Skip to main content

CWE archive

CWE-204 CVEs

Programmatic archive

167 CVEs tagged with CWE-2043 Critical, 7 High, 142 Medium, 15 Low, 0 Unrated.

CVE-2026-42218

Published Jul 20, 2026

xrdp is an open source RDP server. Versions 0.10.6 and prior contain a timing side-channel vulnerability in the login interface. Due to a discrepancy in response processing times,…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2024-23574

Published Jul 17, 2026

HCL Aftermarket EPC is vulnerable to attack since It was found that a malicious actor can use brute-force techniques to either guess or confirm valid users in the system. Use renu…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-47083

Published Jul 16, 2026

An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is an ESEARCH cross-user content oracle. By using the ESEARCH command, an authenticated IMAP user could…

CVSS 4.3 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-15747

Published Jul 14, 2026

Mojolicious versions from 4.59 before 9.48 for Perl expose a stable representation of the session CSRF token to a BREACH compression oracle. _csrf_token generates and caches one…

CVSS 9.1 · Critical
evidence mentions
3
Buzz score
25.4

CVE-2026-44753

Published Jul 14, 2026

SAP HANA Database (user self service tools) allows an unauthenticated user to send specially crafted requests that produce distinguishable responses, enabling enumeration of valid…

CVSS 3.7 · Low
evidence mentions
2
Buzz score
21.0

CVE-2026-61503

Published Jul 13, 2026

Rejetto HFS 3.0.0 through 3.2.0 returns observably different responses from its login endpoint depending on whether the submitted username exists. A remote unauthenticated attacke…

CVSS 6.9 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2026-53422

Published Jul 2, 2026

Observable Response Discrepancy vulnerability in Erlang OTP ssh (ssh_sftpd module) allows an authenticated SFTP user to enumerate the existence of files and directories outside th…

CVSS 2.3 · Low
evidence mentions
7
Buzz score
33.8
Vendor/product tagsBeta · best-effort

CVE-2026-53908

Published Jul 1, 2026

MCO is vulnerable to User Enumeration through authentication-related functionalities. The application returns distinguishable responses for valid and invalid users during username…

CVSS 6.9 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-53947

Published Jun 24, 2026

Ghost is a Node.js content management system. From 5.18.0 until 6.21.1, a discrepancy in responses from the members signin endpoints made it possible for an unauthenticated attack…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-54445

Published Jun 17, 2026

vantage6 is an open-source infrastructure for privacy preserving analysis. Versions prior to 5.0.0 provide an initial user with username `root` and password `root`. This is not id…

CVSS 6.9 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2026-43926

Published Jun 4, 2026

FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, the password reset confirmation endpoint `/client/reset-password-confirm/:hash` is…

CVSS 6.3 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-45294

Published May 29, 2026

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.219, the password reset endpoint returns visually distinct responses depending on w…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-45620

Published May 29, 2026

WWBN AVideo is an open source video platform. In 29.0 and earlier, objects/mention.json.php has no User::loginCheck() or admin gate. It only has an entry guard: preg_match('/^@/',…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2018-25350

Published May 23, 2026

userSpice 4.3.24 contains a username enumeration vulnerability that allows unauthenticated attackers to discover valid usernames by sending POST requests to the existingUsernameCh…

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
17.5

CVE-2026-44306

Published May 12, 2026

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.21 and 6.15.0, responses from the forgot password forms hinted at whether an account existed f…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-8242

Published May 10, 2026

A vulnerability was found in Industrial Application Software IAS Canias ERP 8.03. The impacted element is the function doAction of the component Login RMI Interface. Performing a…

CVSS 2.9 · Low
evidence mentions
5
Buzz score
29.4

CVE-2026-20195

Published May 6, 2026

A vulnerability in an identity management API endpoint of Cisco ISE could allow an unauthenticated, remote attacker to enumerate valid user accounts on an affected device. This…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-34319

Published Apr 21, 2026

Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell: Core Client). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Eas…

CVSS 5.0 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-24468

Published Apr 20, 2026

OpenAEV is an open source platform allowing organizations to plan, schedule and conduct cyber adversary simulation campaign and tests. Starting in version 1.11.0 and prior to vers…

CVSS 5.3 · Medium
evidence mentions
4
Buzz score
21.1

CVE-2026-40485

Published Apr 18, 2026

ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the public API login endpoint (/api/public/user/login) returns distinguishable HTTP response code…

CVSS 5.3 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2026-34264

Published Apr 14, 2026

During authorization checks in SAP Human Capital Management for SAP S/4HANA, the system returns specific messages. Due to this, an authenticated user with low privileges could gue…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-39851

Published Apr 8, 2026

Saleor is an e-commerce platform. From 2.10.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, the requestEmailChange() mutation was revealing the existence of user-provided em…

CVSS 5.3 · Medium
evidence mentions
6
Buzz score
24.5
Vendor/product tagsBeta · best-effort

CVE-2025-67807

Published Apr 1, 2026

The login mechanism of Sage DPW 2025_06_004 displays distinct responses for valid and invalid usernames, allowing enumeration of existing accounts in versions before 2021_06_000.…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 167 CVEsPage 1 of 7