| 2026-08-07 | CVE-2026-71851 | crypto-js: Insufficient Entropy in Cryptographic Secret Generation via Vulnerable CryptoJS Dependency Chain | crypto-js | critical | entropy | Advisory → |
| 2026-05-08 | CVE-2026-44714 | bitcoinj has a ScriptExecution P2PKH/P2WPKH Verification Bypass | org.bitcoinj:bitcoinj-core | high | entropy | Advisory → |
| 2026-04-23 | CVE-2026-41564 | CryptX versions before 0.088 for Perl do not reseed the Crypt::PK PRNG state after forking. | | high | entropy | Advisory → |
| 2026-04-14 | CVE-2025-69893 | A side-channel vulnerability exists in the implementation of BIP-39 mnemonic processing, as observed in Trezor One v1.13.0 to v1.14.0, Trezor T v1.13.0 to v1.14.0, and Trezor Safe | | medium | broader | Advisory → |
| 2026-03-27 | CVE-2026-33936 | python-ecdsa: Denial of Service via improper DER length validation in crafted private keys | ecdsaecdsa | medium | entropy | Advisory → |
| 2026-03-23 | CVE-2026-4599 | Versions of the package jsrsasign from 7.0.0 and before 11.1.1 are vulnerable to Incomplete Comparison with Missing Factors via the getRandomBigIntegerZeroToMax and getRandomBigInt | | critical | entropy | Advisory → |
| 2026-01-08 | CVE-2025-14505 | Elliptic Uses a Cryptographic Primitive with a Risky Implementation | elliptic | medium | entropy | Advisory → |
| 2025-02-12 | GHSA-vjh7-7g9h-fjfh | Elliptic's private key extraction in ECDSA upon signing a malformed input (e.g. a string) | elliptic | critical | entropy | Advisory → |
| 2024-12-04 | CVE-2024-54134 | Modified package published to npm, containing malware that exfiltrates private key material | @solana/web3.js | high | entropy | Advisory → |
| 2024-12-03 | GHSA-2mhj-xmf4-pr8m | Malicious code in @solana/web3.js (npm) | @solana/web3.js | unknown | entropy | Advisory → |
| 2024-10-21 | CVE-2024-48930 | secp256k1-node allows private key extraction over ECDH | secp256k1 | high | entropy | Advisory → |
| 2024-10-15 | CVE-2024-48948 | Valid ECDSA signatures erroneously rejected in Elliptic | elliptic | medium | entropy | Advisory → |
| 2024-10-10 | CVE-2024-38365 | btcd did not correctly re-implement Bitcoin Core's "FindAndDelete()" functionality | github.com/btcsuite/btcd | high | entropy | Advisory → |
| 2024-10-10 | CVE-2024-48949 | Elliptic's verify function omits uniqueness validation | elliptic | medium | entropy | Advisory → |
| 2024-08-02 | CVE-2024-42459 | Elliptic's EDDSA missing signature length check | elliptic | medium | entropy | Advisory → |
| 2024-08-02 | CVE-2024-42461 | Elliptic allows BER-encoded signatures | elliptic | medium | entropy | Advisory → |
| 2024-08-02 | CVE-2024-42460 | Elliptic's ECDSA missing check for whether leading bit of r and s is zero | elliptic | medium | entropy | Advisory → |
| 2024-05-05 | CVE-2024-34478 | btcd susceptible to consensus failures | github.com/btcsuite/btcd | medium | entropy | Advisory → |
| 2024-04-17 | CVE-2024-30253 | Handling untrusted input can result in a crash, leading to loss of availability / denial of service | @solana/web3.js | high | entropy | Advisory → |
| 2024-04-15 | CVE-2024-31497 | In PuTTY 0.68 through 0.80 before 0.81, biased ECDSA nonce generation allows an attacker to recover a user's NIST P-521 secret key via a quick attack in approximately 60 signatures | | medium | entropy | Advisory → |
| 2024-02-21 | CVE-2024-1631 | Impact: The library offers a function to generate an ed25519 key pair via Ed25519KeyIdentity.generate with an optional param to provide a 32 byte seed value, which will then be use | | critical | entropy | Advisory → |
| 2024-02-08 | CVE-2024-23660 | The Binance Trust Wallet app for iOS in commit 3cd6e8f647fbba8b5d8844fcd144365a086b629f, git tag 0.0.4 misuses the trezor-crypto library and consequently generates mnemonic words f | | high | entropy | Advisory → |
| 2024-01-22 | CVE-2024-23342 | Minerva timing attack on P-256 in python-ecdsa | ecdsaecdsa | high | entropy | Advisory → |
| 2024-01-19 | CVE-2024-23688 | Consensys Discovery versions less than 0.4.5 uses the same AES/GCM nonce for the entire session. | | medium | entropy | Advisory → |
| 2023-10-25 | CVE-2023-46233 | crypto-js PBKDF2 1,000 times weaker than specified in 1993 and 1.3M times weaker than current standard | crypto-js | critical | entropy | Advisory → |
| 2023-08-09 | CVE-2023-39910 | The cryptocurrency wallet entropy seeding mechanism used in Libbitcoin Explorer 3.0.0 through 3.6.0 is weak, aka the Milk Sad issue. | | high | entropy | Advisory → |
