Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-204

MITRE ↗

CWE-204

2
CRITICAL
11
HIGH
140
MEDIUM
18
LOW
181 CVEs · Page 2/4
4.3
CVE-2026-2859

Improper permission enforcement in Checkmk versions 2.4.0 before 2.4.0p23, 2.3.0 before 2.3.0p43, and 2.2.0 (EOL) allows

4.3
CVE-2026-39851

Saleor is an e-commerce platform. From 2.10.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, the requestEmailChange

4.3
CVE-2026-53908

MCO is vulnerable to User Enumeration through authentication-related functionalities. The application returns distinguis

4.3
CVE-2026-53422

Observable Response Discrepancy vulnerability in Erlang OTP ssh (ssh_sftpd module) allows an authenticated SFTP user to

4.3
CVE-2026-47083

An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is an ESEARCH cross-user content oracle. By u

3.7
CVE-2026-4045

A flaw has been found in projectsend up to r1945. This impacts an unknown function of the file includes/Classes/Auth.php

3.7
CVE-2025-67806

The login mechanism of Sage DPW 2021_06_004 displays distinct responses for valid and invalid usernames, allowing enumer

3.7
CVE-2026-8242

A vulnerability was found in Industrial Application Software IAS Canias ERP 8.03. The impacted element is the function d

3.7
CVE-2026-44753

SAP HANA Database (user self service tools) allows an unauthenticated user to send specially crafted requests that produ

3.7
CVE-2026-19965

A vulnerability was determined in automad up to 2.0.0-beta.32. This vulnerability affects the function requestPasswordRe

CVE-2025-3716

User enumeration in ESET Protect (on-prem) via Response Timing.

CVE-2026-43926

FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, the password reset conf

CVE-2026-54445

vantage6 is an open-source infrastructure for privacy preserving analysis. Versions prior to 5.0.0 provide an initial us

CVE-2026-54768

WPGraphQL provides a GraphQL API for WordPress sites. From 2.0.0 until 2.15.1, the deprecated user field on SendPassword

CVE-2026-54739

Lemmy is a link aggregator and forum for the fediverse. Prior to 0.19.19 and 1.0.0-beta.1, Lemmy's login endpoint in cra

CVE-2026-66002

Frappe is a full-stack web application framework. Prior to 15.115.0 and 16.27.0, the public request-data web form and Pe

8.6
CVE-2025-5485

User names used to access the web management interface are limited to the device identifier, which is a numerical ident

7.5
CVE-2025-3092

An unauthenticated remote attacker can enumerate valid user names from an unprotected endpoint.

7.5
CVE-2025-46390

CWE-204: Observable Response Discrepancy

6.5
CVE-2025-61907

Icinga 2 is an open source monitoring system. In Icinga 2 versions 2.4 through 2.15.0, filter expressions provided to th

6.5
CVE-2025-66307

This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create

6.5
CVE-2025-67874

ChurchCRM is an open-source church management system. Prior to version 6.5.0, the application echoes back plaintext pass

5.9
CVE-2025-9824

ImpactThe attacker can validate if a user exists by checking the time login returns. This timing difference can be used

5.3
CVE-2024-36510

An observable response discrepancy vulnerability [CWE-204] in FortiClientEMS 7.4.0, 7.2.0 through 7.2.4, 7.0 all version

5.3
CVE-2025-0693

Variable response times in the AWS Sign-in IAM user login flow allowed for the use of brute force enumeration techniques

5.3
CVE-2024-35114

IBM Control Center 6.2.1 and 6.3.1 could allow a remote attacker to enumerate usernames due to an observable discr

5.3
CVE-2023-37413

IBM Aspera Faspex 5.0.0 through 5.0.10 could disclose sensitive username information due to an observable response discr

5.3
CVE-2025-24980

pimcore/admin-ui-classic-bundle provides a Backend UI for Pimcore. In affected versions an error message discloses exist

5.3
CVE-2025-23193

SAP NetWeaver Server ABAP allows an unauthenticated attacker to exploit a vulnerability that causes the server to respon

5.3
CVE-2025-1101

A CWE-204 "Observable Response Discrepancy" in the login page in Q-Free MaxTime less than or equal to version 2.11.0 all

5.3
CVE-2024-55198

User Enumeration via Discrepancies in Error Messages in the Celk Sistemas Celk Saude v.3.1.252.1 password recovery funct

5.3
CVE-2025-31124

Zitadel is open-source identity infrastructure software. ZITADEL administrators can enable a setting called "Ignoring un

5.3
CVE-2024-56476

IBM TXSeries for Multiplatforms 9.1 and 11.1 could allow an attacker to enumerate usernames due to an observable login a

5.3
CVE-2025-30280

A vulnerability has been identified in Mendix Runtime V10 (All versions < V10.21.0), Mendix Runtime V10.12 (All versions

5.3
CVE-2025-30150

Shopware 6 is an open commerce platform based on Symfony Framework and Vue. Through the store-api it is possible as a at

5.3
CVE-2025-24342

A vulnerability in the login functionality of the web application of ctrlX OS allows a remote unauthenticated attacker t

5.3
CVE-2025-46736

Umbraco is a free and open source .NET content management system. Prior to versions 10.8.10 and 13.8.1, based on an anal

5.3
CVE-2024-51447

A vulnerability has been identified in Polarion V2310 (All versions), Polarion V2404 (All versions < V2404.2). The login

5.3
CVE-2025-3939

Observable Response Discrepancy vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enter

5.3
CVE-2025-0163

IBM Security Verify Access Appliance and Docker 10.0 through 10.0.8 could allow a remote attacker to enumerate usernames

5.3
CVE-2025-49187

For failed login attempts, the application returns different error messages depending on whether the login failed due to

5.3
CVE-2025-27451

For failed login attempts, the application returns different error messages depending on whether the login failed due to

5.3
CVE-2025-52899

Tuleap is an Open Source Suite created to facilitate management of software development and collaboration. In Tuleap Com

5.3
CVE-2025-54834

OPEXUS FOIAXpress Public Access Link (PAL) version v11.1.0 allows an unauthenticated, remote attacker to query the /App/

5.3
CVE-2025-58442

Saleor is an e-commerce platform. Starting in version 3.21.0 and prior to version 3.21.16, requesting certain fields in

5.3
CVE-2025-56764

Trivision NC-227WF firmware 5.80 (build 20141010) login mechanism reveals whether a username exists or not by returning

5.3
CVE-2025-58586

For failed login attempts, the application returns different error messages depending on whether the login failed due to

5.3
CVE-2025-61789

Icinga DB Web provides a graphical interface for Icinga monitoring. Before 1.1.4 and 1.2.3, an authorized user with acce

5.3
CVE-2025-34254

D-Link Nuclias Connect firmware versions <= 1.3.1.4 contain an observable response discrepancy vulnerability. The applic

5.3
CVE-2025-34255

D-Link Nuclias Connect firmware versions <= 1.3.1.4 contain an observable response discrepancy vulnerability. The applic

Frequently Asked Questions

What is CWE-204?

CWE-204 (CWE-204) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-204?

There are 181 CVE records associated with CWE-204 in our database. Of these, 2 are critical severity, 11 are high severity, and 140 are medium severity.

How can I protect against CWE-204 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-204 using AI-powered security agents.

Detect CWE-204 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-204 vulnerabilities across your infrastructure.

Get Started