Skip to main content

CWE archive

CWE-334 CVEs

Programmatic archive

13 CVEs tagged with CWE-3342 Critical, 5 High, 6 Medium, 0 Low, 0 Unrated.

CVE-2024-54017

Published May 12, 2026

A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions < V11.0), SIPROTEC 5 6MD85 (CP200) (All versions), SIPROTEC 5 6MD85 (CP300) (All versions >= V7.80 <…

CVSS 6.9 · Medium

CVE-2025-3895

Published May 23, 2025

Token used for resetting passwords in MegaBIP software are generated using a small space of random values combined with a queryable value. It allows an unauthenticated attacker w…

CVSS 9.1 · Critical

CVE-2024-52616

Published Nov 21, 2024

A flaw was found in the Avahi-daemon, where it initializes DNS transaction IDs randomly only once at startup, incrementing them sequentially after that. This predictable behavior…

CVSS 5.3 · Medium

CVE-2024-51720

Published Nov 12, 2024

An insufficient entropy vulnerability in the SecuSUITE Secure Client Authentication (SCA) Server of SecuSUITE versions 5.0.420 and earlier could allow an attacker to potentially e…

CVSS 4.8 · Medium

CVE-2024-6890

Published Aug 7, 2024

Password reset tokens are generated using an insecure source of randomness. Attackers who know the username of the Journyx installation user can bruteforce the password reset and…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-6951

Published Apr 2, 2024

A Use of Weak Credentials vulnerability affecting the Wi-Fi network generated by a set of DJI drones could allow a remote attacker to derive the WPA2 PSK key and authenticate with…

CVSS 6.6 · Medium

CVE-2022-24402

Published Oct 19, 2023

The TETRA TEA1 keystream generator implements a key register initialization function that compresses the 80-bit key to only 32 bits for usage during the keystream generation phase…

CVSS 8.8 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2023-39979

Published Sep 2, 2023

There is a vulnerability in MXsecurity versions prior to 1.0.1 that can be exploited to bypass authentication. A remote attacker might access the system if the web service authent…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-13 of 13 CVEsPage 1 of 1