CWE-203

Observable Discrepancy

Parent: CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor

The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.

751 vulnerabilities with CWE-203
CVE-2026-33429 MEDIUM
Parse Server: Protected field change detection oracle via LiveQuery watch parameter
CVSS 5.3
CVE-2026-33425 MEDIUM
Discourse has inferable private group membership or existence via exclude_groups parameter
CVSS 5.3
CVE-2026-3580 MEDIUM
Compiler-induced timing leak in sp_256_get_entry_256_9 on RISC-V
CVSS 4.7
CVE-2026-3579 MEDIUM
Non-constant time multiplication subroutine __muldi3 on RISC-V RV32I
CVSS 5.9
CVE-2026-28490 MEDIUM
Authlib Vulnerable to JWE RSA1_5 Bleichenbacher Padding Oracle
CVSS 6.5
CVE-2026-21386 MEDIUM
Private channel enumeration via /mute slash command
CVSS 4.3
CVE-2026-4045 LOW
projectsend r1945 - Info Disclosure
CVSS 3.7
CVE-2026-4040 LOW
OpenClaw <2026.2.17 - Info Disclosure
CVSS 3.3
CVE-2026-26315 HIGH
go-ethereum <1.16.9 - Info Disclosure
CVSS 7.5
CVE-2026-23621 MEDIUM
GFI MailEssentials AI <22.4 - Info Disclosure
CVSS 4.3
CVE-2026-23620 MEDIUM
GFI MailEssentials AI <22.4 - Info Disclosure
CVSS 4.3
CVE-2026-26185 MEDIUM
Directus < 11.14.1 - Timing-Based User Enumeration via Password Reset
CVSS 5.3
CVE-2026-25562 MEDIUM
WeKan < 8.19 - Unauthorized Attachment Metadata Exposure via Attachments Publication
CVSS 4.3
CVE-2026-25509 MEDIUM
Ci4-cms-erp Ci4ms < 0.28.5.0 - Information Disclosure
CVSS 5.3
CVE-2026-23849 MEDIUM
File Browser <2.55.0 - Info Disclosure
CVSS 5.3
CVE-2026-23519 CRITICAL
RustCrypto CMOV <0.4.4 - Info Disclosure
CVSS 9.8
CVE-2026-21484 MEDIUM
AnythingLLM <e287fab56089cf8fcea9ba579a3ecdeca0daa313 - Info Disclo...
CVSS 5.3
CVE-2025-67806 LOW
Sage DPW <2021_06_000 - Info Disclosure
CVSS 3.7
CVE-2025-65185 LOW
Entrinsik Informer 5.10.1 - Username Enumeration via Local User Login
CVSS 2.8
CVE-2025-68164 LOW
JetBrains TeamCity < 2025.11 - Port Enumeration via Perforce Connection Test
CVSS 2.7
CVE-2025-13912 LOW
wolfSSL < 5.8.4 - Timing Side-Channel Information Disclosure via LLVM Optimization
CVE-2025-63094 HIGH
XiangShan Nanhu V2 and Kunmighu V3 - Exposure of Sensitive Information via Speculative Execution Side-Channel
CVSS 7.5
CVE-2025-39665 MEDIUM
Nagvis < 1.9.48 - Unauthenticated User Enumeration via Checkmk MultisiteAuth
CVSS 5.3
CVE-2025-59702 HIGH
Entrust nShield HSM <13.6.12 Authenticated Tamper Event Falsification
CVSS 7.2
CVE-2025-56423 MEDIUM
OpenAtlas < 8.12.1 - User Enumeration via Login Error Messages
CVSS 5.3
Details
Vulnerabilities 751