Skip to main content

Threats Tagged 'cwe-204'

View all threats tagged with 'cwe-204'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-204

Threats Tagged 'cwe-204'

Click on any threat for detailed analysis and mitigation recommendations

Smart Video Intercom System developed by Kingdom Communication Associated has a Sensitive Data Exposure vulnerability. Unauthenticated remote attackers can enumerate valid user accounts by exploiting differences in system responses.

Join the discussion

Observable response discrepancy vulnerability in DernekPlus Website Template allows Account Footprinting. This issue affects Website Template: through 10092026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

Join the discussion

Observable response discrepancy vulnerability in GastroMenum GastroMenum Web Panel allows Account Footprinting. This issue affects GastroMenum Web Panel: before 31.08.2026.

Join the discussion

Observable response discrepancy vulnerability in Menulux Software Inc. Menulux Portal allows Account Footprinting. This issue affects Menulux Portal: before 20260903211448.

Join the discussion

Observable Response Discrepancy (CWE-204) in the Kibana Osquery feature can lead to information disclosure via Query System for Information (CAPEC-54). An authenticated user holding Osquery live-query privileges could determine whether a scheduled query identifier exists in a Kibana space they are not authorized to access.

Join the discussion

Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.12.5 and 5.7.5, packages/panels/src/Auth/Pages/Login.php presents the multi-factor authentication challenge before evaluating canAccessPanel(). For an account that canAccessPanel() denies, submitting the correct password renders the MFA challenge while an incorrect password returns the generic authentication failure, allowing an unauthenticated attacker to confirm whether a candidate password is valid for that account. When email-based MFA is configured, the correct-password path also sends a login code to the account holder. The issue applies only to accounts that have MFA enabled and are denied panel access. Authentication is not bypassed because canAccessPanel() still runs after the challenge, and no session is created. This issue is fixed in versions 4.12.5 and 5.7.5.

Join the discussion

Combodo iTop versions prior to 3.2.3 have a vulnerability in the password reset mechanism that allows user enumeration through observable differences in responses to valid versus invalid usernames. This issue has been addressed and fixed in version 3.2.3.

Join the discussion

Observable response discrepancy in Azure Stack HCI allows an unauthorized attacker to disclose information over a network.

Join the discussion

CVE-2026-54739 is a vulnerability in LemmyNet's lemmy software where the login endpoint reveals whether a username or email exists by returning different error responses. This discrepancy allows unauthenticated attackers to enumerate valid accounts, facilitating targeted credential attacks or social engineering. The issue affects versions prior to 0.19.19 and versions from 1.0.0-alpha.0 up to but excluding 1.0.0-beta.1. It is fixed in versions 0.19.19 and 1.0.0-beta.1.

Join the discussion

A vulnerability in PostgreSQL's SCRAM authentication mechanism allows an unauthenticated attacker to determine if a user exists by observing differences in the SCRAM iteration count in authentication responses. This issue affects PostgreSQL major versions 16 through 18, specifically versions before 16.15, 17.11, and 18.5. Versions prior to 16 are not affected. The vulnerability arises because the authentication challenge for nonexistent users always reports the default iteration count, while users with non-default scram_iterations reveal a different count, enabling a user existence oracle.

Join the discussion

Showing 1 to 10 of 72 results

Filters:Tag: cwe-204
Page 1 of 8
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses