Skip to main content

CWE archive

CWE-341 CVEs

Programmatic archive

15 CVEs tagged with CWE-3414 Critical, 5 High, 5 Medium, 1 Low, 0 Unrated.

CVE-2026-38968

Published Jul 2, 2026

ntopng through 6.6 is vulnerable to Predictable Session Identifier which can lead to Session Hijacking. HTTP session identifiers in src/HTTPserver.cpp use weak time-seeded pseudo-…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2026-36609

Published Jun 3, 2026

Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 uses a static authentication nonce that does not change between requests from the same source IP. Combined with the…

CVSS 7.3 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-40164

Published Apr 14, 2026

jq is a command-line JSON processor. Before commit 0c7d133c3c7e37c00b6d46b658a02244fdd3c784, jq used MurmurHash3 with a hardcoded, publicly visible seed (0x432A9843) for all JSON…

CVSS 7.5 · High
evidence mentions
33
Buzz score
48.0

CVE-2025-40780

Published Oct 22, 2025

In specific circumstances, due to a weakness in the Pseudo Random Number Generator (PRNG) that is used, it is possible for an attacker to predict the source port and query ID that…

CVSS 8.6 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-42925

Published Sep 9, 2025

Due to the lack of randomness in assigning Object Identifiers in the SAP NetWeaver AS JAVA IIOP service, an authenticated attacker with low privileges could predict the identifier…

CVSS 4.3 · Medium

CVE-2024-10141

Published Oct 19, 2024

A vulnerability, which was classified as problematic, was found in jsbroks COCO Annotator 0.11.1. This affects an unknown part of the component Session Handler. The manipulation o…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-4277

Published Dec 25, 2022

A vulnerability, which was classified as problematic, has been found in fredsmith utils. This issue affects some unknown processing of the file screenshot_sync of the component Fi…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2020-5365

Published May 20, 2020

Dell EMC Isilon versions 8.2.2 and earlier contain a remotesupport vulnerability. The pre-configured support account, remotesupport, is bundled in the Dell EMC Isilon OneFS instal…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-1731

Published Mar 2, 2020

A flaw was found in all versions of the Keycloak operator, before version 8.0.2,(community only) where the operator generates a random admin password when installing Keycloak, how…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-17917

Published Oct 10, 2018

All versions of Hangzhou Xiongmai Technology Co., Ltd XMeye P2P Cloud Server may allow an attacker to use MAC addresses to enumerate potential Cloud IDs. Using this ID, the attack…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-15 of 15 CVEsPage 1 of 1