CWE-203

Observable Discrepancy

Parent: CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor

The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.

733 vulnerabilities with CWE-203
CVE-2026-11289 MEDIUM
Google Chrome - Improper Protection of Physical Side Channels
CVSS 6.5
CVE-2026-11284 MEDIUM
Google Chrome - Improper Protection of Physical Side Channels
CVSS 6.5
CVE-2026-45294 MEDIUM
FreeScout: User Account Enumeration via Password Reset Response Differentiation
CVSS 5.3
CVE-2026-45410 MEDIUM
Time-based user enumeration in TREK authentication endpoint
CVSS 5.3
CVE-2026-8242 LOW
Industrial Application Software IAS Canias ERP Login RMI doAction response discrepancy
CVSS 3.7
CVE-2026-41588 CRITICAL
RELATE: Timing Attack Vulnerability in course/auth.py — check_sign_in_key()
CVSS 9.0
CVE-2026-44263 MEDIUM
Weblate: Private Translation Enumeration via Screenshot API
CVSS 4.3
CVE-2026-26895 MEDIUM
osTicket < 1.18.3 - User Enumeration via Password Reset Endpoint
CVSS 5.3
CVE-2026-33429 MEDIUM
Parse Server: Protected field change detection oracle via LiveQuery watch parameter
CVSS 5.3
CVE-2026-33425 MEDIUM
Discourse has inferable private group membership or existence via exclude_groups parameter
CVSS 5.3
CVE-2026-3580 LOW
Compiler-induced timing leak in sp_256_get_entry_256_9 on RISC-V
CVE-2026-3579 LOW
Non-constant time multiplication subroutine __muldi3 on RISC-V RV32I
CVE-2026-28490 MEDIUM
Authlib Vulnerable to JWE RSA1_5 Bleichenbacher Padding Oracle
CVSS 6.5
CVE-2026-21386 MEDIUM
Private channel enumeration via /mute slash command
CVSS 4.3
CVE-2026-4045 LOW
projectsend r1945 - Info Disclosure
CVSS 3.7
CVE-2026-4040 LOW
OpenClaw <2026.2.17 - Info Disclosure
CVSS 3.3
CVE-2026-26315 HIGH
go-ethereum <1.16.9 - Info Disclosure
CVSS 7.5
CVE-2026-23621 MEDIUM
GFI MailEssentials AI <22.4 - Info Disclosure
CVSS 4.3
CVE-2026-23620 MEDIUM
GFI MailEssentials AI <22.4 - Info Disclosure
CVSS 4.3
CVE-2026-26185 MEDIUM
Directus < 11.14.1 - Timing-Based User Enumeration via Password Reset
CVSS 5.3
CVE-2026-25562 MEDIUM
WeKan < 8.19 - Unauthorized Attachment Metadata Exposure via Attachments Publication
CVSS 4.3
CVE-2026-25509 MEDIUM
Ci4-cms-erp Ci4ms < 0.28.5.0 - Information Disclosure
CVSS 5.3
CVE-2026-23849 MEDIUM
File Browser <2.55.0 - Info Disclosure
CVSS 5.3
CVE-2026-23519 CRITICAL
RustCrypto CMOV <0.4.4 - Info Disclosure
CVSS 9.8
CVE-2026-21484 MEDIUM
AnythingLLM <e287fab56089cf8fcea9ba579a3ecdeca0daa313 - Info Disclo...
CVSS 5.3
Details
Vulnerabilities 733