Skip to main content

CWE archive

CWE-331 CVEs

Programmatic archive

135 CVEs tagged with CWE-33124 Critical, 56 High, 46 Medium, 9 Low, 0 Unrated.

CVE-2026-4932

Published Jul 28, 2026

IBM PowerVM Hypervisor FW1110.00 through FW1110.20, and FW1060.00 through FW1060.71 could allow an attacker with physical access to the Transparent Memory Encryption (TME) hardwar…

CVSS 4.2 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-11403

Published Jul 14, 2026

A vulnerability in Sonatype Nexus Repository Manager's format-specific API key generation may allow a remote attacker to gain unauthorized access to repository operations as a tar…

CVSS 8.7 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-13199

Published Jul 7, 2026

EEPROM firmware on Raspberry Pi 5 and Compute Module 5 devices produced non-random KASLR and RNG seed values. This resulted in consistent kernel addresses across boots and devices…

CVSS 5.1 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-4930

Published Jun 25, 2026

SYMCRYPTO is the SiXG301's host side hardware engine accessed by PSA crypto library that accelerates symmetric cryptographic operations (AES encryption/decryption and hashing).…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-46473

Published May 21, 2026

Authen::TOTP versions before 0.1.1 for Perl generate secrets using rand. Secrets were generated using Perl's built-in rand function, which is predictable and unsuitable for secur…

CVSS 7.5 · High
evidence mentions
3
Buzz score
25.4

CVE-2026-8700

Published May 15, 2026

Crypt::DSA versions before 1.20 for Perl generate seeds using rand. Seeds were generated using Perl's built-in rand function, which is predictable and unsuitable for security usa…

CVSS 7.3 · High
evidence mentions
3
Buzz score
23.9

CVE-2026-46474

Published May 15, 2026

Trog::TOTP versions before 1.006 for Perl generate secrets using rand. Secrets were generated using Perl's built-in rand function, which is predictable and unsuitable for securit…

CVSS 7.5 · High
evidence mentions
3
Buzz score
23.9

CVE-2026-42155

Published May 15, 2026

Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platform with a high level of backwa…

CVSS 9.3 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2025-14972

Published May 15, 2026

* Countermeasures for DPA within SYMCRYPTO engine on SixG301xxx devices are not sufficiently random and will eventually repeat. * KSU keys using SYMCRYPTO will be impacted by…

CVSS 4.1 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-4827

Published May 12, 2026

CWE‑331: Insufficient Entropy vulnerability exists that could lead to unauthorized access when an attacker on the network can exploit weaknesses in session‑management protections.

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-7210

Published May 11, 2026

`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\r\n\r\nF…

CVSS 6.3 · Medium
evidence mentions
10
Buzz score
40.5
Vendor/product tagsBeta · best-effort

CVE-2026-2336

Published Apr 16, 2026

A privilege escalation vulnerability in Microchip IStaX allows an authenticated low-privileged user to recover a shared per-device cookie secret from their own webstax_auth sessio…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-41080

Published Apr 16, 2026

libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document.

CVSS 2.9 · Low
evidence mentions
7
Buzz score
40.8
Vendor/product tagsBeta · best-effort

CVE-2026-34236

Published Apr 1, 2026

Auth0-PHP is a PHP SDK for Auth0 Authentication and Management APIs. From version 8.0.0 to before version 8.19.0, in applications built with the Auth0 PHP SDK, cookies are encrypt…

CVSS 8.2 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-2878

Published Feb 25, 2026

In Progress® Telerik® UI for AJAX, versions prior to 2026.1.225, an insufficient entropy vulnerability exists in RadAsyncUpload, where a predictable temporary identifier, based on…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-0577

Published Feb 18, 2026

An insufficient entropy vulnerability was found in glibc. The getrandom and arc4random family of functions may return predictable randomness if these functions are called again af…

CVSS 4.8 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-2541

Published Feb 15, 2026

The Micca KE700 system relies on a 6-bit portion of an identifier for authentication within rolling codes, providing only 64 possible combinations. This low entropy allows an atta…

CVSS 6.4 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-7432

Published Feb 9, 2026

DPA countermeasures in Silicon Labs' Series 2 devices are not reseeded under certain conditions.  This may allow an attacker to eventually extract secret keys through a DPA attac…

CVSS 1.0 · Low

CVE-2026-1814

Published Feb 3, 2026

Rapid7 Nexpose versions 6.4.50 and later are vulnerable to an insufficient entropy issue in the CredentialsKeyStorePassword.generateRandomPassword() method. When updating legacy k…

CVSS 6.8 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-13399

Published Jan 29, 2026

A weakness in the web interface’s application layer encryption in VX800v v1.0 allows an adjacent attacker to brute force the weak AES key and decrypt intercepted traffic. Successf…

CVSS 7.7 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-22698

Published Jan 10, 2026

RustCrypto: Elliptic Curves is general purpose Elliptic Curve Cryptography (ECC) support, including types and traits for representing various elliptic curve forms, scalars, points…

CVSS 8.7 · High
evidence mentions
6
Buzz score
29.5
Vendor/product tagsBeta · best-effort

CVE-2020-36925

Published Jan 6, 2026

Arteco Web Client DVR/NVR contains a session hijacking vulnerability with insufficient session ID complexity that allows remote attackers to bypass authentication. Attackers can b…

CVSS 8.7 · High

CVE-2025-15387

Published Dec 31, 2025

VPN Firewall developed by QNO Technology has a Insufficient Entropy vulnerability, allowing unauthenticated remote attackers to obtain any logged-in user session through brute-for…

CVSS 8.7 · High
evidence mentions
2
Buzz score
16.0

CVE-2025-67504

Published Dec 9, 2025

WBCE CMS is a content management system. Versions 1.6.4 and below use function GenerateRandomPassword() to create passwords using PHP's rand(). rand() is not cryptographically sec…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-66565

Published Dec 9, 2025

Fiber Utils is a collection of common functions created for Fiber. In versions 2.0.0-rc.3 and below, when the system's cryptographic random number generator (crypto/rand) fails, b…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-25 of 135 CVEsPage 1 of 6