The product uses a Pseudo-Random Number Generator (PRNG) in a security context, but the PRNG's algorithm is not cryptographically strong.
Volume of CVEs assigned to CWE-338 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
204 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-0166HIGH OpenSSL 0.9.8c-1 up to versions before 0.9.8g-9 on Debian-based operating systems uses a random number generator that generates predictable numbers, which makes it easier for remot | May 13, 2008 | 7.5 | 75 | NO | YES |
CVE-2009-2367CRITICAL cgi-bin/makecgi-pro in Iomega StorCenter Pro generates predictable session IDs, which allows remote attackers to hijack active sessions and gain privileges via brute force guessing | Jul 8, 2009 | 9.8 | 48 | NO | YES |
CVE-2026-61500CRITICAL Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs of the same generator to unauthentic | Jul 13, 2026 | 9.8 | 42 | NO | NO |
CVE-2026-16235CRITICAL Crypt::Password versions through 0.28 for Perl generate insecure random values for salts.
These versions use the built-in rand function, which is predictable and unsuitable for cr | Jul 20, 2026 | 9.8 | 41 | NO | NO |
CVE-2026-56141CRITICAL In JetBrains Hub before 2026.1.13757,
2025.3.148033,
2025.2.148048,
2025.1.148120,
2024.3.148430,
2024.2.148429 account takeover via predictable restore codes was possible | Jun 19, 2026 | 9.8 | 41 | NO | NO |
CVE-2024-29868CRITICAL Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) vulnerability in Apache StreamPipes user self-registration and password recovery mechanism.
This allows an attac | Jun 24, 2024 | 9.1 | 41 | NO | YES |
CVE-2026-63089CRITICAL WireGuard Easy through 15.3.0, fixed in commit 66b292b, contains a cryptographically weak one-time link token generation vulnerability that allows unauthenticated network attackers | Jul 16, 2026 | 9.3 | 39 | NO | NO |
CVE-2026-47372CRITICAL Crypt::SaltedHash versions through 0.09 for Perl generate insecure random values for salts.
These versions use the built-in rand function, which is predictable and unsuitable for | May 20, 2026 | 9.1 | 38 | NO | NO |
CVE-2026-13577HIGH Dancer2 versions through 2.1.0 for Perl generate insecure session ids when required CSPRNG modules are unavailable.
Dancer2::Core::Role::SessionFactory::generate_id silently falls | Jul 20, 2026 | 8.2 | 37 | NO | NO |
CVE-2026-9323HIGH The urwid web display backend (urwid/display/web.py) generates web session identifiers (urwid_id) in Screen.start() by concatenating two random.randrange(10**9) calls that use Pyth | Jul 18, 2026 | 8.1 | 37 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.