CWE-204
138 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-204page 1 of 3
- CVE-2016-9499MEDIUMCVSS 5.3EG 5.32018-07-13
Accellion FTP server prior to version FTA_9_12_220 only returns the username in the server response if the username is invalid. An attacker may use this information to determine valid user accounts and enumerate them.
- CVE-2018-25350CRITICALCVSS 9.8EG 9.82026-05-26
userSpice 4.3.24 contains a username enumeration vulnerability that allows unauthenticated attackers to discover valid usernames by sending POST requests to the existingUsernameCheck.php endpoint. Attackers can submit usernames and analyze…
- CVE-2019-19030MEDIUMCVSS 5.3EG 5.32022-12-26
Cloud Native Computing Foundation Harbor before 1.10.3 and 2.x before 2.0.1 allows resource enumeration because unauthenticated API calls reveal (via the HTTP status code) whether a resource exists.
- CVE-2019-25338MEDIUMCVSS 5.3EG 7.52026-02-12
DokuWiki 2018-04-22b contains a username enumeration vulnerability in its password reset functionality that allows attackers to identify valid user accounts. Attackers can submit different usernames to the password reset endpoint and disti…
- CVE-2020-11063LOWCVSS 3.7EG 3.72020-05-13
In TYPO3 CMS versions 10.4.0 and 10.4.1, it has been discovered that time-based attacks can be used with the password reset functionality for backend users. This allows an attacker to mount user enumeration based on email addresses assigne…
- CVE-2021-20049HIGHCVSS 7.5EG 7.52021-12-23
A vulnerability in SonicWall SMA100 password change API allows a remote unauthenticated attacker to perform SMA100 username enumeration based on the server responses. This vulnerability impacts 10.2.1.2-24sv, 10.2.0.8-37sv and earlier 10.x…
- CVE-2021-20556MEDIUMCVSS 5.3EG 5.32024-05-03
IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 could allow a remote user to enumerate usernames due to differentiating error messages on existing usernames. IBM X-Force ID: 199181.
- CVE-2021-34580HIGHCVSS 7.5EG 7.52021-10-27
In mymbCONNECT24, mbCONNECT24 <= 2.9.0 an unauthenticated user can enumerate valid backend users by checking what kind of response the server sends for crafted invalid login attempts.
- CVE-2021-36201MEDIUMCVSS 4.3EG 5.32022-10-11
Under certain circumstances a CCURE Portal user could enumerate user accounts in CCURE 9000 version 2.90 and prior versions.
- CVE-2021-38476MEDIUMCVSS 6.5EG 6.52021-10-19
InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 authentication process response indicates and validates the existence of a username. This may allow an attacker to enumerate different user accounts.
- CVE-2021-39189MEDIUMCVSS 5.3EG 5.32021-09-15
Pimcore is an open source data & experience management platform. In versions prior to 10.1.3, it is possible to enumerate usernames via the forgot password functionality. This issue is fixed in version 10.1.3. As a workaround, one may appl…
- CVE-2021-47717MEDIUMCVSS 6.9EG 0.02025-12-09
IntelliChoice eFORCE Software Suite 2.5.9 contains a username enumeration vulnerability that allows attackers to enumerate valid users by exploiting the 'ctl00$MainContent$UserName' POST parameter. Attackers can send requests with valid us…
- CVE-2022-0564MEDIUMCVSS 5.3EG 5.32022-02-21
A vulnerability in Qlik Sense Enterprise on Windows could allow an remote attacker to enumerate domain user accounts. An attacker could exploit this vulnerability by sending authentication requests to an affected system. A successful explo…
- CVE-2022-1989MEDIUMCVSS 5.3EG 5.32022-08-23
All CODESYS Visualization versions before V4.2.0.0 generate a login dialog vulnerable to information exposure allowing a remote, unauthenticated attacker to enumerate valid users.
