In Wago Smart Designer in versions up to 2.33.1 a low privileged remote attacker may enumerate projects and usernames th
Weblate is a web based localization tool. Prior to version 5.17.1, the screenshots, tasks, and component link API allowe
Capgo before 12.128.2 contains an information disclosure vulnerability in the GET /statistics/app/:app_id endpoint that
Electric Postgres Sync versions below 1.6.10 contains an information disclosure vulnerability that allows attackers to i
Weblate is a web-based localization tool. In versions prior to 2026.7, several endpoints look up objects in a globally s
A flaw has been found in projectsend up to r1945. This impacts an unknown function of the file includes/Classes/Auth.php
The login mechanism of Sage DPW 2021_06_004 displays distinct responses for valid and invalid usernames, allowing enumer
A vulnerability was found in Industrial Application Software IAS Canias ERP 8.03. The impacted element is the function d
When Multi-Attribute Login is enabled, the login interface fails to consistently mask the existence of user accounts. Fo
A vulnerability was determined in automad up to 2.0.0-beta.32. This vulnerability affects the function requestPasswordRe
A vulnerability was identified in OpenClaw up to 2026.2.17. This issue affects the function tools.exec.safeBins of the c
Observable discrepancy in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to o
Observable discrepancy in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to o
Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API
Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Application Interface). Supported v
NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, the shared-view password check fell back
Frappe is a full-stack web application framework. Prior to 16.16.0 and 15.106.0, user enumeration could be performed via
Budibase is an open-source low-code platform. Prior to 3.40.1, packages/server/src/integrations/mongodb.ts passed builde
The frontend validatate.api.exists action can be exploited by authenticated users to extract plaintext user macro values
The Zabbix API host.get action can be exploited by authenticated users to extract a host's PSK key leading to potential
Observable discrepancy in SVG in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin d
WatchGuard Dimension's web login endpoint does not enforce effective rate-limiting or account lockout by default allowin
Frequently Asked Questions
What is CWE-203?
CWE-203 (CWE-203) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-203?
There are 73 CVE records associated with CWE-203 in our database. Of these, 4 are critical severity, 8 are high severity, and 43 are medium severity.
How can I protect against CWE-203 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-203 using AI-powered security agents.
Detect CWE-203 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-203 vulnerabilities across your infrastructure.
Get Started