Arteco Web Client DVR/NVR contains a session hijacking vulnerability with insufficient session ID complexity that allows
osTicket 1.18.3 generates API keys using a predictable construction based on MD5 hashing. The use of MD5, combined with
crypto-js is a JavaScript library of crypto standards. Versions of crypto-js prior to 4.0.0 generate randomness in Crypt
A weakness in the web interface’s application layer encryption in VX800v v1.0 allows an adjacent attacker to brute force
A privilege escalation vulnerability in Microchip IStaX allows an authenticated low-privileged user to recover a shared
Auth0-PHP is a PHP SDK for Auth0 Authentication and Management APIs. From version 8.0.0 to before version 8.19.0, in app
RustCrypto: Elliptic Curves is general purpose Elliptic Curve Cryptography (ECC) support, including types and traits for
`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allow
Trog::TOTP versions before 1.006 for Perl generate secrets using rand. Secrets were generated using Perl's built-in ran
Authen::TOTP versions before 0.1.1 for Perl generate secrets using rand. Secrets were generated using Perl's built-in r
A cryptographic weakness exists in the Omada adoption protocol where session encryption keys used to protect communicati
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, inline images that are accessible without being
Crypt::DSA versions before 1.20 for Perl generate seeds using rand. Seeds were generated using Perl's built-in rand fun
In Progress® Telerik® UI for AJAX, versions prior to 2026.1.225, an insufficient entropy vulnerability exists in RadAsyn
IBM PowerVM Hypervisor FW1110.00 through FW1110.20, FW1060.00 through FW1060.71, and FW950.00 through FW950.H2 could all
IBM PowerVM Hypervisor Platform KeyStore (PKS) and virtual TPM FW1110.00 through FW1110.20, FW1060.00 through FW1060.71,
An insufficient entropy vulnerability was found in glibc. The getrandom and arc4random family of functions may return pr
IBM PowerVM Hypervisor FW1110.00 through FW1110.20, and FW1060.00 through FW1060.71 could allow an attacker with physica
EEPROM firmware on Raspberry Pi 5 and Compute Module 5 devices produced non-random KASLR and RNG seed values. This resul
A security vulnerability has been detected in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC
A weakness has been identified in pkp pkp-lib 3.3.0/3.4.0/3.5.0. This vulnerability affects the function setData of the
libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document.
Rapid7 Nexpose versions 6.4.50 and later are vulnerable to an insufficient entropy issue in the CredentialsKeyStorePassw
DPA countermeasures in Silicon Labs' Series 2 devices are not reseeded under certain conditions. This may allow an att
The Micca KE700 system relies on a 6-bit portion of an identifier for authentication within rolling codes, providing onl
CWE‑331: Insufficient Entropy vulnerability exists that could lead to unauthorized access when an attacker on the networ
* Countermeasures for DPA within SYMCRYPTO engine on SixG301xxx devices are not sufficiently random and will eventually
Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Commun
SYMCRYPTO is the SiXG301's host side hardware engine accessed by PSA crypto library that accelerates symmetric cryptogra
A vulnerability in Sonatype Nexus Repository Manager's format-specific API key generation may allow a remote attacker to
Frequently Asked Questions
What is CWE-331?
CWE-331 (CWE-331) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-331?
There are 30 CVE records associated with CWE-331 in our database. Of these, 3 are critical severity, 10 are high severity, and 6 are medium severity.
How can I protect against CWE-331 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-331 using AI-powered security agents.
Detect CWE-331 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-331 vulnerabilities across your infrastructure.
Get Started