Skip to main content

CWE archive

CWE-340 CVEs

Programmatic archive

50 CVEs tagged with CWE-34011 Critical, 13 High, 24 Medium, 2 Low, 0 Unrated.

CVE-2026-13577

Published Jul 20, 2026

Dancer2 versions through 2.1.0 for Perl generate insecure session ids when required CSPRNG modules are unavailable. Dancer2::Core::Role::SessionFactory::generate_id silently fall…

CVSS 8.2 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-47085

Published Jul 16, 2026

An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. URLAUTH token forgery can occur via a missing mboxkey. If an attacker knew a folder name on the victim's accou…

CVSS 4.0 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-56016

Published Jul 1, 2026

CGI::Session::ID::md5 versions before 4.49 for Perl generate predictable session ids from low-entropy sources. The generate_id method builds the session id from a MD5 digest of t…

CVSS 5.9 · Medium
evidence mentions
3
Buzz score
23.9

CVE-2026-9219

Published Jun 26, 2026

Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior have a predictable registration ID derived from IMEI. The enrollment system lacks additional authent…

CVSS 8.3 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-11374

Published Jun 23, 2026

In ManageEngine ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus, the SSO tickets generated to authenticate that session could be predicted by an una…

CVSS 9.0 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-9733

Published Jun 23, 2026

Mojolicious::Plugin::Web::Auth::OAuth2 versions through 0.17 for Perl have an insecure default state parameter. When no state generator is specified in the constructor, the modul…

CVSS 9.1 · Critical
evidence mentions
4
Buzz score
32.6

CVE-2026-9692

Published Jun 18, 2026

Mojolicious::Sessions::Storable versions through 0.05 for Perl generate session ids insecurely. The default session id generator returns a SHA-1 hash seeded with the built-in ran…

CVSS 5.3 · Medium
evidence mentions
4
Buzz score
31.1

CVE-2026-42932

Published Jun 12, 2026

Naxclow device identifiers use fixed manufacturing prefixes combined with sequential counters, producing a fully predictable and enumerable identifier space. Because the platform…

CVSS 6.9 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-45673

Published Jun 12, 2026

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's DNS resolver uses a predictable…

CVSS 6.8 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-8503

Published May 15, 2026

Apache::Session::Generate::SHA256 versions before 1.3.19 for Perl create insecure session ids. Apache::Session::Generate::SHA256 generated session ids insecurely. The default ses…

CVSS 6.5 · Medium
evidence mentions
5
Buzz score
32.9
Vendor/product tagsBeta · best-effort

CVE-2026-5084

Published May 11, 2026

WebDyne::Session versions through 2.075 for Perl generates the session id insecurely. The session handler generates the session id from an MD5 hash seeded with a call to the buil…

CVSS 6.5 · Medium
evidence mentions
4
Buzz score
36.1

CVE-2026-5080

Published Apr 30, 2026

Dancer::Session::Abstract versions through 1.3522 for Perl generates session ids insecurely. The session id is generated from summing the character codepoints of the absolute pat…

CVSS 5.9 · Medium
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2026-40496

Published Apr 21, 2026

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, attachment download tokens are generated using a weak and predictable formula: `md5(APP_KEY…

CVSS 8.8 · High
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-5085

Published Apr 13, 2026

Solstice::Session versions through 1440 for Perl generates session ids insecurely. The _generateSessionID method returns an MD5 digest seeded by the epoch time, a random hash ref…

CVSS 9.1 · Critical
evidence mentions
4
Buzz score
31.1
Vendor/product tagsBeta · best-effort

CVE-2026-5083

Published Apr 8, 2026

Ado::Sessions versions through 0.935 for Perl generates insecure session ids. The session id is generated from a SHA-1 hash seeded with the built-in rand function, the epoch time…

CVSS 5.3 · Medium
evidence mentions
4
Buzz score
32.6
Vendor/product tagsBeta · best-effort

CVE-2026-5082

Published Apr 8, 2026

Amon2::Plugin::Web::CSRFDefender versions from 7.00 through 7.03 for Perl generate an insecure session id. The generate_session_id function will attempt to read bytes from the /d…

CVSS 5.3 · Medium
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2026-28810

Published Apr 7, 2026

Generation of Predictable Numbers or Identifiers vulnerability in Erlang/OTP kernel (inet_res, inet_db modules) allows DNS Cache Poisoning. The built-in DNS resolver (inet_res) u…

CVSS 6.3 · Medium
evidence mentions
8
Buzz score
40.0
Vendor/product tagsBeta · best-effort

CVE-2025-13044

Published Apr 7, 2026

IBM Concert 1.0.0 through 2.2.0 creates temporary files with predictable names, which allows local users to overwrite arbitrary files via a symlink attack.

CVSS 6.2 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-3256

Published Mar 28, 2026

HTTP::Session versions before 0.54 for Perl defaults to using insecurely generated session ids. HTTP::Session defaults to using HTTP::Session::ID::SHA1 to generate session ids us…

CVSS 9.8 · Critical
evidence mentions
5
Buzz score
32.9
Vendor/product tagsBeta · best-effort

CVE-2025-15604

Published Mar 28, 2026

Amon2 versions before 6.17 for Perl use an insecure random_string implementation for security functions. In versions 6.06 through 6.16, the random_string function will attempt to…

CVSS 9.8 · Critical
evidence mentions
5
Buzz score
34.4
Vendor/product tagsBeta · best-effort

CVE-2026-4269

Published Mar 16, 2026

A missing S3 ownership verification in the Bedrock AgentCore Starter Toolkit before version v0.1.13 may allow a remote actor to inject code during the build process, leading to co…

CVSS 5.8 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-3255

Published Feb 27, 2026

HTTP::Session2 versions before 1.12 for Perl for Perl may generate weak session ids using the rand() function. The HTTP::Session2 session id generator returns a SHA-1 hash seeded…

CVSS 6.5 · Medium
evidence mentions
5
Buzz score
29.4
Vendor/product tagsBeta · best-effort
Showing 1-25 of 50 CVEsPage 1 of 2