CWE-203

Observable Discrepancy

Parent: CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor

The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.

751 vulnerabilities with CWE-203
CVE-2025-12888 HIGH
Xtensa-based ESP32 - Timing Side Channel
CVSS 7.5
CVE-2025-11932 MEDIUM
wolfssl - Timing Side-Channel in TLS 1.3 PSK Binder Verification
CVSS 4.3
CVE-2025-64749 MEDIUM
Directus < 11.13.0 - Information Disclosure via Collection Existence Error Messages
CVSS 4.3
CVE-2025-59716 MEDIUM
owncloud guests < 0.12.4 - Unauthenticated User Enumeration via Registration Endpoint
CVSS 5.3
CVE-2025-11145 HIGH
CBK Soft Software Hardware Electronic Computer Systems Industry and...
CVSS 7.5
CVE-2025-36225 MEDIUM
IBM Aspera Faspex 5.0.0-5.0.13.1 - Authenticated Sensitive Information Disclosure via Observable Discrepancy
CVSS 4.3
CVE-2025-11443 LOW
JhumanJ OpnForm <1.9.3 - Info Disclosure
CVSS 3.7
CVE-2025-54477 MEDIUM
Passkey <unknown> - Info Disclosure
CVSS 5.3
CVE-2025-41252 HIGH
VMware NSX 9.x, 4.2.x, 4.1.x, 4.0.x; NSX-T 3.x; Cloud Foundation 5.x, 4.5.x - Unauthenticated Username Enumeration
CVSS 7.5
CVE-2025-1396 LOW
WSO2 Identity Server - Username Enumeration via Multi-Attribute Login Error Messages
CVSS 3.7
CVE-2025-10890 CRITICAL
Google Chrome < 140.0.7339.207 - Side-Channel Information Leakage in V8
CVSS 9.1
CVE-2025-9031 MEDIUM
DivvyDrive Web 4.8.2.2-4.8.2.14 - Observable Timing Discrepancy via Cross-Domain Search
CVSS 4.3
CVE-2025-43786 MEDIUM
Liferay Digital Experience Platform 2024.Q1.1-2024.Q1.12 - Information Disclosure via ERC Enumeration
CVSS 5.3
CVE-2025-39702 CRITICAL
Linux Kernel - Observable Timing Discrepancy in IPv6 Segment Routing MAC Comparison
CVSS 9.8
CVE-2025-48561 MEDIUM
Multiple Locations - Info Disclosure
CVSS 5.5
CVE-2025-57770 MEDIUM
Zitadel < 2.71.15 - Unauthenticated Username Enumeration via Select Account Page
CVSS 5.3
CVE-2025-43751 MEDIUM
Liferay Portal 7.4.0-7.4.3.132 & DXP 2023.Q3.1-2024.Q4.7 User Enumeration via Create Account
CVSS 5.3
CVE-2025-43743 MEDIUM
Liferay Portal 7.4.0-7.4.3.132 & DXP Authenticated User Enumeration via Calendar Access
CVSS 4.3
CVE-2025-43739 MEDIUM
Liferay Portal/DXP Email Content Modification via Calendar Portlet
CVSS 4.3
CVE-2025-9109 LOW
Portabilis i-Diario <1.5.0 - Info Disclosure
CVSS 3.7
CVE-2025-8774 LOW
riscv-boom SonicBOOM <2.2.3 - Info Disclosure
CVSS 2.5
CVE-2025-54999 LOW
OpenBao 0.1.0-2.3.1 - User Enumeration via Userpass Auth Timing Side Channel
CVSS 3.7
CVE-2025-47872 MEDIUM
Product Registration - Info Disclosure
CVSS 5.8
CVE-2025-6011 LOW
HashiCorp Vault < 1.20.1 and 1.16.23 - Timing Side Channel in Userpass Auth Method
CVSS 3.7
CVE-2025-24391 MEDIUM
OTRS 7.0.x 8.0.x 2023.x 2024.x 2025.x - User Enumeration via External Interface Response Discrepancy
CVSS 5.3
Details
Vulnerabilities 751