vantage6 is a privacy preserving federated learning infrastructure for secure insight exchange. vantage6 does not inform
Observable Response Discrepancy in GitHub repository answerdev/answer prior to 1.0.6.
A vulnerability has been identified in Mendix Forgot Password (Mendix 7 compatible) (All versions < V3.7.1), Mendix Forg
Observable Response Discrepancy in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 112011
Teltonika’s Remote Management System versions prior to 4.10.0 contain a function that allows users to claim their devic
When supplied with a random MAC address, Snap One OvrC cloud servers will return information about the device.
Avaya IX Workforce Engagement v15.2.7.1195 - User Enumeration - Observable Response Discrepancy
TN-5900 Series version 3.3 and prior versions is vulnearble to user enumeration vulnerability. The vulnerability may all
Observable Response Discrepancy in the SICK ICR890-4 could allow a remote attacker to identify valid usernames for the F
Tadiran Telecom Aeonix - CWE-204: Observable Response Discrepancy
Silverware Games is a premium social network where people can play games online. Prior to version 1.3.6, the Password Re
User enumeration vulnerability in Password Recovery plugin 1.2 version for Roundcube, which could allow a remote attacke
Piccolo is an ORM and query builder which supports asyncio. In versions 0.120.0 and prior, the implementation of `BaseUs
User enumeration vulnerability in Arconte Áurea 1.5.0.0 version. The exploitation of this vulnerability could allow an a
An issue discovered in Elenos ETG150 FM transmitter v3.12 allows attackers to enumerate user accounts based on server re
Sulu is an open-source PHP content management system based on the Symfony framework. It allows over the Admin Login form
An observable response discrepancy in the Gallagher Command Centre RESTAPI allows an insufficiently-privileged user to
Kirby is a Content Management System. Prior to versions 3.5.8.2, 3.6.6.2, 3.7.5.1, and 3.8.1, a user enumeration vulnera
A vulnerability in Qlik Sense Enterprise on Windows could allow an remote attacker to enumerate domain user accounts. An
A Observable Response Discrepancy vulnerability in spacewalk-java of SUSE Manager Server 4.1, SUSE Manager Server 4.2 al
All CODESYS Visualization versions before V4.2.0.0 generate a login dialog vulnerable to information exposure allowing a
A remote, unauthenticated attacker can enumerate valid users by sending specific requests to the webservice of MB connec
A user enumeration vulnerability exists in the login functionality of Ghost Foundation Ghost 5.9.4. A specially-crafted
Cloud Native Computing Foundation Harbor before 1.10.3 and 2.x before 2.0.1 allows resource enumeration because unauthen
Under certain circumstances a CCURE Portal user could enumerate user accounts in CCURE 9000 version 2.90 and prior versi
In mymbCONNECT24, mbCONNECT24 <= 2.9.0 an unauthenticated user can enumerate valid backend users by checking what kind o
A vulnerability in SonicWall SMA100 password change API allows a remote unauthenticated attacker to perform SMA100 usern
InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 authentication process response indicates and valida
Pimcore is an open source data & experience management platform. In versions prior to 10.1.3, it is possible to enumerat
In TYPO3 CMS versions 10.4.0 and 10.4.1, it has been discovered that time-based attacks can be used with the password re
Accellion FTP server prior to version FTA_9_12_220 only returns the username in the server response if the username is i
Frequently Asked Questions
What is CWE-204?
CWE-204 (CWE-204) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-204?
There are 181 CVE records associated with CWE-204 in our database. Of these, 2 are critical severity, 11 are high severity, and 140 are medium severity.
How can I protect against CWE-204 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-204 using AI-powered security agents.
Detect CWE-204 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-204 vulnerabilities across your infrastructure.
Get Started