CWE-204: CWE-204

46
Total CVEs
0
Critical
2
High
5.3
Avg CVSS

Yearly Trend

2026
5
2025
31
2024
9
2021
1

Top Affected Vendors

1 Ibm 4
2 Dlink 2
3 Sick 2
4 Medtronic 1
5 Difuse 1
6 Enalean 1
7 Fortinet 1
8 Sonicwall 1
9 Logpoint 1
10 Windu 1

All CWE-204 CVEs (46)

CVE-2025-46390
7.5

CVE-2025-46390 is an observable response discrepancy vulnerability (CWE-204) that allows attackers to infer sensitive information by analyzing differe...

Aug 6, 2025
CVE-2021-20049
7.5

CVE-2021-20049 is a username enumeration vulnerability in SonicWall SMA100's password change API that allows unauthenticated attackers to determine va...

Dec 23, 2021
CVE-2025-67874
6.5

ChurchCRM versions before 6.5.0 echo plaintext passwords back in HTTP responses, allowing attackers to steal user credentials. This affects all Church...

Dec 16, 2025
CVE-2025-66307
6.5

This vulnerability in Grav's admin plugin allows attackers to enumerate valid usernames and discover associated email addresses through the 'Forgot Pa...

Dec 1, 2025
CVE-2025-9824
5.9

This vulnerability allows attackers to determine whether specific usernames exist in a system by measuring differences in login response times. This e...

Sep 3, 2025
CVE-2026-26744
5.3

A user enumeration vulnerability in FormaLMS 4.1.18 and earlier allows unauthenticated attackers to determine valid usernames via the password recover...

Feb 19, 2026
CVE-2026-25509
5.3

CVE-2026-25509 is an email enumeration vulnerability in CI4MS, a CodeIgniter 4-based CMS skeleton. Unauthenticated attackers can determine whether spe...

Feb 3, 2026
CVE-2026-24664
5.3

CVE-2026-24664 is a username enumeration vulnerability in Open eClass (formerly GUnet eClass) that allows unauthenticated attackers to identify valid ...

Feb 3, 2026
CVE-2026-23511
5.3

CVE-2026-23511 is a user enumeration vulnerability in ZITADEL identity management platform that allows unauthenticated attackers to confirm valid user...

Jan 15, 2026
CVE-2025-62181
5.3

Pega Platform versions 7.1.0 through Infinity 25.1.0 have a user enumeration vulnerability in the deprecated basic authentication feature. Attackers c...

Dec 10, 2025
CVE-2025-40806
5.3

Gridscale X Prepay versions before V4.2.1 have a user enumeration vulnerability where attackers can distinguish between valid and invalid users based ...

Dec 9, 2025
CVE-2025-65899
5.3

CVE-2025-65899 is a user enumeration vulnerability in Kalmia CMS that allows unauthenticated attackers to determine valid usernames by observing diffe...

Dec 4, 2025
CVE-2025-12994
5.3

Medtronic CareLink Network has an information disclosure vulnerability where unauthenticated remote attackers can query an API endpoint to determine i...

Dec 4, 2025
CVE-2025-59116
5.3

Windu CMS version 4.1 is vulnerable to user enumeration during login, allowing attackers to determine valid usernames by analyzing response difference...

Nov 18, 2025
CVE-2025-25236
5.3

Omnissa Workspace ONE UEM has an observable response discrepancy vulnerability that allows attackers to enumerate sensitive information like tenant ID...

Nov 12, 2025
CVE-2025-34254
5.3

This vulnerability allows unauthenticated remote attackers to enumerate valid usernames on D-Link Nuclias Connect systems by observing different error...

Oct 16, 2025
CVE-2025-34255
5.3

This vulnerability allows unauthenticated attackers to enumerate valid email addresses on D-Link Nuclias Connect systems by exploiting response differ...

Oct 16, 2025
CVE-2025-61789
5.3

This vulnerability in Icinga DB Web allows authorized users to bypass variable protection mechanisms and guess values of protected or hidden custom va...

Oct 16, 2025
CVE-2025-58586
5.3

This vulnerability allows attackers to enumerate valid usernames by observing different error messages for incorrect passwords versus non-existent use...

Oct 6, 2025
CVE-2025-56764
5.3

This vulnerability allows attackers to enumerate valid usernames on Trivision NC-227WF devices by exploiting inconsistent error messages during login ...

Sep 29, 2025
CVE-2025-58442
5.3

This vulnerability in Saleor e-commerce platform allows attackers to determine whether a specific email address exists in the system by analyzing erro...

Sep 9, 2025
CVE-2025-52899
5.3

This vulnerability in Tuleap's forgot password form allows attackers to enumerate valid usernames by observing differences in response times or error ...

Jul 29, 2025
CVE-2025-27451
5.3

This vulnerability allows attackers to enumerate valid usernames by observing different error messages for incorrect passwords versus non-existent use...

