CWE-330


Use of Insufficiently Random Values

The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.


We have discovered 293 live websites that are affected by CWE-330.

Contact us to get more info









CVEs

  • Count - 6



Website Distribution by Country

Number of websites using CWE-330
United States71 websites



Germany60 websites
France43 websites
Netherlands12 websites
Hungary9 websites
Switzerland8 websites
GB8 websites
Poland7 websites
Austria6 websites
Australia5 websites

Website Distribution by TLD

Number of websites using CWE-330
.com92 websites
.de36 websites
.net22 websites
.org21 websites
.fr15 websites
.nl11 websites
.eu8 websites
.at7 websites
.ch6 websites
.co.uk4 websites

Newest CVEs

List of the most recent CVEs that are part of CWE-330
DiscoveredCVEDescriptionWebsites
Apr, 2026CVE-2026-33710 Chamilo LMS has Weak REST API Key Generation (Predictable)9
Feb, 2026CVE-2024-48928 Piwigo's secret key can be brute forced220
Nov, 2025CVE-2025-12787 Hydra Booking – All in One Appointment Booking System | Appointment Scheduling, Booking Calendar & WooCommerce Bookings <= 1.1.27 - Unauthenticated Arbitrary Booking Cancellation via Weak Hash Generation52
Dec, 2024CVE-2024-12432 WPC Shop as a Customer for WooCommerce <= 1.2.8 - Authentication Bypass Due to Insufficiently Unique Key4
Jun, 2024CVE-2024-5149 BuddyForms <= 2.8.9 - Email Verification Bypass due to Insufficient Randomness3
Mar, 2023CVE-2022-39216 Combodo iTop's weak password reset token leads to account takeover5
List of the most common CVEs that are part of CWE-330
DiscoveredCVEDescriptionWebsites
Feb, 2026CVE-2024-48928 Piwigo's secret key can be brute forced220
Nov, 2025CVE-2025-12787 Hydra Booking – All in One Appointment Booking System | Appointment Scheduling, Booking Calendar & WooCommerce Bookings <= 1.1.27 - Unauthenticated Arbitrary Booking Cancellation via Weak Hash Generation52
Apr, 2026CVE-2026-33710 Chamilo LMS has Weak REST API Key Generation (Predictable)9
Mar, 2023CVE-2022-39216 Combodo iTop's weak password reset token leads to account takeover5
Dec, 2024CVE-2024-12432 WPC Shop as a Customer for WooCommerce <= 1.2.8 - Authentication Bypass Due to Insufficiently Unique Key4
Jun, 2024CVE-2024-5149 BuddyForms <= 2.8.9 - Email Verification Bypass due to Insufficient Randomness3

Websites affected by CWE-330

Top websites that are affected by CWE-330. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***************.de Germany***,***
*********.com United States*,***,***
******.*********.com Germany*,***,***
*******.**.**.ke Kenya*,***,***
**.******.gt United States*,***,***
**********.******.eu France*,***,***
**********.fr France*,***,***
***********.com France*,***,***
*****.******.su Russia*,***,***
**************.at Germany*,***,***
See full domain list