Skip to main content

CWE archive

CWE-335 CVEs

Programmatic archive

43 CVEs tagged with CWE-3356 Critical, 26 High, 11 Medium, 0 Low, 0 Unrated.

CVE-2026-11702

Published Jun 26, 2026

Bytes::Random::Secure::Tiny versions through 1.011 for Perl share internal state across forked processes. When an object is initialised before forking, then the internal state fo…

CVSS 7.5 · High
evidence mentions
5
Buzz score
32.9

CVE-2026-11625

Published Jun 26, 2026

Bytes::Random::Secure versions through 0.29 for Perl share internal state across forked processes. When an object is initialised before forking, or when the functional interface…

CVSS 7.5 · High
evidence mentions
6
Buzz score
39.5

CVE-2026-41564

Published Apr 23, 2026

CryptX versions before 0.088 for Perl do not reseed the Crypt::PK PRNG state after forking. The Crypt::PK::RSA, Crypt::PK::DSA, Crypt::PK::DH, Crypt::PK::ECC, Crypt::PK::Ed25519…

CVSS 7.5 · High
evidence mentions
4
Buzz score
27.6
Vendor/product tagsBeta · best-effort

CVE-2026-3503

Published Mar 19, 2026

Protection mechanism failure in wolfCrypt post-quantum implementations (ML-KEM and ML-DSA) in wolfSSL on ARM Cortex-M microcontrollers allows a physical attacker to compromise key…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-52578

Published Nov 18, 2025

Incorrect Usage of Seeds in Pseudo-Random Number Generator (CWE- 335) vulnerability in the High Sec ELM may allow a sophisticated attacker with physical access, to compromise inte…

CVSS 5.7 · Medium

CVE-2025-27580

Published Apr 24, 2025

NIH BRICS (aka Biomedical Research Informatics Computing System) through 14.0.0-67 generates predictable tokens (that depend on username, time, and the fixed 7Dl9#dj- string) and…

CVSS 7.5 · High

CVE-2024-10026

Published Jan 30, 2025

A weak hashing algorithm and small sizes of seeds/secrets in Google's gVisor allowed for a remote attacker to calculate a local IP address and a per-boot identifier that could aid…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-24783

Published Jan 27, 2025

** UNSUPPORTED WHEN ASSIGNED ** Incorrect Usage of Seeds in Pseudo-Random Number Generator (PRNG) vulnerability in Apache Cocoon. This issue affects Apache Cocoon: all versions.…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2024-55566

Published Dec 9, 2024

ColPack 1.0.10 through 9a7293a has a predictable temporary file (located under /tmp with a name derived from an unseeded RNG). The impact can be overwriting files or making ColPac…

CVSS 6.6 · Medium

CVE-2024-9312

Published Oct 10, 2024

Authd, through version 0.3.6, did not sufficiently randomize user IDs to prevent collisions. A local attacker who can register user names could spoof another user's ID and gain th…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-36048

Published May 18, 2024

QAbstractOAuth in Qt Network Authorization in Qt before 5.15.17, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.6, and 6.6.x through 6.7.x before 6.7.1 uses only the time to se…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-1579

Published Apr 29, 2024

Incorrect Usage of Seeds in Pseudo-Random Number Generator (PRNG) vulnerability in Secomea GateManager (Webserver modules) allows Session Hijacking.This issue affects GateManager:…

CVSS 8.1 · High

CVE-2024-27632

Published Apr 8, 2024

An issue in GNU Savane v.3.12 and before allows a remote attacker to escalate privileges via the form_id in the form_header() function.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-4472

Published Feb 1, 2024

Objectplanet Opinio version 7.22 and prior uses a cryptographically weak pseudo-random number generator (PRNG) coupled to a predictable seed, which could lead to an unauthenticate…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-49343

Published Dec 14, 2023

Temporary data passed between application components by Budgie Extras Dropby applet could potentially be viewed or manipulated. The data is stored in a location that is accessible…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-39218

Published Sep 20, 2022

The JS Compute Runtime for Fastly's Compute@Edge platform provides the environment JavaScript is executed in when using the Compute@Edge JavaScript SDK. In versions prior to 0.5.3…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-31034

Published Jun 27, 2022

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All versions of Argo CD starting with v0.11.0 are vulnerable to a variety of attacks when an SSO login is…

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2022-26852

Published Apr 8, 2022

Dell PowerScale OneFS, versions 8.2.x-9.3.x, contain a predictable seed in pseudo-random number generator. A remote unauthenticated attacker could potentially exploit this vulnera…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2016-3735

Published Jan 28, 2022

Piwigo is image gallery software written in PHP. When a criteria is not met on a host, piwigo defaults to usingmt_rand in order to generate password reset tokens. mt_rand output c…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 43 CVEsPage 1 of 2