CVEs classified under CWE-1241, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (7)
CVE-2023-4695 — CVSS 8.1 (high): Use of Predictable Algorithm in Random Number Generator in GitHub repository pkp/pkp-lib prior to 3.3.0-16.
CVE-2026-82190: Joomla Extension - j2commerce.com - Predictable/forgeable order access token in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 - Anyone who…
CVE-2026-73576 — CVSS 6.3 (medium): In Zimbra Collaboration (ZCS) before 10.1.17, weak cryptographic key generation vulnerability exists in the OnlyOffice integration. The…
CVE-2026-6420 — CVSS 6.3 (medium): A flaw was found in Keylime. An attacker with root access on an enrolled monitored machine, where the Keylime agent runs, can exploit a…
CVE-2026-82191: Joomla Extension - j2commerce.com - Unescaped request data reflected into PayPal notify redirect in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22…
CVE-2025-13079 — CVSS 5.3 (medium): The Popup Builder – Create highly converting, mobile friendly marketing popups. plugin for WordPress is vulnerable to authorization…
CVE-2025-32056 — CVSS 4.0 (medium): The anti-theft protection mechanism can be bypassed by attackers due to weak response generation algorithms for the head unit. It is…