Skip to main content

CWE archive

CWE-203 CVEs

Programmatic archive

748 CVEs tagged with CWE-20316 Critical, 107 High, 538 Medium, 87 Low, 0 Unrated.

CVE-2023-39522

Published Aug 29, 2023

goauthentik is an open-source Identity Provider. In affected versions using a recovery flow with an identification stage an attacker is able to determine if a username exists. Onl…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-40756

Published Aug 28, 2023

User enumeration is found in PHPJabbers Callback Widget v1.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if th…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-40021

Published Aug 16, 2023

Oppia is an online learning platform. When comparing a received CSRF token against the expected token, Oppia uses the string equality operator (`==`), which is not safe against ti…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-40343

Published Aug 16, 2023

Jenkins Tuleap Authentication Plugin 1.1.20 and earlier uses a non-constant time comparison function when validating an authentication token allowing attackers to use statistical…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-46724

Published Aug 14, 2023

This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 16.4 and iPadOS 16.4. A person with physical access to an iOS device may be…

CVSS 2.4 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-20583

Published Aug 1, 2023

A potential power side-channel vulnerability in AMD processors may allow an authenticated attacker to monitor the CPU power consumption as the data in a cache line changes over ti…

CVSS 4.7 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2023-3462

Published Jul 31, 2023

HashiCorp's Vault and Vault Enterprise are vulnerable to user enumeration when using the LDAP auth method. An attacker may submit requests of existent and non-existent LDAP users…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-3897

Published Jul 25, 2023

Username enumeration is possible through Bypassing CAPTCHA in On-premise SureMDM Solution on Windows deployment allows attacker to enumerate local user information via error messa…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-3640

Published Jul 24, 2023

A possible unauthorized memory access flaw was found in the Linux kernel's cpu_entry_area mapping of X86 CPU data to memory, where a user may guess the location of exception stack…

CVSS 7.0 · High
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2023-3529

Published Jul 6, 2023

A vulnerability classified as problematic has been found in Rotem Dynamics Rotem CRM up to 20230729. This affects an unknown part of the file /LandingPages/api/otp/send?id=[ID][am…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-3336

Published Jul 5, 2023

TN-5900 Series version 3.3 and prior versions is vulnearble to user enumeration vulnerability. The vulnerability may allow a remote attacker to determine whether a user is valid d…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-37305

Published Jun 30, 2023

An issue was discovered in the ProofreadPage (aka Proofread Page) extension for MediaWiki through 1.39.3. In includes/Page/PageContentHandler.php and includes/Page/PageDisplayHand…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-22359

Published Jun 26, 2023

User enumeration in Checkmk <=2.2.0p4 allows an authenticated attacker to enumerate usernames.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-42792

Published Jun 23, 2023

This issue was addressed with improved data protection. This issue is fixed in iOS 16.1 and iPadOS 16. An app may be able to read sensitive location information

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-34878

Published Jun 14, 2023

An issue was discovered in Ujcms v6.0.2 allows attackers to gain sensitive information via the dir parameter to /api/backend/core/web-file-html/download-zip.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-34344

Published Jun 12, 2023

AMI BMC contains a vulnerability in the IPMI handler, where an unauthorized attacker can use certain oracles to guess a valid username, which may lead to information disclosure.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 301-325 of 748 CVEsPage 13 of 30