CWE-203: CWE-203

94
Total CVEs
9
Critical
38
High
6.5
Avg CVSS

Yearly Trend

2026
7
2025
31
2024
35
2023
10
2022
4

Top Affected Vendors

1 Google 7
2 Debian 5
3 Fedoraproject 4
4 Liferay 3
5 Linux 3
6 Microsoft 3
7 Oracle 3
8 Honor 3
9 Ibm 2
10 Monospace 2

All CWE-203 CVEs (94)

CVE-2019-25337
9.8

CVE-2019-25337 is a username enumeration vulnerability in ownCloud that allows remote attackers to discover valid user accounts by sending crafted req...

Feb 12, 2026
CVE-2025-27667
9.8

This vulnerability allows attackers to enumerate administrative user email addresses in Vasion Print (formerly PrinterLogic) systems. Attackers can id...

Mar 5, 2025
CVE-2024-25714
9.8

CVE-2024-25714 is a critical timing side-channel vulnerability in Rhonabwy's HMAC signature verification that allows attackers to potentially forge va...

Feb 11, 2024
CVE-2024-25190
9.8

CVE-2024-25190 is a timing side-channel vulnerability in l8w8jwt 2.2.1 that allows attackers to bypass authentication by exploiting non-constant-time ...

Feb 8, 2024
CVE-2024-23771
9.8

This vulnerability in darkhttpd allows remote attackers to bypass authentication via timing side-channel attacks. The web server uses non-constant-tim...

Jan 22, 2024
CVE-2023-40756
9.8

This vulnerability in PHPJabbers Callback Widget v1.0 allows attackers to enumerate valid user accounts through differences in password recovery messa...

Aug 28, 2023
CVE-2022-23303
9.8

CVE-2022-23303 is a side-channel vulnerability in SAE (Simultaneous Authentication of Equals) implementations in hostapd and wpa_supplicant that allow...

Jan 17, 2022
CVE-2023-26556
9.1

This vulnerability allows attackers to extract secret cryptographic keys through timing side-channel attacks in threshold signature implementations. T...

Apr 21, 2023
CVE-2021-1924
9.0

This vulnerability allows attackers to extract RSA private keys through timing and power side-channel attacks during modular exponentiation in RSA-CRT...

Nov 12, 2021
CVE-2023-5410
8.2

This vulnerability in HP PC system BIOS could allow attackers to tamper with memory, potentially leading to privilege escalation or system compromise....

Mar 12, 2024
CVE-2024-43095
7.8

This CVE describes a logic error in Android that allows local attackers to obtain any system permission without additional privileges. User interactio...

Jan 21, 2025
CVE-2023-21337
7.8

This vulnerability in Android's InputMethod allows attackers to determine whether specific apps are installed without requiring query permissions, exp...

Oct 30, 2023
CVE-2023-21324
7.8

This vulnerability in Android's Package Installer allows attackers to detect whether specific apps are installed without requiring query permissions, ...

Oct 30, 2023
CVE-2023-21298
7.8

This vulnerability in Android's Slice component allows attackers to detect which applications are installed on a device through side-channel analysis....

Oct 30, 2023
CVE-2026-26315
7.5

A cryptographic flaw in go-ethereum's ECIES implementation allows attackers to extract bits of the p2p node key. This affects all Geth nodes running v...

Feb 19, 2026
CVE-2022-50800
7.5

H3C SSL VPN has a user enumeration vulnerability that allows attackers to determine valid usernames by analyzing login response differences. Attackers...

Dec 30, 2025
CVE-2025-12888
7.5

This vulnerability allows attackers to extract private keys from X25519 cryptographic implementations on Xtensa-based ESP32 chips through timing side-...

Nov 21, 2025
CVE-2025-6386
7.5

This timing attack vulnerability in the parisneo/lollms authentication system allows attackers to enumerate valid usernames and guess passwords by ana...

Jul 7, 2025
CVE-2025-1468
7.5

An unauthenticated remote attacker can access sensitive authentication information in CODESYS OPC UA Server when using the non-default Basic128Rsa15 s...

Mar 18, 2025
CVE-2024-41335
7.5

This vulnerability in Draytek routers allows attackers to perform timing attacks against insecure strcmp/memcmp implementations, potentially revealing...

Feb 27, 2025
CVE-2025-21510
7.5

This vulnerability in Oracle JD Edwards EnterpriseOne Tools allows unauthenticated attackers to remotely access sensitive data via HTTP. It affects We...

Jan 21, 2025
CVE-2024-54767
7.5

An access control vulnerability in AVM FRITZ!Box 7530 AX routers allows unauthenticated attackers to access sensitive system information via the /juis...

Jan 6, 2025
CVE-2018-9364
7.5

CVE-2018-9364 is a vulnerability in LG's LAF component that allows modification of protected partitions without user interaction. This could lead to s...

Nov 19, 2024
CVE-2024-39921
7.5

A timing side-channel vulnerability in IPCOM EX2 and VE2 series devices allows attackers to potentially decrypt encrypted communications by analyzing ...

Sep 4, 2024
CVE-2024-37880
7.5

This vulnerability allows attackers to recover ML-KEM 512 secret keys through timing side-channel attacks when the Kyber reference implementation is c...

