CWE-203
Observable Discrepancy
The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.
751 vulnerabilities with CWE-203
CVE-2026-67193
MEDIUM
Xlight FTP Server < 3.9.5 Information Disclosure via USER Command
CVSS 5.3
CVE-2026-55555
LOW
Dompdf: File existence oracle via font-face stylesheet declaration
CVE-2026-64713
HIGH
Apple Safari - Denial of Service
CVSS 8.1
CVE-2026-65314
MEDIUM
Electric Postgres Sync Excluded-Column Value Inference via Subset Where Clauses
CVSS 4.3
CVE-2026-47011
LOW
Siebel CRM Deployment 17.0-26.4 - Authenticated Information Disclosure via HTTP with User Interaction
CVSS 2.6
CVE-2026-64822
MEDIUM
djangoSIGE 1.10 User Enumeration via ForgotPasswordView
CVSS 5.3
CVE-2026-56339
HIGH
Capgo - Unauthenticated Organization Existence Enumeration via rescind_invitation RPC
CVSS 7.5
CVE-2026-56296
MEDIUM
Cap-go - App Existence Oracle via Unauthenticated transfer_app RPC
CVSS 5.3
CVE-2026-58503
MEDIUM
Frappe: Unauthenticated User Enumeration via reset_password
CVE-2026-51926
HIGH
docuForm FSM Client 11.11c - User Enumeration via Login Interface Response Timing
CVSS 7.5
CVE-2026-44332
MEDIUM
Fiber: Username Enumeration via Timing Oracle in BasicAuth Default Authorizer
CVSS 5.3
CVE-2026-56327
MEDIUM
Capgo - Unauthenticated Organization Existence Oracle via public.invite_user_to_org RPC
CVSS 5.3
CVE-2026-14112
MEDIUM
Google Chrome < 150.0.7871.47 - Information Disclosure via Crafted HTML Page
CVSS 5.3
CVE-2026-14071
MEDIUM
Google Chrome - Improper Protection of Physical Side Channels
CVSS 6.5
CVE-2026-47379
MEDIUM
NocoDB: Plaintext Password Comparison in Shared Views
CVE-2026-56316
MEDIUM
Cap-go - Job Existence Oracle via Unauthenticated OPTIONS /build/upload/:jobId/*
CVSS 5.3
CVE-2026-56319
MEDIUM
Capgo - App Existence Oracle via GET /statistics/app/:app_id
CVSS 4.3
CVE-2026-11289
MEDIUM
Google Chrome - Improper Protection of Physical Side Channels
CVSS 6.5
CVE-2026-11284
MEDIUM
Google Chrome - Improper Protection of Physical Side Channels
CVSS 6.5
CVE-2026-45294
MEDIUM
FreeScout: User Account Enumeration via Password Reset Response Differentiation
CVSS 5.3
CVE-2026-45410
MEDIUM
Time-based user enumeration in TREK authentication endpoint
CVSS 5.3
CVE-2026-8242
LOW
Industrial Application Software IAS Canias ERP Login RMI doAction response discrepancy
CVSS 3.7
CVE-2026-41588
CRITICAL
RELATE: Timing Attack Vulnerability in course/auth.py — check_sign_in_key()
CVSS 9.0
CVE-2026-44263
MEDIUM
Weblate: Private Translation Enumeration via Screenshot API
CVSS 4.3
CVE-2026-26895
MEDIUM
osTicket < 1.18.3 - User Enumeration via Password Reset Endpoint
CVSS 5.3
Details
Vulnerabilities
751