- CVE-2022-20633MEDIUMCVSS 5.3EG 5.32024-11-15
A vulnerability in the web-based management interface of Cisco ECE could allow an unauthenticated, remote attacker to perform a username enumeration attack against an affected device. This vulnerability is due to differences in aut…
- CVE-2022-22520MEDIUMCVSS 5.3EG 7.52022-09-14
A remote, unauthenticated attacker can enumerate valid users by sending specific requests to the webservice of MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2.
- CVE-2022-31248MEDIUMCVSS 5.3EG 5.32022-06-22
A Observable Response Discrepancy vulnerability in spacewalk-java of SUSE Manager Server 4.1, SUSE Manager Server 4.2 allows remote attackers to discover valid usernames. This issue affects: SUSE Manager Server 4.1 spacewalk-java versions …
- CVE-2022-39228MEDIUMCVSS 5.3EG 5.32023-03-01
vantage6 is a privacy preserving federated learning infrastructure for secure insight exchange. vantage6 does not inform the user of wrong username/password combination if the username actually exists. This is an attempt to prevent bots fr…
- CVE-2022-39315MEDIUMCVSS 6.5EG 6.52022-10-25
Kirby is a Content Management System. Prior to versions 3.5.8.2, 3.6.6.2, 3.7.5.1, and 3.8.1, a user enumeration vulnerability affects all Kirby sites with user accounts unless Kirby's API and Panel are disabled in the config. It can only …
- CVE-2022-41697MEDIUMCVSS 5.3EG 5.32022-12-22
A user enumeration vulnerability exists in the login functionality of Ghost Foundation Ghost 5.9.4. A specially-crafted HTTP request can lead to a disclosure of sensitive information. An attacker can send a series of HTTP requests to trigg…
- CVE-2023-1540MEDIUMCVSS 5.3EG 5.32023-03-21
Observable Response Discrepancy in GitHub repository answerdev/answer prior to 1.0.6.
- CVE-2023-23449MEDIUMCVSS 5.3EG 5.32023-05-15
Observable Response Discrepancy in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows a remote attacker to gain information about valid usernames by analyzing challenge responses…
- CVE-2023-23584MEDIUMCVSS 4.3EG 4.32023-12-18
An observable response discrepancy in the Gallagher Command Centre RESTAPI allows an insufficiently-privileged user to infer the presence of items that would not otherwise be viewable. This issue affects: Gallagher Command Centre 8.70 p…
- CVE-2023-27283MEDIUMCVSS 5.3EG 5.32024-05-04
IBM Aspera Orchestrator 4.0.1 could allow a remote attacker to enumerate usernames due to observable response discrepancies. IBM X-Force ID: 248545.
- CVE-2023-27464MEDIUMCVSS 5.3EG 5.32023-04-11
A vulnerability has been identified in Mendix Forgot Password (Mendix 7 compatible) (All versions < V3.7.1), Mendix Forgot Password (Mendix 8 compatible) (All versions < V4.1.1), Mendix Forgot Password (Mendix 9 compatible) (All versions <…
- CVE-2023-28412MEDIUMCVSS 5.3EG 5.32023-05-22
When supplied with a random MAC address, Snap One OvrC cloud servers will return information about the device. The MAC address of devices can be enumerated in an attack and the OvrC cloud will disclose their information. …
- CVE-2023-31186MEDIUMCVSS 5.3EG 5.32023-05-30
Avaya IX Workforce Engagement v15.2.7.1195 - User Enumeration - Observable Response Discrepancy
- CVE-2023-3221MEDIUMCVSS 5.3EG 5.32023-09-04
User enumeration vulnerability in Password Recovery plugin 1.2 version for Roundcube, which could allow a remote attacker to create a test script against the password recovery function to enumerate all users in the database.
- CVE-2023-32346MEDIUMCVSS 5.3EG 5.32023-05-22
Teltonika’s Remote Management System versions prior to 4.10.0 contain a function that allows users to claim their devices. This function returns information based on whether the serial number of a device has already been claimed, the MA…
- CVE-2023-3336MEDIUMCVSS 5.3EG 5.32023-07-05
TN-5900 Series version 3.3 and prior versions is vulnearble to user enumeration vulnerability. The vulnerability may allow a remote attacker to determine whether a user is valid during password recovery through the web login page and enabl…
- CVE-2023-33859MEDIUMCVSS 5.3EG 5.32024-07-10
IBM Security QRadar EDR 3.12 could disclose sensitive information due to an observable login response discrepancy. IBM X-Force ID: 257697.
