Skip to main content

CWE archive

CWE-204 CVEs

Programmatic archive

167 CVEs tagged with CWE-2043 Critical, 7 High, 142 Medium, 15 Low, 0 Unrated.

CVE-2025-54834

Published Jul 31, 2025

OPEXUS FOIAXpress Public Access Link (PAL) version v11.1.0 allows an unauthenticated, remote attacker to query the /App/CreateRequest.aspx endpoint to check for the existence of v…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-52899

Published Jul 29, 2025

Tuleap is an Open Source Suite created to facilitate management of software development and collaboration. In Tuleap Community Edition prior to version 16.9.99.1750843170 and Tule…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-54129

Published Jul 21, 2025

HAXiam is a packaging wrapper for HAXcms which allows anyone to spawn their own microsite management platform. In versions 11.0.4 and below, the application returns a 200 response…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-3092

Published Jun 24, 2025

An unauthenticated remote attacker can enumerate valid user names from an unprotected endpoint.

CVSS 7.5 · High

CVE-2025-5485

Published Jun 12, 2025

User names used to access the web management interface are limited to the device identifier, which is a numerical identifier no more than 10 digits. A malicious actor can enumer…

CVSS 8.8 · High
evidence mentions
2
Buzz score
17.5

CVE-2025-49187

Published Jun 12, 2025

For failed login attempts, the application returns different error messages depending on whether the login failed due to an incorrect password or a non-existing username. This all…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-48015

Published May 20, 2025

Failed login response could be different depending on whether the username was local or central.

CVSS 3.7 · Low

CVE-2024-51447

Published May 13, 2025

A vulnerability has been identified in Polarion V2310 (All versions), Polarion V2404 (All versions < V2404.2). The login implementation of the affected application contains an obs…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-46736

Published May 6, 2025

Umbraco is a free and open source .NET content management system. Prior to versions 10.8.10 and 13.8.1, based on an analysis of the timing of post login API responses, it's possib…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-24342

Published Apr 30, 2025

A vulnerability in the login functionality of the web application of ctrlX OS allows a remote unauthenticated attacker to guess valid usernames via multiple crafted HTTP requests.

CVSS 5.3 · Medium

CVE-2025-30150

Published Apr 8, 2025

Shopware 6 is an open commerce platform based on Symfony Framework and Vue. Through the store-api it is possible as a attacker to check if a specific e-mail address has an account…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-30280

Published Apr 8, 2025

A vulnerability has been identified in Mendix Runtime V10 (All versions < V10.21.0), Mendix Runtime V10.12 (All versions < V10.12.16), Mendix Runtime V10.18 (All versions < V10.18…

CVSS 6.9 · Medium

CVE-2025-31124

Published Mar 31, 2025

Zitadel is open-source identity infrastructure software. ZITADEL administrators can enable a setting called "Ignoring unknown usernames" which helps mitigate attacks that try to g…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-2910

Published Mar 28, 2025

User enumeration in the password reset module of the MeetMe authentication service in versions prior to 2024-09 allows an attacker to determine whether an email address is registe…

CVSS 6.9 · Medium

CVE-2024-55198

Published Mar 13, 2025

User Enumeration via Discrepancies in Error Messages in the Celk Sistemas Celk Saude v.3.1.252.1 password recovery functionality which allows a remote attacker to enumerate users…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-24023

Published Mar 3, 2025

Flask-AppBuilder is an application development framework. Prior to 4.5.3, Flask-AppBuilder allows unauthenticated users to enumerate existing usernames by timing the response time…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-1101

Published Feb 12, 2025

A CWE-204 "Observable Response Discrepancy" in the login page in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to enumerate valid u…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-23193

Published Feb 11, 2025

SAP NetWeaver Server ABAP allows an unauthenticated attacker to exploit a vulnerability that causes the server to respond differently based on the existence of a specified user, p…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-24980

Published Feb 7, 2025

pimcore/admin-ui-classic-bundle provides a Backend UI for Pimcore. In affected versions an error message discloses existing accounts and leads to user enumeration on the target vi…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-37413

Published Jan 29, 2025

IBM Aspera Faspex 5.0.0 through 5.0.10 could disclose sensitive username information due to an observable response discrepancy.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-47159

Published Jan 27, 2025

IBM Sterling File Gateway 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.1 could allow an authenticated user to enumerate usernames due to an observable discrepancy in request…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 76-100 of 167 CVEsPage 4 of 7