Jul 3, 2025
CVE-2025-49187
5.3

This vulnerability allows attackers to enumerate valid usernames by observing different error messages for incorrect passwords versus non-existent use...

Jun 12, 2025
CVE-2025-3939
5.3

This CVE describes an Observable Response Discrepancy vulnerability in Tridium Niagara Framework and Enterprise Security that allows cryptanalysis. At...

May 22, 2025
CVE-2025-46736
5.3

This CVE describes a timing attack vulnerability in Umbraco CMS that allows attackers to determine whether specific user accounts exist by analyzing p...

May 6, 2025
CVE-2024-55198
5.3

This vulnerability in Celk Sistemas Celk Saude v.3.1.252.1 allows remote attackers to enumerate valid usernames by analyzing differences in error mess...

Mar 13, 2025
CVE-2025-23193
5.3

CVE-2025-23193 is an information disclosure vulnerability in SAP NetWeaver Server ABAP that allows unauthenticated attackers to determine whether spec...

Feb 11, 2025
CVE-2025-24980
5.3

This vulnerability in pimcore/admin-ui-classic-bundle allows attackers to enumerate valid user accounts via the 'Forgot password' function due to impr...

Feb 7, 2025
CVE-2023-37413
5.3

IBM Aspera Faspex versions 5.0.0 through 5.0.10 can leak sensitive username information through observable response discrepancies. This vulnerability ...

Jan 29, 2025
CVE-2025-0693
5.3

This vulnerability in AWS Sign-in allows attackers to use timing differences in IAM user login responses to brute-force enumerate valid usernames in A...

Jan 23, 2025
CVE-2024-36510
5.3

This vulnerability allows unauthenticated attackers to enumerate valid user accounts on Fortinet products by observing differences in login response b...

Jan 14, 2025
CVE-2022-20633
5.3

This vulnerability in Cisco ECE allows unauthenticated remote attackers to enumerate valid usernames by analyzing differences in authentication respon...

Nov 15, 2024
CVE-2024-8651
5.3

This vulnerability in NetCat CMS allows attackers to determine whether specific usernames exist in the system by sending specially crafted HTTP reques...

Sep 19, 2024
CVE-2023-49069
5.3

This vulnerability allows unauthenticated remote attackers to distinguish between valid and invalid usernames in Mendix applications using basic authe...

Sep 10, 2024
CVE-2024-42343
5.3

This CVE describes an observable response discrepancy vulnerability in Loway software where attackers can infer information about system state through...

Sep 8, 2024
CVE-2024-39912
5.3

This vulnerability in web-auth/webauthn-lib allows attackers to enumerate valid usernames when WebAuthn is used as the primary authentication method. ...

Jul 15, 2024
CVE-2024-38322
5.3

IBM Storage Defender - Resiliency Service versions 2.0.0 through 2.0.4 have a username and password error response discrepancy that allows attackers t...

Jun 28, 2024
CVE-2024-33856
5.3

This vulnerability in Logpoint allows attackers to enumerate valid usernames by timing responses from the Forgot Password endpoint. Attackers can iden...

May 7, 2024
CVE-2021-20556
5.3

This vulnerability in IBM Cognos Controller allows remote attackers to enumerate valid usernames by analyzing differences in error messages. Attackers...

May 3, 2024
CVE-2026-24332
4.3

This CVE reveals that Discord's WebSocket API leaks information about users who set their status to 'Invisible'. The API incorrectly includes invisibl...

Jan 22, 2026
CVE-2025-42903
4.3

This vulnerability in SAP Financial Service Claims Management allows attackers to enumerate valid user accounts and potentially disclose personal data...

Oct 14, 2025
CVE-2023-47159
4.3

IBM Sterling File Gateway versions 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.1 contain an information disclosure vulnerability where authentic...

Jan 27, 2025
CVE-2024-47129
4.3

The goTenna Pro App fails to pad broadcasted frames with extra characters, allowing attackers to determine the length of encrypted messages. This info...

Sep 26, 2024
CVE-2025-67500
3.7

This vulnerability in Mastodon allows attackers to confirm the existence of private statuses by sending requests with non-English Accept-Language head...

Dec 10, 2025
CVE-2021-47717
N/A

IntelliChoice eFORCE Software Suite 2.5.9 contains a username enumeration vulnerability that allows attackers to determine valid user accounts by anal...

Dec 9, 2025

About CWE-204 (CWE-204)

Our database tracks 46 CVEs classified as CWE-204, with 0 rated critical and 2 rated high severity. The average CVSS score for CWE-204 vulnerabilities is 5.3.

External reference: View CWE-204 on MITRE CWE →

Monitor CWE-204 Vulnerabilities

Get alerted when new CWE-204 CVEs affect your infrastructure.

Start Monitoring Free