Threats Tagged 'cwe-330'
View all threats tagged with 'cwe-330'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-330'
Click on any threat for detailed analysis and mitigation recommendations
0 OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 uses an administrator password-reset unlock-code design that lacks a per-device secret or other server-side cryptographic material. An attacker with physical-console access and access to the privileged password-reset workflow can forge a valid unlock code offline and use it to reset the administrator password. The underlying design has been present since at least firmware 2.2.3.4. Upgrade to version 3.5.4. Join the discussion | CVE Database V5 | 09/22/2026, 23:10:18 UTC Added: 09/22/2026, 23:33:13 UTC |
0 Postiz generates security-sensitive credentials using `Math.random()` instead of a cryptographically secure source. The same helper is used for OAuth access tokens, authorization codes, client secrets, organization API keys, and PKCE verifiers, meaning these credentials depend entirely on V8’s deterministic xorshift128+ PRNG state. An unauthenticated OAuth dynamic client registration endpoint exposes freshly generated client credentials, giving attackers enough consecutive PRNG output to reconstruct that internal state. Once recovered, they can deterministically derive past and future values produced by the same generator, potentially compromising credentials belonging to other users and organizations. Join the discussion | CVE Database V5 | 09/22/2026, 16:11:33 UTC Added: 09/22/2026, 16:33:28 UTC |
0 Bucket Squatting in Google Cloud Gemini Enterprise Agent Platform SDK for Python versions prior to 1.166.1 allows an attacker to achieve Remote Code Execution (RCE) and tenant-project token theft. Join the discussion | CVE Database V5 | 09/15/2026, 15:22:29 UTC Added: 09/15/2026, 15:32:36 UTC |
OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE). In versions 0.6.1 through 0.6.2.5, when cjose encrypts a JWE using an AES-CBC-HMAC content-encryption algorithm (`A128CBC-HS256`, `A192CBC-HS384`, or `A256CBC-HS512`) together with any key-management algorithm that generates a fresh content-encryption key (CEK), the CEK is all zero bytes instead of being randomly generated. The resulting JWE is therefore encrypted and authenticated under a fixed, publicly known key, so anyone who obtains the JWE can recover the plaintext and forge or modify the content. This is fixed in version 0.6.2.6 by `_cjose_jwe_set_cek_aes_cbc()` generating the CEK from `RAND_bytes`. A regression test asserts that the `encrypted_key` differs across two encryptions for each AES-CBC-HMAC variant. Until upgrading, for data encrypted with cjose, three options are available. Use an AES-GCM `enc` (`A128GCM` / `A192GCM` / `A256GCM`) instead of an AES-CBC-HMAC `enc`, use `alg=dir` with a caller-supplied CEK, or avoid using cjose for JWE encryption with the affected algorithm pair. These are mitigations for new ciphertexts only; data already encrypted under the zero key remains compromised and should be re-encrypted (and any secrets it contained rotated). Join the discussion | CVE Database V5 | 09/08/2026, 23:36:13 UTC Added: 09/09/2026, 11:05:13 UTC |
0 IBM i versions 7.3, 7.4, 7.5, and 7.6 contain a vulnerability where predictable server seeds could allow a remote authenticated attacker to bypass security restrictions. This issue is due to the use of insufficiently random values in the system's security mechanisms. The vulnerability has a medium severity with a CVSS score of 5.4. Join the discussion | CVE Database V5 | 09/04/2026, 16:37:35 UTC Added: 09/04/2026, 16:52:49 UTC |
The API Publisher component previously used a non-cryptographic pseudorandom number generator (PRNG) to create shared secrets for Webhook HMAC validation. This PRNG lacks sufficient entropy for security-sensitive operations, allowing a sophisticated attacker to predict future secrets. This enables malicious actors to forge event payloads with valid HMAC signatures, bypassing the API Gateway's authenticity verification. Successful exploitation could allow an attacker to predict shared secrets used for Webhook HMAC validation and forge event payloads with valid signatures. This may enable bypassing API Gateway authenticity checks, leading to unauthorized event injection, data manipulation, or downstream system compromise. Join the discussion | CVE Database V5 | 09/03/2026, 12:35:32 UTC Added: 09/03/2026, 12:53:06 UTC |
CVE-2026-81852 is a vulnerability in ash-project's ash_admin component where a hardcoded, publicly known Content-Security-Policy (CSP) nonce is used. This nonce is a compile-time constant that is not rotated per request, allowing an attacker who can inject HTML on an admin page to reuse the known nonce to bypass CSP protections against inline scripts. The issue affects versions from 0.10.8 up to but not including 1.3.1. The vulnerability has a low severity score and no known exploits in the wild. Join the discussion | CVE Database V5 | 08/31/2026, 02:29:14 UTC Added: 08/31/2026, 02:37:40 UTC |
0 CVE-2026-19485 is a critical vulnerability in Google Cloud Vertex AI Search for Commerce prior to 2026-04-27. It involves predictable resource names in the BigQuery Import Staging component, allowing an attacker who knows a victim's project number to gain read/write access to staged data and error logs. This vulnerability has been patched by Google, and no customer action is required. The vulnerability has a CVSS 4.0 score of 9.3, indicating high severity. It affects the cloud service hosted by Google Cloud Platform. Join the discussion | CVE Database V5 | 08/26/2026, 18:06:00 UTC Added: 08/26/2026, 18:52:52 UTC |
0 Typebot.io versions up to and including 3.17.1 have a vulnerability in their passwordless email magic-link authentication. The 6-digit login code is generated insecurely with Math.random(), allowing brute force attacks due to a limited keyspace and no effective attempt limits or lockout. Attackers can guess valid codes within their 10-minute lifetime without consuming attempts, enabling account takeover. OAuth or SSO-only deployments without email providers are not affected. This issue is fixed in version 3.18.0. Join the discussion | CVE Database V5 | 08/25/2026, 21:43:21 UTC Added: 08/25/2026, 21:52:55 UTC |
Combodo iTop versions prior to 3.2.3 use a weak 24-bit pseudo-random secret to protect inline images accessible without authentication. This insufficient entropy vulnerability allows potential attackers to predict or guess the secret, potentially exposing these images. The issue has been fixed in version 3.2.3. Join the discussion | CVE Database V5 | 08/21/2026, 19:59:29 UTC Added: 08/21/2026, 20:07:45 UTC |
Showing 1 to 10 of 58 results