NervesHub is a web service that allows users to manage over-the-air (OTA) firmware updates of devices in the field. A vu
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.206, FreeScout's
SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a weak session identifier generation vulnerability th
XikeStor SKS8310-8X Network Switch firmware versions 1.04.B07 and prior contain a predictable session identifier vulnera
High-risk TrustAllCerts routines disable standard TLS certificate validation. Combined with hard-coded DES symmetric enc
Binardat 10G08-0800GSM network switch firmware versions prior to V300SP10260209 generate predictable numeric session ide
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, attachment download tokens are g
In ManageEngine ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus, the SSO tickets generated
RELATE is a web-based courseware package. Prior to commit 2f68e16, RELATE is vulnerable to predictable token generation
A vulnerability in the SAML 2.0 single sign-on (SSO) feature of Cisco Secure Firewall ASA Software and Secure FTD Softwa
BigBlueButton is an open-source virtual classroom. Prior to 3.0.21, bbb-web generated conference sessionToken values wit
An issue in Eufy Homebase 2 version 3.3.4.1h allows a local attacker to obtain sensitive information via the cryptograph
Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, Jervis uses java.uti
Piwigo is an open source photo gallery application for the web. In versions on the 14.x branch, when installing, the sec
Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, REST API keys are generated using md5(time
Crypt::DSA versions before 1.22 for Perl draw the DSA signing nonce and private key from a biased random generator, lead
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, inline images that are accessible without being
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Fina
Adminer before 5.4.3 uses a CSRF token scheme that transmits both the XOR mask and the masked value in every token (form
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Sen
When connecting to the Solax Cloud MQTT server the username is the "registration number", which is the 10 character stri
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. All new in
Netatalk 2.0.0 through 4.4.2 generates AFP session tokens derived from predictable process IDs, which allows a remote au
Use of Insufficiently Random Values, Protection Mechanism Failure vulnerability in Apache Wicket. This issue affects Ap
A flaw was found in libkcapi. When performing one-shot symmetric cipher operations on large inputs (over 64 KiB) in stat
Net::BitTorrent versions before 2.1.0 for Perl generate the MSE Diffie-Hellman private key with a non-cryptographic PRNG
libtpms, a library that provides software emulation of a Trusted Platform Module, has a flaw in versions 0.10.0 and 0.10
Fleet is open source device management software. In versions prior to 4.80.1, Fleet generated device lock and wipe PINs
OpenClaw before 2026.4.2 reuses the PKCE verifier as the OAuth state parameter in the Gemini OAuth flow, exposing it thr
The netty incubator codec.bhttp is a java language binary http parser. Prior to version 0.0.21.Final, HKDF_expand return
AdGuard Home is a network-wide software for blocking ads and tracking. Prior to 0.107.75, AdGuard Home's client-triggere
IBM Maximo Application Suite 9.2, 9.1, and 9.0 could allow a remote attacker to tamper with session data due to the use
Values produced by ${random.value} are not suitable for use as secrets. ${random.uuid} is not affected. ${random.int} an
IDs for WebSocket sessions in the spring-websocket module are not cryptographically unpredictable, which may be possible
Netty is a network application framework for development of protocol servers and clients. Prior to version 4.2.15.Final,
Correlation IDs for replies in the RabbitTemplate.sendAndReceive() with the fixed reply queue are predictable due to int
Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.6.0, the _redirect_to_target(
A weakness has been identified in Cesanta Mongoose up to 7.20. The impacted element is the function mg_sendnsreq of the
A security vulnerability has been detected in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC
A flaw has been found in mangroup dtale up to 3.22.0. This vulnerability affects the function build_secret_key of the fi
A weakness has been identified in pkp pkp-lib 3.3.0/3.4.0/3.5.0. This vulnerability affects the function setData of the
A vulnerability has been found in TOTOLINK N600R 4.3.0cu.7866_B20220506. This vulnerability affects the function loginAu
A vulnerability was found in chatchat-space Langchain-Chatchat up to 0.3.1.3. The affected element is the function _get_
A flaw has been found in zcaceres markdownify-mcp up to 1.1.0. This impacts the function saveToTempFile of the file src/
Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Commun
Typebot is an open-source chatbot builder. In self-hosted versions up to and including 3.17.1, the default passwordless
A Predictable Resource Name vulnerability in BigQuery Import Staging in Google Cloud Vertex AI Search for Commerce versi
Frequently Asked Questions
What is CWE-330?
CWE-330 (CWE-330) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-330?
There are 47 CVE records associated with CWE-330 in our database. Of these, 8 are critical severity, 9 are high severity, and 20 are medium severity.
How can I protect against CWE-330 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-330 using AI-powered security agents.
Detect CWE-330 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-330 vulnerabilities across your infrastructure.
Get Started