
unknown
CVSS Score Range

Exploit Exposure

Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
0.5% of CVEs· 83rd percentile
Nuclei
2 CVEs
1.0% of CVEs· 84th percentile
ExploitDB
2 CVEs
1.0% of CVEs· 81st percentile

Social Chatter

Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.

Media Mentions

Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.

Top Affected Vendors

Top Affected Products