Total
199 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-15618 | 1 Mock | 1 Business\ | 2026-06-17 | N/A | 9.1 CRITICAL |
| Business::OnlinePayment::StoredTransaction versions through 0.01 for Perl uses an insecure secret key. Business::OnlinePayment::StoredTransaction generates a secret key by using a MD5 hash of a single call to the built-in rand function, which is unsuitable for cryptographic use. This key is intended for encrypting credit card transaction data. | |||||
| CVE-2025-15604 | 1 Tokuhirom | 1 Amon2 | 2026-06-17 | N/A | 9.8 CRITICAL |
| Amon2 versions before 6.17 for Perl use an insecure random_string implementation for security functions. In versions 6.06 through 6.16, the random_string function will attempt to read bytes from the /dev/urandom device, but if that is unavailable then it generates bytes by concatenating a SHA-1 hash seeded with the built-in rand() function, the PID, and the high resolution epoch time. The PID will come from a small set of numbers, and the epoch time may be guessed, if it is not leaked from the HTTP Date header. The built-in rand function is unsuitable for cryptographic usage. Before version 6.06, there was no fallback when /dev/urandom was not available. Before version 6.04, the random_string function used the built-in rand() function to generate a mixed-case alphanumeric string. This function may be used for generating session ids, generating secrets for signing or encrypting cookie session data and generating tokens used for Cross Site Request Forgery (CSRF) protection. | |||||
| CVE-2025-15578 | 1 Teejay | 1 Maypole | 2026-06-17 | N/A | 9.8 CRITICAL |
| Maypole versions from 2.10 through 2.13 for Perl generates session ids insecurely. The session id is seeded with the system time (which is available from HTTP response headers), a call to the built-in rand() function, and the PID. | |||||
| CVE-2024-7315 | 1 Wpvivid | 1 Migration\, Backup\, Staging | 2026-06-17 | N/A | 7.5 HIGH |
| The Migration, Backup, Staging WordPress plugin before 0.9.106 does not use sufficient randomness in the filename that is created when generating a backup, which could be bruteforced by attackers to leak sensitive information about said backups. | |||||
| CVE-2024-5264 | 1 Thalesgroup | 1 Luna Eft | 2026-06-17 | N/A | 5.9 MEDIUM |
| Network Transfer with AES KHT in Thales Luna EFT 2.1 and above allows a user with administrative console access to access backups taken via offline analysis | |||||
| CVE-2024-58135 | 1 Mojolicious | 1 Mojolicious | 2026-06-17 | N/A | 5.3 MEDIUM |
| Mojolicious versions from 7.28 through 9.45 for Perl will generate weak HMAC session cookie secrets via "mojo generate app" by default. When creating a default app skeleton with the "mojo generate app" tool, a weak secret is written to the application's configuration file using the insecure rand() function, and used for authenticating and protecting the integrity of the application's sessions. This may allow an attacker to brute force the application's session keys. Release 9.46 fixes the issue by providing high quality randomness, even in absence of CryptX. Users should be aware that the update does not replace previously generated weak secrets. A secret generated with the previous version MUST be replaced to ensure the updated version is using a strong secret. | |||||
| CVE-2024-58041 | 1 Wonko | 1 Smolder | 2026-06-17 | N/A | 9.1 CRITICAL |
| Smolder versions through 1.51 for Perl uses insecure rand() function for cryptographic functions. Smolder 1.51 and earlier for Perl uses the rand() function as the default source of entropy, which is not cryptographically secure, for cryptographic functions. Specifically Smolder::DB::Developer uses the Data::Random library which specifically states that it is "Useful mostly for test programs". Data::Random uses the rand() function. | |||||
| CVE-2024-58040 | 1 Qwer | 1 Crypt\ | 2026-06-17 | N/A | 9.1 CRITICAL |
| Crypt::RandomEncryption for Perl version 0.01 uses insecure rand() function during encryption. | |||||
| CVE-2024-58036 | 1 Norbu09 | 1 Net\ | 2026-06-17 | N/A | 5.5 MEDIUM |
