Skip to main content

CWE archive

CWE-203 CVEs

Programmatic archive

762 CVEs tagged with CWE-20318 Critical, 110 High, 543 Medium, 91 Low, 0 Unrated.

CVE-2024-31870

Published Jun 15, 2024

IBM Db2 for i 7.2, 7.3, 7.4, and 7.5 supplies user defined table function is vulnerable to user enumeration by a local authenticated attacker, without having authority to the rela…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-32926

Published Jun 13, 2024

there is a possible information disclosure due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges need…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-5697

Published Jun 11, 2024

A website was able to detect when a user took a screenshot of a page using the built-in Screenshot functionality in Firefox. This vulnerability affects Firefox < 127.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-37880

Published Jun 10, 2024

The Kyber reference implementation before 9b8d306, when compiled by LLVM Clang through 18.x with some common optimization options, has a timing side channel that allows attackers…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-2408

Published Jun 9, 2024

The openssl_private_decrypt function in PHP, when using PKCS1 padding (OPENSSL_PKCS1_PADDING, which is the default), is vulnerable to the Marvin Attack unless it is used with an O…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-31878

Published Jun 7, 2024

IBM i 7.2, 7.3, 7.4, and 7.5 Service Tools Server (SST) is vulnerable to SST user enumeration by a remote attacker. This vulnerability can be used by a malicious actor to gather…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-5124

Published Jun 6, 2024

A timing attack vulnerability exists in the gaizhenbiao/chuanhuchatgpt repository, specifically within the password comparison logic. The vulnerability is present in version 20240…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-30312

Published May 28, 2024

An issue discovered in OpenWrt 18.06, 19.07, 21.02, 22.03, and beyond allows off-path attackers to hijack TCP sessions, which could lead to a denial of service, impersonating the…

CVSS 7.3 · High

CVE-2023-30308

Published May 28, 2024

An issue discovered in Ruijie EG210G-P, Ruijie EG105G-V2, Ruijie NBR, and Ruijie EG105G routers allows attackers to hijack TCP sessions which could lead to a denial of service.

CVSS 6.5 · Medium

CVE-2021-47226

Published May 21, 2024

In the Linux kernel, the following vulnerability has been resolved: x86/fpu: Invalidate FPU state after a failed XRSTOR from a user buffer Both Intel and AMD consider it to be a…

CVSS 7.1 · High
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2024-30171

Published May 14, 2024

An issue was discovered in Bouncy Castle Java TLS API and JSSE Provider before 1.78. Timing-based leakage may occur in RSA based handshakes because of exception processing.

CVSS 5.9 · Medium

CVE-2024-27839

Published May 14, 2024

A privacy issue was addressed by moving sensitive data to a more secure location. This issue is fixed in iOS 17.5 and iPadOS 17.5. A malicious application may be able to determine…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-27283

Published May 4, 2024

IBM Aspera Orchestrator 4.0.1 could allow a remote attacker to enumerate usernames due to observable response discrepancies. IBM X-Force ID: 248545.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-20556

Published May 3, 2024

IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 could allow a remote user to enumerate usernames due to differentiating error messages on existing usernames. IBM X-Force ID: 19…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-30176

Published May 1, 2024

In Logpoint before 7.4.0, an attacker can enumerate a valid list of usernames by using publicly exposed URLs of shared widgets.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-30257

Published Apr 18, 2024

1Panel is an open source Linux server operation and maintenance management panel. The password verification in the source code uses the != symbol instead hmac.Equal. This may lead…

CVSS 3.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-2464

Published Mar 21, 2024

This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with val…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-28868

Published Mar 20, 2024

Umbraco is an ASP.NET content management system. Umbraco 10 prior to 10.8.4 with access to the native login screen is vulnerable to a possible user enumeration attack. This issue…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-25651

Published Mar 14, 2024

User enumeration can occur in the Authentication REST API in Delinea PAM Secret Server 11.4. This allows a remote attacker to determine whether a user is valid because of a differ…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-5410

Published Mar 12, 2024

A potential security vulnerability has been reported in the system BIOS of certain HP PC products, which might allow memory tampering. HP is releasing mitigation for the potential…

CVSS 8.2 · High

CVE-2024-24766

Published Mar 6, 2024

CasaOS-UserService provides user management functionalities to CasaOS. Starting in version 0.4.4.3 and prior to version 0.4.7, the Casa OS Login page disclosed the username enumer…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort
Showing 201-225 of 762 CVEsPage 9 of 31