CWE-203
Observable Discrepancy
The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.
751 vulnerabilities with CWE-203
CVE-2025-6386
HIGH
parisneo/lollms < 20.1 - Timing Attack via Password Comparison in authenticate_user
CVSS 7.5
CVE-2025-6056
MEDIUM
Ergon Informatik AG's Airlock IAM <8.3.1 - Info Disclosure
CVE-2025-27451
MEDIUM
Endress meac300-fnade4 Firmware <= 0.16.0 - Username Enumeration via Different Error Messages
CVSS 5.3
CVE-2025-40732
HIGH
Daily Expense Manager 1.0 - User Enumeration via /check.php Name Parameter
CVSS 7.5
CVE-2025-52576
MEDIUM
Kanboard < 1.2.46 - Username Enumeration and Brute-Force Protection Bypass via HTTP Header Spoofing
CVSS 5.3
CVE-2025-46570
LOW
vllm < 0.9.0 - Observable Timing Discrepancy in PageAttention Prefill
CVSS 2.6
CVE-2025-46804
LOW
Screen 5.0.0 - Unauthenticated Information Disclosure via Setuid Path Leak
CVSS 3.3
CVE-2025-23182
MEDIUM
UBtech Freepass - Observable Discrepancy
CVSS 4.3
CVE-2025-3939
MEDIUM
Tridium Niagara Framework and Enterprise Security < 4.14.2, < 4.15.1, < 4.10.11 - Observable Response Discrepancy
CVSS 5.3
CVE-2025-46720
LOW
Keystone < 6.5.0 - Unauthorized Information Exposure via Update and Delete Mutation Filters
CVSS 3.1
CVE-2025-32789
LOW
EspoCRM < 9.0.7 - Exposure of Sensitive Information via User Password Hash Sorting
CVSS 3.1
CVE-2025-0361
MEDIUM
Axis Communications - Info Disclosure
CVSS 4.3
CVE-2025-31124
MEDIUM
zitadel < 2.63.9 - Username Enumeration via Normalization Bypass
CVSS 5.3
CVE-2025-30344
MEDIUM
OpenSlides <4.2.5 - Info Disclosure
CVSS 5.3
CVE-2025-1468
HIGH
CODESYS OPC UA Server - Info Disclosure
CVSS 7.5
CVE-2025-29780
MEDIUM
Post-Quantum Secure Feldman's Verifiable Secret Sharing <0.8.0b2 - ...
CVE-2025-27667
CRITICAL
Vasion Print < 20.0.1923 and Virtual Appliance < 22.0.843 - Administrative User Email Enumeration
CVSS 9.8
CVE-2025-24023
LOW
Flask-AppBuilder < 4.5.3 - Unauthenticated Username Enumeration via Timing Attack
CVSS 3.7
CVE-2025-24506
MEDIUM
Broadcom Symantec Privileged Access Management 3.4.6-4.1.7 and 4.2.0 - User ID Disclosure via Authentication Strategy
CVE-2025-21510
HIGH
Oracle JD Edwards EnterpriseOne Tools < 9.2.9.0 - Unauthenticated Unauthorized Data Access via Web Runtime SEC
CVSS 7.5
CVE-2025-24011
MEDIUM
Umbraco CMS 14.0.0-14.3.1 - Unauthenticated User Enumeration via Management API Response Analysis
CVSS 5.3
CVE-2025-21336
MEDIUM
Windows 10 1507-22H2, Windows 11 22H2-24H2, Windows Server 2008 - Cryptographic Information Disclosure
CVSS 5.6
CVE-2024-55374
MEDIUM
REDCap 14.3.13 - Username Enumeration via Login Discrepancy
CVSS 5.3
CVE-2024-47057
MEDIUM
Mautic - Unauthenticated Username Enumeration via Timing Attack in Password Reset
CVSS 5.3
CVE-2024-11084
MEDIUM
Helix ALM <2025.1 - Info Disclosure
Details
Vulnerabilities
751