CWE-203

Observable Discrepancy

Parent: CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor

The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.

751 vulnerabilities with CWE-203
CVE-2026-67193 MEDIUM
Xlight FTP Server < 3.9.5 Information Disclosure via USER Command
CVSS 5.3
CVE-2026-55555 LOW
Dompdf: File existence oracle via font-face stylesheet declaration
CVE-2026-64713 HIGH
Apple Safari - Denial of Service
CVSS 8.1
CVE-2026-65314 MEDIUM
Electric Postgres Sync Excluded-Column Value Inference via Subset Where Clauses
CVSS 4.3
CVE-2026-47011 LOW
Siebel CRM Deployment 17.0-26.4 - Authenticated Information Disclosure via HTTP with User Interaction
CVSS 2.6
CVE-2026-64822 MEDIUM
djangoSIGE 1.10 User Enumeration via ForgotPasswordView
CVSS 5.3
CVE-2026-56339 HIGH
Capgo - Unauthenticated Organization Existence Enumeration via rescind_invitation RPC
CVSS 7.5
CVE-2026-56296 MEDIUM
Cap-go - App Existence Oracle via Unauthenticated transfer_app RPC
CVSS 5.3
CVE-2026-58503 MEDIUM
Frappe: Unauthenticated User Enumeration via reset_password
CVE-2026-51926 HIGH
docuForm FSM Client 11.11c - User Enumeration via Login Interface Response Timing
CVSS 7.5
CVE-2026-44332 MEDIUM
Fiber: Username Enumeration via Timing Oracle in BasicAuth Default Authorizer
CVSS 5.3
CVE-2026-56327 MEDIUM
Capgo - Unauthenticated Organization Existence Oracle via public.invite_user_to_org RPC
CVSS 5.3
CVE-2026-14112 MEDIUM
Google Chrome < 150.0.7871.47 - Information Disclosure via Crafted HTML Page
CVSS 5.3
CVE-2026-14071 MEDIUM
Google Chrome - Improper Protection of Physical Side Channels
CVSS 6.5
CVE-2026-47379 MEDIUM
NocoDB: Plaintext Password Comparison in Shared Views
CVE-2026-56316 MEDIUM
Cap-go - Job Existence Oracle via Unauthenticated OPTIONS /build/upload/:jobId/*
CVSS 5.3
CVE-2026-56319 MEDIUM
Capgo - App Existence Oracle via GET /statistics/app/:app_id
CVSS 4.3
CVE-2026-11289 MEDIUM
Google Chrome - Improper Protection of Physical Side Channels
CVSS 6.5
CVE-2026-11284 MEDIUM
Google Chrome - Improper Protection of Physical Side Channels
CVSS 6.5
CVE-2026-45294 MEDIUM
FreeScout: User Account Enumeration via Password Reset Response Differentiation
CVSS 5.3
CVE-2026-45410 MEDIUM
Time-based user enumeration in TREK authentication endpoint
CVSS 5.3
CVE-2026-8242 LOW
Industrial Application Software IAS Canias ERP Login RMI doAction response discrepancy
CVSS 3.7
CVE-2026-41588 CRITICAL
RELATE: Timing Attack Vulnerability in course/auth.py — check_sign_in_key()
CVSS 9.0
CVE-2026-44263 MEDIUM
Weblate: Private Translation Enumeration via Screenshot API
CVSS 4.3
CVE-2026-26895 MEDIUM
osTicket < 1.18.3 - User Enumeration via Password Reset Endpoint
CVSS 5.3
Details
Vulnerabilities 751