| 2023-06-12 | CVE-2020-36732 | crypto-js uses insecure random numbers | crypto-js | medium | entropy | Advisory → |
| 2023-06-09 | CVE-2023-34363 | An issue was discovered in Progress DataDirect Connect for ODBC before 08.02.2770 for Oracle. | | medium | entropy | Advisory → |
| 2023-04-27 | CVE-2023-31290 | Trust Wallet Core before 3.1.1, as used in the Trust Wallet browser extension before 0.0.183, allows theft of funds because the entropy is 32 bits, as exploited in the wild in Dece | | medium | entropy | Advisory → |
| 2023-03-23 | CVE-2023-20107 | A vulnerability in the deterministic random bit generator (DRBG), also known as pseudorandom number generator (PRNG), in Cisco Adaptive Security Appliance (ASA) Software and Cisco | | high | entropy | Advisory → |
| 2022-11-07 | CVE-2022-44797 | btcd mishandles witness size checking | github.com/lightningnetwork/lndgithub.com/btcsuite/btcd | critical | entropy | Advisory → |
| 2022-09-20 | CVE-2022-34746 | An insufficient entropy vulnerability caused by the improper use of randomness sources with low entropy for RSA key pair generation was found in Zyxel GS1900 series firmware versio | | medium | entropy | Advisory → |
| 2022-09-18 | CVE-2022-40769 | profanity through 1.60 has only four billion possible RNG initializations. | | high | entropy | Advisory → |
| 2022-06-29 | CVE-2022-32969 | MetaMask before 10.11.3 might allow an attacker to access a user's secret recovery phrase because an input field is used for a BIP39 mnemonic, and Firefox and Chromium save such fi | | medium | broader | Advisory → |
| 2022-03-08 | CVE-2022-26317 | A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.29). | | medium | entropy | Advisory → |
| 2022-03-01 | CVE-2021-36171 | The use of a cryptographically weak pseudo-random number generator in the password reset feature of FortiPortal before 6.0.6 may allow a remote unauthenticated attacker to predict | | high | entropy | Advisory → |
| 2021-11-16 | CVE-2021-26322 | Persistent platform private key may not be protected with a random IV leading to a potential “two time pad attack”. | | high | entropy | Advisory → |
| 2021-02-02 | CVE-2020-28498 | Elliptic Uses a Broken or Risky Cryptographic Algorithm | elliptic | medium | entropy | Advisory → |
| 2020-07-29 | CVE-2020-13822 | Signature Malleabillity in elliptic | elliptic | high | entropy | Advisory → |
| 2020-06-16 | CVE-2020-14199 | BIP-143 in the Bitcoin protocol specification mishandles the signing of a Segwit transaction, which allows attackers to trick a user into making two signatures in certain cases, po | | medium | broader | Advisory → |
| 2020-01-02 | CVE-2019-14859 | Improper Verification of Cryptographic Signature in Pure-Python ECDSA | ecdsaecdsa | critical | entropy | Advisory → |
| 2019-12-11 | CVE-2019-14317 | wolfSSL and wolfCrypt 4.1.0 and earlier (formerly known as CyaSSL) generate biased DSA nonces. | | medium | entropy | Advisory → |
| 2019-11-02 | CVE-2019-18673 | On SHIFT BitBox02 devices, a side channel for the row-based OLED display was found. | | medium | broader | Advisory → |
| 2019-10-31 | CVE-2019-14356 | On Coldcard MK1 and MK2 devices, a side channel for the row-based OLED display was found. | | medium | broader | Advisory → |
| 2019-10-08 | CVE-2019-14853 | ecdsa Denial of Service vulnerability in signature verification and signature malleability | ecdsaecdsa | high | entropy | Advisory → |
| 2019-08-10 | CVE-2019-14354 | On Ledger Nano S and Nano X devices, a side channel for the row-based OLED display was found. | | low | broader | Advisory → |
| 2019-08-08 | CVE-2019-14353 | On Trezor One devices before 1.8.2, a side channel for the row-based OLED display was found. | | medium | broader | Advisory → |
| 2019-07-16 | CVE-2019-13603 | An issue was discovered in the HID Global DigitalPersona (formerly Crossmatch) U.are.U 4500 Fingerprint Reader Windows Biometric Framework driver 5.0.0.5. | | medium | entropy | Advisory → |
| 2019-05-03 | CVE-2019-1715 | A vulnerability in the Deterministic Random Bit Generator (DRBG), also known as Pseudorandom Number Generator (PRNG), used in Cisco Adaptive Security Appliance (ASA) Software and C | | high | entropy | Advisory → |
| 2018-12-09 | CVE-2018-19983 | An issue was discovered on Sigma Design Z-Wave S0 through S2 devices. | | medium | entropy | Advisory → |