Jun 10, 2024
CVE-2024-5124
7.5

This timing attack vulnerability in gaizhenbiao/chuanhuchatgpt allows attackers to guess passwords by measuring how long password comparisons take. At...

Jun 6, 2024
CVE-2022-45177
7.5

This vulnerability in LIVEBOX Collaboration vDesk allows attackers to infer internal system state information through observable response discrepancie...

Feb 21, 2024
CVE-2024-21484
7.5

This vulnerability allows attackers to decrypt RSA-encrypted data by exploiting timing discrepancies in the jsrsasign library's PKCS1.5 and RSAOAEP de...

Jan 22, 2024
CVE-2023-45287
7.5

This CVE describes a timing side-channel vulnerability in Go's RSA-based TLS key exchange implementation prior to version 1.20. Attackers could potent...

Dec 5, 2023
CVE-2023-36127
7.5

CVE-2023-36127 is a user enumeration vulnerability in PHPJabbers Appointment Scheduler 3.0 that allows attackers to determine valid usernames via pass...

Oct 10, 2023
CVE-2023-33741
7.5

The Macrovideo v380pro security camera firmware v1.4.97 exposes device credentials when sharing camera access. This allows unauthorized users to obtai...

May 30, 2023
CVE-2023-29850
7.5

SENAYAN Library Management System (SLiMS) Bulian v9.5.2 fails to strip EXIF metadata from uploaded images, allowing attackers to extract sensitive inf...

Apr 14, 2023
CVE-2022-24912
7.5

This vulnerability allows attackers to perform timing attacks against the webhook secret validation in Atlantis, potentially recovering the secret thr...

Jul 29, 2022
CVE-2022-34174
7.5

This vulnerability in Jenkins creates a timing side-channel in the login form that allows attackers to distinguish between invalid usernames and valid...

Jun 23, 2022
CVE-2020-36517
7.5

This vulnerability allows DNS operators to discover internal network resources through hardcoded DNS resolver configurations in Home Assistant systems...

Mar 10, 2022
CVE-2021-38562
7.5

This vulnerability in Best Practical Request Tracker (RT) allows attackers to perform timing attacks against the REST2 authentication middleware, pote...

Oct 18, 2021
CVE-2021-37848
7.5

This vulnerability in Pengutronix barebox bootloader leaks timing information during password hash comparison, allowing attackers to perform timing at...

Aug 2, 2021
CVE-2021-34575
7.5

This vulnerability allows unauthenticated attackers to enumerate valid user accounts in MB connect line mymbCONNECT24 and mbCONNECT24 software. By ana...

Aug 2, 2021
CVE-2021-33560
7.5

This vulnerability in Libgcrypt allows side-channel attacks against ElGamal encryption due to missing exponent blinding and inappropriate window size ...

Jun 8, 2021
CVE-2021-33838
7.5

The Luca COVID-19 contact tracing app for Android versions through 1.7.4 leaks sensitive information about users' COVID-19 status. Remote attackers ca...

Jun 4, 2021
CVE-2020-1459
7.5

CVE-2020-1459 is a speculative execution side-channel vulnerability affecting ARM processors that allows local attackers to potentially access sensiti...

Aug 17, 2020
CVE-2023-51437
7.4

This vulnerability allows attackers to forge SASL Role Tokens that pass signature verification due to timing discrepancies in Apache Pulsar's authenti...

Feb 7, 2024
CVE-2024-23342
7.4

CVE-2024-23342 is a vulnerability in the Python ecdsa package that allows attackers to perform side-channel timing attacks (Minerva attack) to extract...

Jan 23, 2024
CVE-2023-0361
7.4

This CVE describes a timing side-channel vulnerability in GnuTLS that allows attackers to perform Bleichenbacher-style attacks against RSA encryption....

Feb 15, 2023
CVE-2023-30312
7.3

This vulnerability allows off-path attackers to hijack TCP sessions on OpenWrt routers with NAT enabled, enabling them to impersonate clients or serve...

May 28, 2024
CVE-2025-59702
7.2

This vulnerability allows a physically proximate attacker with elevated privileges to falsify tamper events on Entrust nShield hardware security modul...

Dec 2, 2025
CVE-2025-39702
7.0

This CVE addresses a timing side-channel vulnerability in the Linux kernel's IPv6 Segment Routing (SR) implementation. Attackers could potentially exp...

Sep 5, 2025
CVE-2024-8994
6.2

This CVE describes an information leak vulnerability affecting certain Honor products. Successful exploitation could allow unauthorized access to sens...

Dec 26, 2024
CVE-2024-28885
5.9

This vulnerability in Intel QAT Engine for OpenSSL before version 1.6.1 allows an attacker to infer sensitive information through timing discrepancies...

Nov 13, 2024
CVE-2024-50382
5.9

This vulnerability in Botan's AES-GCM implementation allows side-channel attacks through compiler-induced secret-dependent control flow. Attackers cou...

Oct 23, 2024

About CWE-203 (CWE-203)

Our database tracks 94 CVEs classified as CWE-203, with 9 rated critical and 38 rated high severity. The average CVSS score for CWE-203 vulnerabilities is 6.5.

External reference: View CWE-203 on MITRE CWE →

Monitor CWE-203 Vulnerabilities

Get alerted when new CWE-203 CVEs affect your infrastructure.

Start Monitoring Free