The product provides different responses to incoming requests in a way that reveals internal state information to an unauthorized actor outside of the intended control sphere.
167 vulnerabilities with CWE-204
CVE-2026-42218
MEDIUM
XRDP is vulnerable to a server timing attack, leading to user enumeration
CVSS 5.3
CVE-2026-47083
MEDIUM
Cyrusimap Cyrus Imap < 3.12.3 - Observable Response Discrepancy
CVSS 4.3
CVE-2026-15747
CRITICAL
Mojolicious versions from 4.59 before 9.48 for Perl expose a stable representation of the session CSRF token to a BREACH compression oracle
CVSS 9.1
CVE-2026-44753
LOW
SAP HANA User Self Service - Account and Email Enumeration
CVSS 3.7
CVE-2026-61503
MEDIUM
Rejetto HFS < 3.2.1 Username Enumeration via Login Response Differences
CVSS 5.3
CVE-2026-53422
MEDIUM
SFTP REALPATH path-existence oracle allowing filesystem enumeration outside configured root
CVSS 4.3
CVE-2026-53908
MEDIUM
MyComplianceOffice - User Enumeration in MCO
CVSS 4.3
CVE-2026-53947
MEDIUM
Ghost: Member existence leak via magic link sign-in response
CVSS 5.3
CVE-2026-54445
MEDIUM
Vantage6: Set admin user and password from environment or configuration
CVE-2026-43926
MEDIUM
FOSSBilling's password reset confirmation endpoint lacks rate limiting
CVE-2026-45294
MEDIUM
FreeScout: User Account Enumeration via Password Reset Response Differentiation
CVSS 5.3
CVE-2026-45620
MEDIUM
AVideo CVE-2026-43881 incomplete fix - `objects/mention.json.php:17` is an unauthenticated user enumeration
CVSS 5.3
CVE-2026-44306
MEDIUM
Statamic: Email enumeration via forgot password endpoint
CVSS 5.3
CVE-2026-8242
LOW
Industrial Application Software IAS Canias ERP Login RMI doAction response discrepancy
CVSS 3.7
CVE-2026-20195
MEDIUM
Cisco Identity Services Engine Observable Response Discrepancy Vulnerability
CVSS 5.3
CVE-2026-34319
MEDIUM
MySQL Shell 8.0.0-8.0.45, 8.4.0-8.4.8, 9.0.0-9.6.0 - Denial of Service via Shell Core Client
CVSS 5.0
CVE-2026-24468
MEDIUM
OpenAEV Vulnerable to Username/Email Enumeration Through Differential HTTP Responses in Password Reset API
CVSS 5.3
CVE-2026-40485
MEDIUM
ChurchCRM: Username Enumeration via Differential Response in Public Login API
CVSS 5.3
CVE-2026-34264
MEDIUM
Information Disclosure vulnerability in SAP Human Capital Management for SAP S/4HANA
CVSS 6.5
CVE-2026-4113
HIGH
SonicWall SMA1000 <12.4.3-03245 - Info Disclosure
CVSS 7.2
CVE-2026-39851
MEDIUM
Saleor requestEmailChange() - User Enumeration
CVSS 4.3
CVE-2026-33419
HIGH
MinIO: LDAP login brute-force via user enumeration and missing rate limit
CVSS 7.5
CVE-2026-33323
MEDIUM
Parse Server: Email verification resend page leaks user existence
CVSS 5.3
CVE-2026-33688
MEDIUM
AVideo has Pre-Captcha User Enumeration and Account Status Disclosure in Password Recovery Endpoint
CVSS 5.3
CVE-2026-30876
MEDIUM
Chamilo LMS: User enumeration vulnerability via response
CVSS 5.3
Details
Vulnerabilities
167