userSpice 4.3.24 contains a username enumeration vulnerability that allows unauthenticated attackers to discover valid u
Mojolicious versions from 4.59 before 9.48 for Perl expose a stable representation of the session CSRF token to a BREACH
Observable response discrepancy in Azure Stack HCI allows an unauthorized attacker to disclose information over a networ
Observable response discrepancy vulnerability in OpenText™ Vertica allows Password Brute Forcing. The vulnerability co
MinIO is a high-performance object storage system. Prior to RELEASE.2026-03-17T21-25-16Z, MinIO AIStor's STS (Security T
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, iTop returns different responses for valid/inval
In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing returns distinguishable errors for invalid RSA P
An observable response discrepancy vulnerability in the SonicWall SMA1000 series appliances allows a remote attacker to
During authorization checks in SAP Human Capital Management for SAP S/4HANA, the system returns specific messages. Due t
In Gitea before 1.25.2, /api/v1/user has different responses for failed authentication depending on whether a username e
AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatti
ZITADEL is an open source identity management platform. Prior to 4.9.1 and 3.4.6, a user enumeration vulnerability has b
The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2,
CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati
DokuWiki 2018-04-22b contains a username enumeration vulnerability in its password reset functionality that allows attac
A user enumeration vulnerability exists in FormaLMS 4.1.18 and below in the password recovery functionality accessible v
Static Web Server (SWS) is a production-ready web server suitable for static web files or assets. In versions 2.1.0 thro
Piwigo is an open source photo gallery application for the web. In version 15.5.0 and likely earlier 15.x releases, the
Rucio is a software framework that provides functionality to organize, manage, and access large volumes of scientific da
Dify is an open-source LLM app development platform. Prior to 1.9.0, responses from the Dify API to existing and non-exi
NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, the password forgot endpoint return
Shopware is an open commerce platform. Prior to 6.7.8.1 and 6.6.10.15, the Store API login endpoint (POST /store-api/acc
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.34
IBM Aspera Console 3.3.0 through 3.4.8 could allow an attacker to enumerate usernames due to an observable response disc
Raytha CMS is vulnerable to User Enumeration in password reset functionality. Difference in messages could allow an atta
Chamilo LMS is a learning management system. Prior to version 1.11.36, Chamilo is vulnerable to user enumeration with va
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the password recovery endpoint at `o
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version
ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the public API login endpoint (/api/pu
OpenAEV is an open source platform allowing organizations to plan, schedule and conduct cyber adversary simulation campa
A vulnerability in an identity management API endpoint of Cisco ISE could allow an unauthenticated, remote attacker to e
The check user account lock states feature within the email OTP flow fails to validate user input, allowing an attacker
Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.21 and 6.15.0, responses from the f
WWBN AVideo is an open source video platform. In 29.0 and earlier, objects/mention.json.php has no User::loginCheck() or
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.219, the password reset
Ghost is a Node.js content management system. From 5.18.0 until 6.21.1, a discrepancy in responses from the members sign
Rejetto HFS 3.0.0 through 3.2.0 returns observably different responses from its login endpoint depending on whether the
HCL Aftermarket EPC is vulnerable to attack since It was found that a malicious actor can use brute-force techniques to
xrdp is an open source RDP server. Versions 0.10.6 and prior contain a timing side-channel vulnerability in the login in
Observable response discrepancy vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human
The endpoint /v3/import/{token}_{clusterId}.yaml retrieves the cluster object before validating the token. When a valid
A user enumeration vulnerability in bluewave-labs/Checkmate through 2.1.0 allows an unauthenticated remote attacker to d
Budibase is an open-source low-code platform. Prior to 3.39.25, POST /api/global/auth/:tenantId/login incremented the fa
Observable response discrepancy in PostgreSQL SCRAM authentication allows an unauthenticated user to test the existence
Rocket.Chat exposes the sendForgotPasswordEmail Meteor method without a DDP rate limit, so an unauthenticated caller may
Automatisch reveals whether an address is registered through the response to its forgot-password request. The controller
Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell: Core Client). Supported versions that are a
The login mechanism of Sage DPW 2025_06_004 displays distinct responses for valid and invalid usernames, allowing enumer
Discord through 2026-01-16 allows gathering information about whether a user's client state is Invisible (and not actual
Improper permission enforcement in Checkmk versions 2.4.0 before 2.4.0p23, 2.3.0 before 2.3.0p43, and 2.2.0 (EOL) allows
Frequently Asked Questions
What is CWE-204?
CWE-204 (CWE-204) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-204?
There are 181 CVE records associated with CWE-204 in our database. Of these, 2 are critical severity, 11 are high severity, and 140 are medium severity.
How can I protect against CWE-204 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-204 using AI-powered security agents.
Detect CWE-204 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-204 vulnerabilities across your infrastructure.
Get Started