CWE-330

CWE-330 · 7 records · 4 with a public proof-of-concept

Records the NVD classes under CWE-330, highest CVSS first.

  1. CRITICAL 9.6CVE-2026-80154

    All firmware versions of Lantronix SLC8000, SLC9000, EMG8500, EMG7500, SLB882, SLCx-03, and SLCx-02 contain an authentication bypass vulnerability in the web management portal that allows unauthenticated attackers to derive valid session tokens of logged-in us…

    AI risk analysis on Exploit-DB.ai →

  2. CRITICAL 9.1CVE-2026-94456public PoC

    Postiz generates security-sensitive credentials using `Math.random()` instead of a cryptographically secure source. The same helper is used for OAuth access tokens, authorization codes, client secrets, organization API keys, and PKCE verifiers, meaning these c…

    AI risk analysis on Exploit-DB.ai →

  3. HIGH 7.4CVE-2026-92913public PoC

    AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 uses a cryptographically weak pseudo-random number generator when creating account activation / login pairing codes. getRandomCode() in objects/functions.php derives the code entirely from uniqid()…

    AI risk analysis on Exploit-DB.ai →

  4. MEDIUM 6.5CVE-2026-92912public PoC

    AVideo through c3edcc274c389816d434acadac07ee78eaf330c1 uses cryptographically weak uniqid() values for RTMP publish keys in LiveTransmition, reducing key entropy to approximately one million possibilities per creation second. Attackers who know the channel cr…

    AI risk analysis on Exploit-DB.ai →

  5. MEDIUM 6.5CVE-2026-71225

    A flaw was found in libkcapi. When performing one-shot symmetric cipher operations on large inputs (over 64 KiB) in stateful modes such as Counter (CTR) or Cipher Block Chaining (CBC), the library improperly reuses the Initialization Vector (IV) for each inter…

    AI risk analysis on Exploit-DB.ai →

  6. MEDIUM 6.2CVE-2026-92930

    OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 uses an administrator password-reset unlock-code design that lacks a per-device secret or other server-side cryptographic material. An attacker with physical-console access and access to the privileg…

    AI risk analysis on Exploit-DB.ai →

  7. MEDIUM 5.9CVE-2026-96599public PoC

    Isotope eCommerce through 2.9.10 derives order identifiers from uniqid() instead of a cryptographically secure source, allowing unauthenticated attackers to guess identifiers. Guest orders lack ownership verification, enabling attackers to access order details…

    AI risk analysis on Exploit-DB.ai →