CWE-203
Observable Discrepancy
The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.
751 vulnerabilities with CWE-203
CVE-2024-11297
MEDIUM
Page Restriction WordPress < 1.3.6 - Unauthenticated Sensitive Information Exposure via WordPress Core Search
CVSS 5.3
CVE-2024-12663
LOW
Mee-Admin <= 1.6 - Observable Response Discrepancy via Login Username Parameter
CVSS 3.7
CVE-2024-54476
MEDIUM
macOS < 13.7.2, < 14.7.2, < 15.2 - Unprotected User Data Exposure
CVSS 5.5
CVE-2024-54002
MEDIUM
DependencyTrack < 4.12.2 - Username Enumeration via Login Timing Discrepancy
CVSS 5.3
CVE-2024-28885
MEDIUM
Intel(R) QAT Engine <v1.6.1 - Info Disclosure
CVSS 5.9
CVE-2024-51739
HIGH
Combodo iTop < 2.7.11 - Unauthenticated User Enumeration via Password Reset Error Message
CVSS 7.5
CVE-2024-50102
MEDIUM
Linux Kernel 6.4-6.11.6 - Information Leak via Non-Canonical Address Speculation
CVSS 5.5
CVE-2024-41741
MEDIUM
IBM TXSeries for Multiplatforms 10.1 - Info Disclosure
CVSS 5.3
CVE-2024-40490
HIGH
Sourcebans++ <1.8.0 - Info Disclosure
CVSS 7.5
CVE-2024-7010
MEDIUM
mudler/localai <2.17.1 - Info Disclosure
CVSS 5.9
CVE-2024-10463
MEDIUM
Firefox < 132 and ESR < 128.4 - Cross-Origin Video Frame Leak
CVSS 6.5
CVE-2024-49358
MEDIUM
ZimaOS < 1.2.5 - Username Enumeration via Login Endpoint Response Discrepancy
CVSS 5.3
CVE-2024-50383
MEDIUM
Botan < 3.6.0 - Secret-Dependent Timing Discrepancy in donna128
CVSS 5.9
CVE-2024-50382
MEDIUM
Botan < 3.6.0 - Observable Discrepancy in GHASH via LLVM Compiler Optimization
CVSS 5.9
CVE-2024-48644
MEDIUM
Reolink Duo 2 WiFi Camera v3.0.0.1889_23031701 - Info Disclosure
CVSS 5.3
CVE-2024-47678
MEDIUM
Linux Kernel - Observable Discrepancy via ICMP Rate Limit Order
CVSS 5.5
CVE-2024-21251
LOW
Oracle Database Server 19.3-19.24, 21.3-21.15, 23.4-23.5 - Authenticated Data Manipulation in Java VM
CVSS 3.1
CVE-2024-21233
MEDIUM
Oracle Database Server 19.3-19.24, 21.3-21.15, 23.4-23.5 - Authenticated Unauthorized Data Manipulation via Oracle Net
CVSS 4.3
CVE-2024-21210
LOW
Oracle JDK and JRE 8u421, 8u421-perf, 11.0.24, 17.0.12, 21.0.4, 23 - Unauthenticated Data Manipulation via Hotspot
CVSS 3.7
CVE-2024-21208
LOW
Oracle GraalVM - Unauthenticated Partial Denial of Service via Networking Component
CVSS 3.7
CVE-2024-21206
MEDIUM
Oracle Enterprise Command Center Framework 11-13 - Unauthorized Data Access via Diagnostics Component
CVSS 4.3
CVE-2024-47869
LOW
gradio < 4.44.0 - Timing Attack via Analytics Dashboard Hash Comparison
CVSS 3.7
CVE-2024-43546
MEDIUM
Windows 10/11, Server 2022 Cryptographic Component Information Disclosure
CVSS 5.6
CVE-2024-45231
MEDIUM
Django v5.1.1-v4.2.16 - Info Disclosure
CVSS 5.3
CVE-2024-9513
LOW
Netadmin IAM < 3.5 - Information Exposure via Username Argument Discrepancy
CVSS 3.7
Details
Vulnerabilities
751