Skip to main content

CWE archive

CWE-337 CVEs

Programmatic archive

13 CVEs tagged with CWE-3370 Critical, 7 High, 3 Medium, 3 Low, 0 Unrated.

CVE-2026-26018

Published Mar 6, 2026

CoreDNS is a DNS server that chains plugins. Prior to version 1.14.2, a denial of service vulnerability exists in CoreDNS's loop detection plugin that allows an attacker to crash…

CVSS 7.5 · High
evidence mentions
8
Buzz score
35.0
Vendor/product tagsBeta · best-effort

CVE-2026-25235

Published Feb 3, 2026

PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, predictable verification hashes may allow attackers to guess verification tokens…

CVSS 8.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-62710

Published Oct 22, 2025

Sakai is a Collaboration and Learning Environment. Prior to versions 23.5 and 25.0, EncryptionUtilityServiceImpl initialized an AES256TextEncryptor password (serverSecretKey) usin…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-55069

Published Sep 23, 2025

A predictable seed in pseudo-random number generator vulnerability has been discovered in firmware version 3.60 of the Click Plus PLC. The vulnerability relies on the fact that th…

CVSS 8.7 · High

CVE-2025-20613

Published Aug 12, 2025

Predictable Seed in Pseudo-Random Number Generator (PRNG) in the firmware for some Intel(R) TDX may allow an authenticated user to potentially enable information disclosure via lo…

CVSS 2.0 · Low
evidence mentions
1
Buzz score
11.9

CVE-2025-7770

Published Aug 6, 2025

Tigo Energy's CCA device is vulnerable to insecure session ID generation in their remote API. The session IDs are generated using a predictable method based on the current timesta…

CVSS 8.7 · High

CVE-2023-49343

Published Dec 14, 2023

Temporary data passed between application components by Budgie Extras Dropby applet could potentially be viewed or manipulated. The data is stored in a location that is accessible…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-15006

Published Jan 2, 2023

A vulnerability, which was classified as problematic, has been found in enigmaX up to 2.2. This issue affects the function getSeed of the file main.c of the component Scrambling T…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-26852

Published Apr 8, 2022

Dell PowerScale OneFS, versions 8.2.x-9.3.x, contain a predictable seed in pseudo-random number generator. A remote unauthenticated attacker could potentially exploit this vulnera…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2020-28597

Published Mar 3, 2021

A predictable seed vulnerability exists in the password reset functionality of Epignosis EfrontPro 5.2.21. By predicting the seed it is possible to generate the correct password r…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-13 of 13 CVEsPage 1 of 1