Threats Tagged 'cwe-204'
View all threats tagged with 'cwe-204'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-204'
Click on any threat for detailed analysis and mitigation recommendations
0 Smart Video Intercom System developed by Kingdom Communication Associated has a Sensitive Data Exposure vulnerability. Unauthenticated remote attackers can enumerate valid user accounts by exploiting differences in system responses. Join the discussion | CVE Database V5 | 09/11/2026, 07:27:52 UTC Added: 09/11/2026, 07:47:51 UTC |
Observable response discrepancy vulnerability in DernekPlus Website Template allows Account Footprinting. This issue affects Website Template: through 10092026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. Join the discussion | CVE Database V5 | 09/10/2026, 12:06:25 UTC Added: 09/10/2026, 12:38:09 UTC |
0 Observable response discrepancy vulnerability in GastroMenum GastroMenum Web Panel allows Account Footprinting. This issue affects GastroMenum Web Panel: before 31.08.2026. Join the discussion | CVE Database V5 | 09/04/2026, 14:08:37 UTC Added: 09/04/2026, 14:23:06 UTC |
0 Observable response discrepancy vulnerability in Menulux Software Inc. Menulux Portal allows Account Footprinting. This issue affects Menulux Portal: before 20260903211448. Join the discussion | CVE Database V5 | 09/04/2026, 11:56:51 UTC Added: 09/04/2026, 12:07:53 UTC |
Observable Response Discrepancy (CWE-204) in the Kibana Osquery feature can lead to information disclosure via Query System for Information (CAPEC-54). An authenticated user holding Osquery live-query privileges could determine whether a scheduled query identifier exists in a Kibana space they are not authorized to access. Join the discussion | CVE Database V5 | 09/02/2026, 14:43:22 UTC Added: 09/02/2026, 14:52:55 UTC |
Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.12.5 and 5.7.5, packages/panels/src/Auth/Pages/Login.php presents the multi-factor authentication challenge before evaluating canAccessPanel(). For an account that canAccessPanel() denies, submitting the correct password renders the MFA challenge while an incorrect password returns the generic authentication failure, allowing an unauthenticated attacker to confirm whether a candidate password is valid for that account. When email-based MFA is configured, the correct-password path also sends a login code to the account holder. The issue applies only to accounts that have MFA enabled and are denied panel access. Authentication is not bypassed because canAccessPanel() still runs after the challenge, and no session is created. This issue is fixed in versions 4.12.5 and 5.7.5. Join the discussion | CVE Database V5 | 09/01/2026, 19:13:49 UTC Added: 09/01/2026, 19:22:48 UTC |
Combodo iTop versions prior to 3.2.3 have a vulnerability in the password reset mechanism that allows user enumeration through observable differences in responses to valid versus invalid usernames. This issue has been addressed and fixed in version 3.2.3. Join the discussion | CVE Database V5 | 08/21/2026, 19:52:04 UTC Added: 08/21/2026, 20:07:45 UTC |
0 Observable response discrepancy in Azure Stack HCI allows an unauthorized attacker to disclose information over a network. Join the discussion | CVE Database V5 | 08/20/2026, 21:43:11 UTC Added: 08/20/2026, 21:54:20 UTC |
CVE-2026-54739 is a vulnerability in LemmyNet's lemmy software where the login endpoint reveals whether a username or email exists by returning different error responses. This discrepancy allows unauthenticated attackers to enumerate valid accounts, facilitating targeted credential attacks or social engineering. The issue affects versions prior to 0.19.19 and versions from 1.0.0-alpha.0 up to but excluding 1.0.0-beta.1. It is fixed in versions 0.19.19 and 1.0.0-beta.1. Join the discussion | CVE Database V5 | 08/19/2026, 20:16:01 UTC Added: 08/20/2026, 11:11:47 UTC |
0 A vulnerability in PostgreSQL's SCRAM authentication mechanism allows an unauthenticated attacker to determine if a user exists by observing differences in the SCRAM iteration count in authentication responses. This issue affects PostgreSQL major versions 16 through 18, specifically versions before 16.15, 17.11, and 18.5. Versions prior to 16 are not affected. The vulnerability arises because the authentication challenge for nonexistent users always reports the default iteration count, while users with non-default scram_iterations reveal a different count, enabling a user existence oracle. Join the discussion | GCVE Database | 08/19/2026, 08:52:38 UTC Added: 08/13/2026, 17:48:23 UTC |
Showing 1 to 10 of 72 results