Threats Tagged 'cwe-337'
View all threats tagged with 'cwe-337'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-337'
Click on any threat for detailed analysis and mitigation recommendations
0 CVE-2026-25235 is a high-severity vulnerability in the PEAR pearweb PHP framework prior to version 1.33.0. It involves a predictable seed in the pseudo-random number generator used to create verification hashes, allowing attackers to guess verification tokens. This flaw can enable unauthorized verification of election account requests, potentially compromising account integrity. The vulnerability requires no user interaction and can be exploited remotely without authentication. It has a CVSS 4.0 score of 8.2, indicating a significant risk. Although no known exploits are currently in the wild, the issue has been patched in version 1. Join the discussion | CVE Database V5 | 02/03/2026, 18:29:39 UTC Added: 02/03/2026, 19:00:10 UTC |
0 Sakai is a Collaboration and Learning Environment. Prior to versions 23.5 and 25.0, EncryptionUtilityServiceImpl initialized an AES256TextEncryptor password (serverSecretKey) using RandomStringUtils with the default java.util.Random.java.util.Random is a non‑cryptographic PRNG and can be predicted from limited state/seed information (e.g., start time window), substantially reducing the effective search space of the generated key. An attacker who can obtain ciphertexts (e.g., exported or at‑rest strings protected by this service) and approximate the PRNG seed can feasibly reconstruct the serverSecretKey and decrypt affected data. SAK-49866 is patched in Sakai 23.5, 25.0, and trunk. Join the discussion | CVE Database V5 | 10/22/2025, 22:19:21 UTC Added: 10/22/2025, 23:05:24 UTC |
0 A predictable seed in pseudo-random number generator vulnerability has been discovered in firmware version 3.60 of the Click Plus PLC. The vulnerability relies on the fact that the software implements a predictable seed for its pseudo-random number generator, which compromises the security of the generated private keys. Join the discussion | CVE Database V5 | 09/23/2025, 22:15:46 UTC Added: 09/24/2025, 00:09:16 UTC |
0 Tigo Energy's CCA device is vulnerable to insecure session ID generation in their remote API. The session IDs are generated using a predictable method based on the current timestamp, allowing attackers to recreate valid session IDs. When combined with the ability to circumvent session ID requirements for certain commands, this enables unauthorized access to sensitive device functions on connected solar optimization systems. Join the discussion | CVE Database V5 | 08/06/2025, 20:45:06 UTC Added: 08/06/2025, 21:02:45 UTC |
0 cdo-local-uuid project provides a specialized UUID-generating function that can, on user request, cause a program to generate deterministic UUIDs. An information leakage vulnerability is present in `cdo-local-uuid` at version `0.4.0`, and in `case-utils` in unpatched versions (matching the pattern `0.x.0`) at and since `0.5.0`, before `0.15.0`. The vulnerability stems from a Python function, `cdo_local_uuid.local_uuid()`, and its original implementation `case_utils.local_uuid()`. Join the discussion | CVE Database V5 | 01/11/2024, 02:21:53 UTC Added: 06/03/2025, 14:44:01 UTC |
Showing 1 to 5 of 5 results