Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-204

MITRE ↗

CWE-204

2
CRITICAL
11
HIGH
140
MEDIUM
18
LOW
181 CVEs · Page 3/4
5.3
CVE-2025-62236

The Frontier Airlines website has a publicly available endpoint that validates if an email addresses is associated with

5.3
CVE-2025-25236

Omnissa Workspace ONE UEM contains an observable response discrepancy vulnerability. A malicious actor may be able to en

5.3
CVE-2025-59116

Windu CMS is vulnerable to User Enumeration. This issue occurs during logon, where a difference in messages could allow

5.3
CVE-2025-12994

Medtronic CareLink Network allows an unauthenticated remote attacker to initiate a request for security questions to an

5.3
CVE-2025-65899

Kalmia CMS version 0.2.0 contains a user enumeration vulnerability in its authentication mechanism. The application retu

5.3
CVE-2025-40806

A vulnerability has been identified in Gridscale X Prepay (All versions < V4.2.1). The affected application is vulnerabl

5.3
CVE-2025-62181

Pega Platform versions 7.1.0 through Infinity 25.1.0 are affected by a User Enumeration. This issue occurs during user

4.3
CVE-2023-47159

IBM Sterling File Gateway 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.1 could allow an authenticated user to enume

4.3
CVE-2025-54129

HAXiam is a packaging wrapper for HAXcms which allows anyone to spawn their own microsite management platform. In versio

4.3
CVE-2025-42903

A vulnerability in SAP Financial Service Claims Management RFC function ICL_USER_GET_NAME_AND_ADDRESS allows user enumer

3.7
CVE-2024-13198

A vulnerability classified as problematic has been found in langhsu Mblog Blog System 3.5.0. Affected is an unknown func

3.7
CVE-2024-42174

HCL MyXalytics is affected by username enumeration vulnerability. This allows a malicious user to perform enumeration o

3.7
CVE-2025-24023

Flask-AppBuilder is an application development framework. Prior to 4.5.3, Flask-AppBuilder allows unauthenticated users

3.7
CVE-2025-48015

Failed login response could be different depending on whether the username was local or central.

3.7
CVE-2025-9109

A security flaw has been discovered in Portabilis i-Diario up to 1.5.0. Affected by this vulnerability is an unknown fun

3.7
CVE-2025-67500

Mastodon is a free, open-source social network server based on ActivityPub. Versions 4.2.27 and prior, 4.3.0-beta.1 thro

CVE-2025-23214

Cosmos provides users the ability self-host a home server by acting as a secure gateway to your application, as well as

CVE-2025-2910

User enumeration in the password reset module of the MeetMe authentication service in versions prior to 2024-09 allows a

CVE-2025-34155

Tibbo AggreGate Network Manager < 6.40.05 contains an observable response discrepancy in its login functionality. Authen

CVE-2021-47717

IntelliChoice eFORCE Software Suite 2.5.9 contains a username enumeration vulnerability that allows attackers to enumera

6.5
CVE-2023-46170

IBM DS8900F HMC 89.21.19.0, 89.21.31.0, 89.30.68.0, 89.32.40.0, and 89.33.48.0 could allow an authenticated user to arbi

6.2
CVE-2024-24766

CasaOS-UserService provides user management functionalities to CasaOS. Starting in version 0.4.4.3 and prior to version

6.2
CVE-2024-28232

Go package IceWhaleTech/CasaOS-UserService provides user management functionalities to CasaOS. The Casa OS Login page ha

5.8
CVE-2024-40627

Fastapi OPA is an opensource fastapi middleware which includes auth flow. HTTP `OPTIONS` requests are always allowed by

5.3
CVE-2024-25146

Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 befor

5.3
CVE-2023-38362

IBM CICS TX Advanced 10.1 could disclose sensitive information to a remote attacker due to observable discrepancy in HTT

5.3
CVE-2024-1145

User enumeration vulnerability in Devklan's Alma Blog that affects versions 2.1.10 and earlier. This vulnerability could

5.3
CVE-2021-20556

IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 could allow a remote user to enumerate usernames due to differentiating

5.3
CVE-2023-27283

IBM Aspera Orchestrator 4.0.1 could allow a remote attacker to enumerate usernames due to observable response discrepanc

5.3
CVE-2024-33856

An issue was discovered in Logpoint before 7.4.0. An attacker can enumerate a valid list of usernames by observing the r

5.3
CVE-2024-38322

IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.4 agent username and password error response discrepancy exp

5.3
CVE-2024-36996

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.109, an a

5.3
CVE-2024-39211

Kaiten 57.128.8 allows remote attackers to enumerate user accounts via a crafted POST request, because a login response

5.3
CVE-2023-33859

IBM Security QRadar EDR 3.12 could disclose sensitive information due to an observable login response discrepancy. IBM

5.3
CVE-2024-39912

web-auth/webauthn-lib is an open source set of PHP libraries and a Symfony bundle to allow developers to integrate that

5.3
CVE-2024-38431

Matrix Tafnit v8 - CWE-204: Observable Response Discrepancy

5.3
CVE-2024-42343

Loway - CWE-204: Observable Response Discrepancy

5.3
CVE-2023-49069

A vulnerability has been identified in Mendix Runtime V10 (All versions < V10.17.0 only if the basic authentication mech

5.3
CVE-2024-34336

User enumeration vulnerability in ORDAT FOSS-Online before v2.24.01 allows attackers to determine if an account exists i

5.3
CVE-2024-8651

A vulnerability in NetCat CMS allows an attacker to send a specially crafted http request that can be used to check whet

5.3
CVE-2022-20633

A vulnerability in the web-based management interface of Cisco&nbsp;ECE could allow an unauthenticated, remote attacker

4.3
CVE-2024-41715

The goTenna Pro ATAK Plugin does not inject extra characters into broadcasted frames to obfuscate the length of message

4.3
CVE-2024-47129

The goTenna Pro App does not inject extra characters into broadcasted frames to obfuscate the length of messages. This

4.0
CVE-2023-50306

IBM Common Licensing 9.0 could allow a local user to enumerate usernames due to an observable response discrepancy. IBM

3.7
CVE-2024-2482

A vulnerability has been found in Surya2Developer Hostel Management Service 1.0 and classified as problematic. Affected

3.7
CVE-2024-28868

Umbraco is an ASP.NET content management system. Umbraco 10 prior to 10.8.4 with access to the native login screen is vu

3.7
CVE-2024-6056

A vulnerability was found in nasirkhan Laravel Starter up to 11.8.0. It has been rated as problematic. Affected by this

3.7
CVE-2024-12663

A vulnerability classified as problematic was found in funnyzpc Mee-Admin up to 1.6. This vulnerability affects unknown

3.7
CVE-2024-13028

A vulnerability, which was classified as problematic, has been found in Antabot White-Jotter up to 0.2.2. This issue aff

3.3
CVE-2024-31870

IBM Db2 for i 7.2, 7.3, 7.4, and 7.5 supplies user defined table function is vulnerable to user enumeration by a local a

Frequently Asked Questions

What is CWE-204?

CWE-204 (CWE-204) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-204?

There are 181 CVE records associated with CWE-204 in our database. Of these, 2 are critical severity, 11 are high severity, and 140 are medium severity.

How can I protect against CWE-204 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-204 using AI-powered security agents.

Detect CWE-204 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-204 vulnerabilities across your infrastructure.

Get Started