CWE-330: CWE-330

61
Total CVEs
21
Critical
24
High
7.9
Avg CVSS

Yearly Trend

2026
6
2025
12
2024
9
2023
15
2022
10

Top Affected Vendors

1 Google 2
2 Dell 2
3 Tp Link 2
4 Debian 1
5 Wowonder 1
6 Sungrowpower 1
7 Oracle 1
8 Scala Js 1
9 Openautomationsoftware 1
10 Cloudflare 1

All CWE-330 CVEs (61)

CVE-2024-5149
6.5

The BuddyForms WordPress plugin has an email verification bypass vulnerability due to insufficiently random activation codes. Unauthenticated attacker...

Jun 5, 2024
CVE-2024-42165
6.3

This vulnerability in FIWARE Keyrock allows attackers to predict activation tokens due to insufficient randomness, enabling unauthorized account activ...

Aug 12, 2024
CVE-2025-13353
5.5

A vulnerability in gokey versions before 0.2.0 causes passwords derived from seed files to use only 28 bytes of entropy instead of the intended 240 by...

Dec 2, 2025
CVE-2025-11707
5.3

The Login Lockdown & Protection WordPress plugin has an IP block bypass vulnerability where attackers can generate valid unblock keys if they know an ...

Dec 13, 2025
CVE-2025-12787
5.3

This vulnerability allows unauthenticated attackers to cancel arbitrary bookings in the Hydra Booking WordPress plugin. Attackers can brute-force canc...

Nov 11, 2025
CVE-2025-10745
5.3

This vulnerability allows unauthenticated attackers to bypass the Banhammer WordPress plugin's traffic monitoring and blocking features. Attackers can...

Sep 26, 2025
CVE-2024-10604
5.3

This vulnerability in Fuchsia OS allows attackers to predict network protocol header values like TCP sequence numbers and source ports, enabling netwo...

Jan 30, 2025
CVE-2024-52615
5.3

This vulnerability in Avahi-daemon allows attackers to more easily inject malicious DNS responses by exploiting predictable source ports in wide-area ...

Nov 21, 2024
CVE-2025-66511
4.8

Nextcloud Calendar versions before 6.0.3 generate participant tokens for meeting proposals using a predictable hash function instead of cryptographica...

Dec 5, 2025
CVE-2025-13955
N/A

This vulnerability allows attackers within Wi-Fi range to calculate the default password for EZCast Pro II dongles using observable device identifiers...

Dec 10, 2025
CVE-2025-59371
N/A

An authentication bypass vulnerability in the IFTTT integration feature allows authenticated attackers to potentially gain unauthorized access to affe...

Nov 25, 2025

About CWE-330 (CWE-330)

Our database tracks 61 CVEs classified as CWE-330, with 21 rated critical and 24 rated high severity. The average CVSS score for CWE-330 vulnerabilities is 7.9.

External reference: View CWE-330 on MITRE CWE →

Monitor CWE-330 Vulnerabilities

Get alerted when new CWE-330 CVEs affect your infrastructure.

Start Monitoring Free