VYPR

CWE-203

Observable Discrepancy

BaseIncomplete

Description

The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-189

CVEs mapped to this weakness (798)

page 27 of 40
  • CVE-2026-87516MedSep 9, 2026
    risk 0.28cvss 4.3epss 0.00

    Observable discrepancy in Navigation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-79016MedAug 25, 2026
    risk 0.28cvss 4.3epss 0.00

    Observable discrepancy in SVG in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-56319MedJun 20, 2026
    risk 0.28cvss 4.3epss 0.00

    Capgo before 12.128.2 contains an information disclosure vulnerability in the GET /statistics/app/:app_id endpoint that allows app-limited API keys to distinguish existing sibling app IDs through differential error responses. Attackers can enumerate real app IDs outside their…

  • CVE-2023-5872MedApr 16, 2026
    risk 0.28cvss 4.3epss 0.00

    In Wago Smart Designer in versions up to 2.33.1 a low privileged remote attacker may enumerate projects and usernames through iterative requests to an specific endpoint.

  • CVE-2026-23621MedFeb 19, 2026
    risk 0.28cvss 4.3epss 0.00

    GFI MailEssentials AI versions prior to 22.4 contain an arbitrary directory existence enumeration vulnerability in the ListServer.IsPathExist() web method exposed at /MailEssentials/pages/MailSecurity/ListServer.aspx/IsPathExist. An authenticated user can supply an unrestricted…

  • CVE-2026-23620MedFeb 19, 2026
    risk 0.28cvss 4.3epss 0.00

    GFI MailEssentials AI versions prior to 22.4 contain an arbitrary file existence enumeration vulnerability in the ListServer.IsDBExist() web method exposed at /MailEssentials/pages/MailSecurity/ListServer.aspx/IsDBExist. An authenticated user can supply an unrestricted…

  • CVE-2026-25562MedFeb 7, 2026
    risk 0.28cvss 4.3epss 0.00

    WeKan versions prior to 8.19 contain an information disclosure vulnerability in the attachments publication. Attachment metadata can be returned without properly scoping results to boards and cards accessible to the requesting user, potentially exposing attachment metadata to…

  • CVE-2025-36225MedOct 9, 2025
    risk 0.28cvss 4.3epss 0.00

    IBM Aspera 5.0.0 through 5.0.13.1 could disclose sensitive user information from the system to an authenticated user due to an observable discrepancy of returned data.

  • CVE-2025-9031MedSep 24, 2025
    risk 0.28cvss 4.3epss 0.00

    Observable Timing Discrepancy vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive Web allows Cross-Domain Search Timing. This issue affects DivvyDrive Web: from 4.8.2.2 before 4.8.2.15.

  • CVE-2025-23182MedMay 22, 2025
    risk 0.28cvss 4.3epss 0.00

    CWE-203: Observable Discrepancy

  • CVE-2025-0361MedApr 8, 2025
    risk 0.28cvss 4.3epss 0.00

    During an annual penetration test conducted on behalf of Axis Communications, Truesec discovered a flaw in the VAPIX Device Configuration framework that allowed for unauthenticated username enumeration through the VAPIX Device Configuration SSH Management API.

  • CVE-2024-51477MedMar 29, 2025
    risk 0.28cvss 4.3epss 0.00

    IBM InfoSphere Information Server 11.7 could allow an authenticated to obtain sensitive username information due to an observable response discrepancy.

  • CVE-2024-45089MedJan 31, 2025
    risk 0.28cvss 4.3epss 0.00

    IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 Standard Edition EBICS server could allow an authenticated user to obtain sensitive filename information due to an observable discrepancy.

  • CVE-2023-47159MedJan 27, 2025
    risk 0.28cvss 4.3epss 0.00

    IBM Sterling File Gateway 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.1 could allow an authenticated user to enumerate usernames due to an observable discrepancy in request responses.

  • CVE-2025-24011MedJan 21, 2025
    risk 0.28cvss 5.3epss 0.02

    Umbraco is a free and open source .NET content management system. Starting in version 14.0.0 and prior to versions 14.3.2 and 15.1.2, it's possible to determine whether an account exists based on an analysis of response codes and timing of Umbraco management API responses.…

  • CVE-2024-21233MedOct 15, 2024
    risk 0.28cvss 4.3epss 0.00

    Vulnerability in the Oracle Database Core component of Oracle Database Server. Supported versions that are affected are 19.3-19.24, 21.3-21.15 and 23.4-23.5. Easily exploitable vulnerability allows low privileged attacker having Create Session privilege with network access via…

  • CVE-2024-21206MedOct 15, 2024
    risk 0.28cvss 4.3epss 0.00

    Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Diagnostics). Supported versions that are affected are ECC:11-13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to…

  • CVE-2024-45231MedOct 8, 2024
    risk 0.28cvss 5.3epss 0.01

    An issue was discovered in Django v5.1.1, v5.0.9, and v4.2.16. The django.contrib.auth.forms.PasswordResetForm class, when used in a view implementing password reset flows, allows remote attackers to enumerate user e-mail addresses by sending password reset requests and…

  • CVE-2024-47129MedSep 26, 2024
    risk 0.28cvss 4.3epss 0.00

    The goTenna Pro App does not inject extra characters into broadcasted frames to obfuscate the length of messages. This makes it possible to tell the length of the payload regardless of the encryption used.

  • CVE-2024-41715MedSep 26, 2024
    risk 0.28cvss 4.3epss 0.00

    The goTenna Pro ATAK Plugin does not inject extra characters into broadcasted frames to obfuscate the length of messages. This makes it possible to tell the length of the payload regardless of the encryption used.