Cyber Posture

CWE · MITRE source

CWE-330Use of Insufficiently Random Values

Abstraction: Class · CVEs in our corpus: 366

The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.

Last updated: 09 May 2026 03:25 UTC

NIST 800-53 r5 controls that address this weakness (1)AI

Control Title Family Why it addresses this CWE
SC-12Cryptographic Key Establishment and ManagementSCKey generation under controlled management uses approved random-bit sources rather than insufficiently random values.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2019-54207.69.80.93752019-03-27
CVE-2008-00874.87.50.55742008-04-08
CVE-2022-365364.89.80.48012022-09-16
CVE-2018-178884.49.80.40732018-10-12
CVE-2020-119013.59.00.29012020-06-17
CVE-2021-346463.39.80.22512021-08-30
CVE-2017-60262.99.10.18572017-06-30
CVE-2008-24332.79.80.12312008-08-27
CVE-2021-404222.710.00.11042022-04-14
CVE-2023-293322.47.50.14612023-09-12
CVE-2019-98982.29.80.04292019-03-21
CVE-2019-76672.29.80.03652019-07-01
CVE-2019-151302.29.80.03362019-08-18
CVE-2020-115012.27.40.11492020-04-03
CVE-2008-36122.19.80.02522008-09-11
CVE-2017-169242.19.80.01732018-02-19
CVE-2021-272002.19.80.03052021-06-11
CVE-2022-257522.19.80.03112022-04-12
CVE-2022-463532.19.80.01992022-12-13
CVE-2016-51002.09.80.00292017-02-13
CVE-2017-79022.09.80.00042017-06-30
CVE-2017-79052.09.80.00202017-06-30
CVE-2017-170912.08.80.04482017-12-02
CVE-2018-162392.09.80.00422018-08-30
CVE-2018-183752.09.80.00342018-10-16