Skip to main content

CWE archive

CWE-204 CVEs

Programmatic archive

167 CVEs tagged with CWE-2043 Critical, 7 High, 142 Medium, 15 Low, 0 Unrated.

CVE-2024-35114

Published Jan 25, 2025

IBM Control Center 6.2.1 and 6.3.1 could allow a remote attacker to enumerate usernames due to an observable discrepancy between login attempts.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-0693

Published Jan 23, 2025

Variable response times in the AWS Sign-in IAM user login flow allowed for the use of brute force enumeration techniques to identify valid IAM usernames in an arbitrary AWS accoun…

CVSS 6.9 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-23214

Published Jan 20, 2025

Cosmos provides users the ability self-host a home server by acting as a secure gateway to your application, as well as a server manager. By monitoring the error code returned in…

CVSS 6.9 · Medium

CVE-2024-42174

Published Jan 11, 2025

HCL MyXalytics is affected by username enumeration vulnerability. This allows a malicious user to perform enumeration of application users, and therefore compile a list of valid…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-13198

Published Jan 9, 2025

A vulnerability classified as problematic has been found in langhsu Mblog Blog System 3.5.0. Affected is an unknown function of the file /login. The manipulation leads to observab…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-13028

Published Dec 29, 2024

A vulnerability, which was classified as problematic, has been found in Antabot White-Jotter up to 0.2.2. This issue affects some unknown processing of the file /login. The manipu…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-12663

Published Dec 16, 2024

A vulnerability classified as problematic was found in funnyzpc Mee-Admin up to 1.6. This vulnerability affects unknown code of the file /mee/login of the component Login. The man…

CVSS 6.3 · Medium

CVE-2022-20633

Published Nov 15, 2024

A vulnerability in the web-based management interface of Cisco ECE could allow an unauthenticated, remote attacker to perform a username enumeration attack against an affecte…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-47129

Published Sep 26, 2024

The goTenna Pro App does not inject extra characters into broadcasted frames to obfuscate the length of messages. This makes it possible to tell the length of the payload regard…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-41715

Published Sep 26, 2024

The goTenna Pro ATAK Plugin does not inject extra characters into broadcasted frames to obfuscate the length of messages. This makes it possible to tell the length of the payloa…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-34336

Published Sep 12, 2024

User enumeration vulnerability in ORDAT FOSS-Online before v2.24.01 allows attackers to determine if an account exists in the application by comparing the server responses of the…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-49069

Published Sep 10, 2024

A vulnerability has been identified in Mendix Runtime V10 (All versions < V10.17.0 only if the basic authentication mechanism is used by the application), Mendix Runtime V10.12 (A…

CVSS 6.9 · Medium

CVE-2024-40627

Published Jul 15, 2024

Fastapi OPA is an opensource fastapi middleware which includes auth flow. HTTP `OPTIONS` requests are always allowed by `OpaMiddleware`, even when they lack authentication, and ar…

CVSS 5.8 · Medium

CVE-2024-39912

Published Jul 15, 2024

web-auth/webauthn-lib is an open source set of PHP libraries and a Symfony bundle to allow developers to integrate that authentication mechanism into their web applications. The P…

CVSS 5.3 · Medium

CVE-2023-33859

Published Jul 10, 2024

IBM Security QRadar EDR 3.12 could disclose sensitive information due to an observable login response discrepancy. IBM X-Force ID: 257697.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-39211

Published Jul 4, 2024

Kaiten 57.128.8 allows remote attackers to enumerate user accounts via a crafted POST request, because a login response contains a user_email field only if the user account exists.

CVSS 5.3 · Medium

CVE-2024-6056

Published Jun 17, 2024

A vulnerability was found in nasirkhan Laravel Starter up to 11.8.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /forgot-pas…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-31870

Published Jun 15, 2024

IBM Db2 for i 7.2, 7.3, 7.4, and 7.5 supplies user defined table function is vulnerable to user enumeration by a local authenticated attacker, without having authority to the rela…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-33856

Published May 7, 2024

An issue was discovered in Logpoint before 7.4.0. An attacker can enumerate a valid list of usernames by observing the response time at the Forgot Password endpoint.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 101-125 of 167 CVEsPage 5 of 7