CWE-203

Observable Discrepancy

Parent: CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor

The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.

751 vulnerabilities with CWE-203
CVE-2025-6386 HIGH
parisneo/lollms < 20.1 - Timing Attack via Password Comparison in authenticate_user
CVSS 7.5
CVE-2025-6056 MEDIUM
Ergon Informatik AG's Airlock IAM <8.3.1 - Info Disclosure
CVE-2025-27451 MEDIUM
Endress meac300-fnade4 Firmware <= 0.16.0 - Username Enumeration via Different Error Messages
CVSS 5.3
CVE-2025-40732 HIGH
Daily Expense Manager 1.0 - User Enumeration via /check.php Name Parameter
CVSS 7.5
CVE-2025-52576 MEDIUM
Kanboard < 1.2.46 - Username Enumeration and Brute-Force Protection Bypass via HTTP Header Spoofing
CVSS 5.3
CVE-2025-46570 LOW
vllm < 0.9.0 - Observable Timing Discrepancy in PageAttention Prefill
CVSS 2.6
CVE-2025-46804 LOW
Screen 5.0.0 - Unauthenticated Information Disclosure via Setuid Path Leak
CVSS 3.3
CVE-2025-23182 MEDIUM
UBtech Freepass - Observable Discrepancy
CVSS 4.3
CVE-2025-3939 MEDIUM
Tridium Niagara Framework and Enterprise Security < 4.14.2, < 4.15.1, < 4.10.11 - Observable Response Discrepancy
CVSS 5.3
CVE-2025-46720 LOW
Keystone < 6.5.0 - Unauthorized Information Exposure via Update and Delete Mutation Filters
CVSS 3.1
CVE-2025-32789 LOW
EspoCRM < 9.0.7 - Exposure of Sensitive Information via User Password Hash Sorting
CVSS 3.1
CVE-2025-0361 MEDIUM
Axis Communications - Info Disclosure
CVSS 4.3
CVE-2025-31124 MEDIUM
zitadel < 2.63.9 - Username Enumeration via Normalization Bypass
CVSS 5.3
CVE-2025-30344 MEDIUM
OpenSlides <4.2.5 - Info Disclosure
CVSS 5.3
CVE-2025-1468 HIGH
CODESYS OPC UA Server - Info Disclosure
CVSS 7.5
CVE-2025-29780 MEDIUM
Post-Quantum Secure Feldman's Verifiable Secret Sharing <0.8.0b2 - ...
CVE-2025-27667 CRITICAL
Vasion Print < 20.0.1923 and Virtual Appliance < 22.0.843 - Administrative User Email Enumeration
CVSS 9.8
CVE-2025-24023 LOW
Flask-AppBuilder < 4.5.3 - Unauthenticated Username Enumeration via Timing Attack
CVSS 3.7
CVE-2025-24506 MEDIUM
Broadcom Symantec Privileged Access Management 3.4.6-4.1.7 and 4.2.0 - User ID Disclosure via Authentication Strategy
CVE-2025-21510 HIGH
Oracle JD Edwards EnterpriseOne Tools < 9.2.9.0 - Unauthenticated Unauthorized Data Access via Web Runtime SEC
CVSS 7.5
CVE-2025-24011 MEDIUM
Umbraco CMS 14.0.0-14.3.1 - Unauthenticated User Enumeration via Management API Response Analysis
CVSS 5.3
CVE-2025-21336 MEDIUM
Windows 10 1507-22H2, Windows 11 22H2-24H2, Windows Server 2008 - Cryptographic Information Disclosure
CVSS 5.6
CVE-2024-55374 MEDIUM
REDCap 14.3.13 - Username Enumeration via Login Discrepancy
CVSS 5.3
CVE-2024-47057 MEDIUM
Mautic - Unauthenticated Username Enumeration via Timing Attack in Password Reset
CVSS 5.3
CVE-2024-11084 MEDIUM
Helix ALM <2025.1 - Info Disclosure
Details
Vulnerabilities 751