Skip to main content

CWE archive

CWE-330 CVEs

Programmatic archive

381 CVEs tagged with CWE-33075 Critical, 129 High, 148 Medium, 29 Low, 0 Unrated.

CVE-2026-66391

Published Jul 27, 2026

Use of Insufficiently Random Values, Protection Mechanism Failure vulnerability in Apache Wicket. This issue affects Apache Wicket: from 9.0.0 through 9.23.0, from 10.0.0 through…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-46351

Published Jul 16, 2026

BigBlueButton is an open-source virtual classroom. Prior to 3.0.21, bbb-web generated conference sessionToken values with insufficiently secure randomness in bbb-common-web/src/ma…

CVSS 8.1 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-47703

Published Jul 15, 2026

AdGuard Home is a network-wide software for blocking ads and tracking. Prior to 0.107.75, AdGuard Home's client-triggered DoQ forwarding path to a udp:// upstream reduced backend…

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-14702

Published Jul 5, 2026

A flaw has been found in zcaceres markdownify-mcp up to 1.1.0. This impacts the function saveToTempFile of the file src/Markdownify.ts of the component webpage-to-markdown/youtube…

CVSS 1.1 · Low
evidence mentions
7
Buzz score
27.3

CVE-2026-14570

Published Jul 5, 2026

Crypt::DSA versions before 1.22 for Perl draw the DSA signing nonce and private key from a biased random generator, leading to private-key recovery. "Crypt::DSA::Util::makerandom…

CVSS 7.5 · High
evidence mentions
4
Buzz score
26.1

CVE-2026-57082

Published Jun 30, 2026

Net::BitTorrent versions before 2.1.0 for Perl generate the MSE Diffie-Hellman private key with a non-cryptographic PRNG. The MSE (Message Stream Encryption) handshake derives it…

CVSS 5.9 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-11374

Published Jun 23, 2026

In ManageEngine ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus, the SSO tickets generated to authenticate that session could be predicted by an una…

CVSS 9.0 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-50009

Published Jun 12, 2026

Netty is a network application framework for development of protocol servers and clients. Prior to version 4.2.15.Final, Netty QUIC exposes the stateless reset token on the networ…

CVSS 4.8 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-45673

Published Jun 12, 2026

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's DNS resolver uses a predictable…

CVSS 6.8 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-41701

Published Jun 10, 2026

Correlation IDs for replies in the RabbitTemplate.sendAndReceive() with the fixed reply queue are predictable due to internal simple counter. Affected versions: Spring AMQP 4.0.0…

CVSS 4.4 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-41838

Published Jun 9, 2026

IDs for WebSocket sessions in the spring-websocket module are not cryptographically unpredictable, which may be possible to exploit in combination with inadequate authorization ru…

CVSS 4.8 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-41207

Published Jun 4, 2026

The netty incubator codec.bhttp is a java language binary http parser. Prior to version 0.0.21.Final, HKDF_expand returns non-NULL on failure. The byte[] is filled with zeros and…

CVSS 6.9 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-50208

Published Jun 4, 2026

High-risk TrustAllCerts routines disable standard TLS certificate validation. Combined with hard-coded DES symmetric encryption keys, a Man-in-the-Middle (MITM) actor could decryp…

CVSS 9.2 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-44054

Published May 21, 2026

Netatalk 2.0.0 through 4.4.2 generates AFP session tokens derived from predictable process IDs, which allows a remote authenticated attacker to cause a denial of service by exploi…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-42155

Published May 15, 2026

Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platform with a high level of backwa…

CVSS 9.3 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-41505

Published May 7, 2026

RELATE is a web-based courseware package. Prior to commit 2f68e16, RELATE is vulnerable to predictable token generation in auth.py's make_sign_in_key() function and exam.py's gen_…

CVSS 8.7 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-7847

Published May 5, 2026

A vulnerability was found in chatchat-space Langchain-Chatchat up to 0.3.1.3. The affected element is the function _get_file_id of the file libs/chatchat-server/chatchat/server/ap…

CVSS 1.2 · Low
evidence mentions
6
Buzz score
26.0

CVE-2026-40975

Published Apr 28, 2026

Values produced by ${random.value} are not suitable for use as secrets. ${random.uuid} is not affected. ${random.int} and ${random.long} should never be used for secrets as they a…

CVSS 4.8 · Medium
evidence mentions
8
Buzz score
35.0
Vendor/product tagsBeta · best-effort

CVE-2026-40496

Published Apr 21, 2026

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, attachment download tokens are generated using a weak and predictable formula: `md5(APP_KEY…

CVSS 8.8 · High
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-40306

Published Apr 17, 2026

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. All new installations of DNN 10.x.x - 10.2.1 have the same Host GUID.…

CVSS 6.9 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-33710

Published Apr 10, 2026

Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, REST API keys are generated using md5(time() + (user_id * 5) - rand(10000, 10000)). The rand(10000, 1…

CVSS 7.5 · High
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-34511

Published Apr 3, 2026

OpenClaw before 2026.4.2 reuses the PKCE verifier as the OAuth state parameter in the Gemini OAuth flow, exposing it through the redirect URL. Attackers who capture the redirect U…

CVSS 6.0 · Medium
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2024-51346

Published Mar 25, 2026

An issue in Eufy Homebase 2 version 3.3.4.1h allows a local attacker to obtain sensitive information via the cryptographic scheme.

CVSS 7.7 · High
Showing 1-25 of 381 CVEsPage 1 of 16