Skip to main content

CWE archive

CWE-203 CVEs

Programmatic archive

748 CVEs tagged with CWE-20316 Critical, 107 High, 538 Medium, 87 Low, 0 Unrated.

CVE-2026-65314

Published Jul 21, 2026

Electric Postgres Sync versions below 1.6.10 contains an information disclosure vulnerability that allows attackers to infer the values of excluded columns by crafting subset wher…

CVSS 5.3 · Medium
evidence mentions
3
Buzz score
20.4

CVE-2026-47011

Published Jul 21, 2026

Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Application Interface). Supported versions that are affected are 17.0-26.4. Difficult to explo…

CVSS 2.6 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-64822

Published Jul 21, 2026

djangoSIGE through 1.10 (commit a6fe7e8) contains a user enumeration vulnerability in ForgotPasswordView within djangosige/apps/login/views.py that allows unauthenticated attacker…

CVSS 6.9 · Medium
evidence mentions
3
Buzz score
20.4

CVE-2026-56339

Published Jul 15, 2026

Capgo (Cap-go/capgo) before 12.128.2 contains an information disclosure vulnerability in the Supabase PostgREST SECURITY DEFINER RPC function public.rescind_invitation that allows…

CVSS 8.7 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-56296

Published Jul 11, 2026

Cap-go before 12.128.2 contains an information disclosure vulnerability in the public.transfer_app RPC function that returns distinct error messages for existing versus non-existi…

CVSS 6.9 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2026-58503

Published Jul 10, 2026

Frappe is a full-stack web application framework. Prior to 16.16.0 and 15.106.0, user enumeration could be performed via the reset_password endpoint. This issue is fixed in versio…

CVSS 6.9 · Medium
evidence mentions
7
Buzz score
25.8

CVE-2026-51926

Published Jul 9, 2026

An issue in docuForm GmbH FSM Client v.11.11c allows a remote attacker to obtain sensitive information via the login.php component. A vulnerability was identified in the authentic…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-44332

Published Jul 8, 2026

Fiber is an Express inspired web framework written in Go. Prior to 3.3.0, the default Authorizer function in the BasicAuth middleware in middleware/basicauth/config.go uses short-…

CVSS 5.3 · Medium
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-56327

Published Jun 30, 2026

Capgo before 12.128.2 contains an information disclosure vulnerability in the public.invite_user_to_org RPC function that allows unauthenticated attackers to enumerate organizatio…

CVSS 6.9 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2026-47379

Published Jun 23, 2026

NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, the shared-view password check fell back to strict-equality (===) comparison for legacy plaintext pa…

CVSS 6.9 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-56316

Published Jun 21, 2026

Cap-go before 12.128.2 contains an information disclosure vulnerability in the OPTIONS /build/upload/:jobId/* endpoint that allows unauthenticated attackers to enumerate valid bui…

CVSS 6.9 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2026-56319

Published Jun 20, 2026

Capgo before 12.128.2 contains an information disclosure vulnerability in the GET /statistics/app/:app_id endpoint that allows app-limited API keys to distinguish existing sibling…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2023-54357

Published Jun 19, 2026

Joomla com_booking component 2.4.9 contains an information disclosure vulnerability that allows unauthenticated attackers to enumerate user accounts by exploiting the getUserData…

CVSS 8.7 · High

CVE-2026-45294

Published May 29, 2026

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.219, the password reset endpoint returns visually distinct responses depending on w…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-45410

Published May 28, 2026

TREK is a collaborative travel planner. Prior to 3.0.18, early return on missing user during login flow allowed an attacker to enumerate valid user accounts via response timing di…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2026-8242

Published May 10, 2026

A vulnerability was found in Industrial Application Software IAS Canias ERP 8.03. The impacted element is the function doAction of the component Login RMI Interface. Performing a…

CVSS 2.9 · Low
evidence mentions
5
Buzz score
29.4

CVE-2026-41588

Published May 8, 2026

RELATE is a web-based courseware package. Prior to commit 2f68e16, there is a timing attack vulnerability in course/auth.py — check_sign_in_key(). This issue has been patched via…

CVSS 9.0 · Critical
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-44263

Published May 7, 2026

Weblate is a web based localization tool. Prior to version 5.17.1, the screenshots, tasks, and component link API allowed for the enumeration of translations in a project inaccess…

CVSS 4.3 · Medium
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2023-5872

Published Apr 16, 2026

In Wago Smart Designer in versions up to 2.33.1 a low privileged remote attacker may enumerate projects and usernames through iterative requests to an specific endpoint.

CVSS 4.3 · Medium

CVE-2026-26895

Published Apr 2, 2026

User enumeration vulnerability in /pwreset.php in osTicket v1.18.2 allows remote attackers to enumerate valid usernames registered in the platform.

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-67806

Published Apr 1, 2026

The login mechanism of Sage DPW 2021_06_004 displays distinct responses for valid and invalid usernames, allowing enumeration of existing accounts in versions before 2021_06_000.…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort
Showing 1-25 of 748 CVEsPage 1 of 30