| Net::Dropbox::API 1.9 and earlier for Perl uses the rand() function as the default source of entropy, which is not cryptographically secure, for cryptographic functions. Specifically Net::Dropbox::API uses the Data::Random library which specifically states that it is "Useful mostly for test programs". Data::Random uses the rand() function. | |||||
| CVE-2024-57868 | 1 Lev | 1 Web\ | 2026-06-17 | N/A | 5.5 MEDIUM |
| Web::API 2.8 and earlier for Perl uses the rand() function as the default source of entropy, which is not cryptographically secure, for cryptographic functions. Specifically Web::API uses the Data::Random library which specifically states that it is "Useful mostly for test programs". Data::Random uses the rand() function. | |||||
| CVE-2024-57854 | 1 Dougdude | 1 Net\ | 2026-06-17 | N/A | 9.1 CRITICAL |
| Net::NSCA::Client versions through 0.009002 for Perl uses a poor random number generator. Version v0.003 switched to use Data::Rand::Obscure instead of Crypt::Random for generation of a random initialisation vectors. Data::Rand::Obscure uses Perl's built-in rand() function, which is not suitable for cryptographic functions. | |||||
| CVE-2024-57835 | 1 Nipotan | 1 Line Integration For Amon2 | 2026-06-17 | N/A | 5.5 MEDIUM |
| Amon2::Auth::Site::LINE uses the String::Random module to generate nonce values. String::Random defaults to Perl's built-in predictable random number generator, the rand() function, which is not cryptographically secure | |||||
| CVE-2024-56830 | 2026-06-17 | N/A | 5.4 MEDIUM | ||
| The Net::EasyTCP package 0.15 through 0.26 for Perl uses Perl's builtin rand() if no strong randomization module is present. | |||||
| CVE-2024-56370 | 2026-06-17 | N/A | 6.5 MEDIUM | ||
| Net::Xero 0.044 and earlier for Perl uses the rand() function as the default source of entropy, which is not cryptographically secure, for cryptographic functions. Specifically Net::Xero uses the Data::Random library which specifically states that it is "Useful mostly for test programs". Data::Random uses the rand() function. | |||||
| CVE-2024-53702 | 1 Sonicwall | 10 Sma 200, Sma 200 Firmware, Sma 210 and 7 more | 2026-06-17 | N/A | 5.3 MEDIUM |
| Use of cryptographically weak pseudo-random number generator (PRNG) vulnerability in the SonicWall SMA100 SSLVPN backup code generator that, in certain cases, can be predicted by an attacker, potentially exposing the generated secret. | |||||
| CVE-2024-52322 | 1 Localshop | 1 Webservice\ | 2026-06-17 | N/A | 5.5 MEDIUM |
| WebService::Xero 0.11 and earlier for Perl uses the rand() function as the default source of entropy, which is not cryptographically secure, for cryptographic functions. Specifically WebService::Xero uses the Data::Random library which specifically states that it is "Useful mostly for test programs". Data::Random uses the rand() function. | |||||
| CVE-2024-4772 | 1 Mozilla | 1 Firefox | 2026-06-17 | N/A | 5.9 MEDIUM |
| An HTTP digest authentication nonce value was generated using `rand()` which could lead to predictable values. This vulnerability affects Firefox < 126. | |||||
| CVE-2024-47126 | 1 Gotenna | 1 Gotenna Pro | 2026-06-17 | N/A | 6.5 MEDIUM |
| The goTenna Pro App does not use SecureRandom when generating passwords for sharing cryptographic keys. The random function in use makes it easier for attackers to brute force this password if the broadcasted encryption key is captured over RF. This only applies to the optional broadcast of an encryption key, so it is advised to share the key with local QR code for higher security operations. | |||||
| CVE-2024-45751 | 2026-06-17 | N/A | 5.9 MEDIUM | ||
| tgt (aka Linux target framework) before 1.0.93 attempts to achieve entropy by calling rand without srand. The PRNG seed is always 1, and thus the sequence of challenges is always identical. | |||||
| CVE-2024-45723 | 1 Gotenna | 1 Gotenna | 2026-06-17 | N/A | 6.5 MEDIUM |
| The goTenna Pro ATAK Plugin does not use SecureRandom when generating passwords for sharing cryptographic keys. The random function in use makes it easier for attackers to brute force this password if the broadcasted encryption key is captured over RF. This only applies to the optional broadcast of an encryption key, so it is advised to share the key with local QR code for higher security operations. | |||||