- CVE-2023-35698MEDIUMCVSS 5.3EG 5.32023-07-10
Observable Response Discrepancy in the SICK ICR890-4 could allow a remote attacker to identify valid usernames for the FTP server from the response given during a failed login attempt.
- CVE-2023-37217MEDIUMCVSS 5.3EG 5.32023-07-30
Tadiran Telecom Aeonix - CWE-204: Observable Response Discrepancy
- CVE-2023-37413MEDIUMCVSS 5.3EG 5.32025-01-29
IBM Aspera Faspex 5.0.0 through 5.0.10 could disclose sensitive username information due to an observable response discrepancy.
- CVE-2023-37831MEDIUMCVSS 5.3EG 5.32023-10-31
An issue discovered in Elenos ETG150 FM transmitter v3.12 allows attackers to enumerate user accounts based on server responses when credentials are submitted.
- CVE-2023-38362MEDIUMCVSS 5.3EG 5.32024-03-04
IBM CICS TX Advanced 10.1 could disclose sensitive information to a remote attacker due to observable discrepancy in HTTP responses. IBM X-Force ID: 260814.
- CVE-2023-39343MEDIUMCVSS 4.3EG 4.32023-08-04
Sulu is an open-source PHP content management system based on the Symfony framework. It allows over the Admin Login form to detect which user (username, email) exists and which one do not exist. Sulu Installation not using the old Symfony …
- CVE-2023-40179MEDIUMCVSS 5.3EG 5.32023-08-25
Silverware Games is a premium social network where people can play games online. Prior to version 1.3.6, the Password Recovery form would throw an error if the specified email was not found in our database. It would only display the "Enter…
- CVE-2023-4095MEDIUMCVSS 5.3EG 5.32023-09-19
User enumeration vulnerability in Arconte Áurea 1.5.0.0 version. The exploitation of this vulnerability could allow an attacker to obtain a list of registered users in the application, obtaining the necessary information to perform more c…
- CVE-2023-41885MEDIUMCVSS 5.3EG 5.32023-09-12
Piccolo is an ORM and query builder which supports asyncio. In versions 0.120.0 and prior, the implementation of `BaseUser.login` leaks enough information to a malicious user such that they would be able to successfully generate a list of …
- CVE-2023-46170MEDIUMCVSS 6.5EG 6.52024-03-07
IBM DS8900F HMC 89.21.19.0, 89.21.31.0, 89.30.68.0, 89.32.40.0, and 89.33.48.0 could allow an authenticated user to arbitrarily read files after enumerating file names.
- CVE-2023-47159MEDIUMCVSS 4.3EG 4.32025-01-27
IBM Sterling File Gateway 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.1 could allow an authenticated user to enumerate usernames due to an observable discrepancy in request responses.
- CVE-2023-49069MEDIUMCVSS 5.3EG 5.32024-09-10
A vulnerability has been identified in Mendix Runtime V10 (All versions < V10.17.0 only if the basic authentication mechanism is used by the application), Mendix Runtime V10.12 (All versions < V10.12.11 only if the basic authentication mec…
- CVE-2023-50306MEDIUMCVSS 4.0EG 4.02024-02-20
IBM Common Licensing 9.0 could allow a local user to enumerate usernames due to an observable response discrepancy. IBM X-Force ID: 273337.
- CVE-2024-0391MEDIUMCVSS 5.3EG 5.32026-05-11
The check user account lock states feature within the email OTP flow fails to validate user input, allowing an attacker to infer the existence of registered user accounts. The discovery of valid usernames can increase the risk of brute-fo…
- CVE-2024-1145MEDIUMCVSS 5.3EG 5.32024-03-19
User enumeration vulnerability in Devklan's Alma Blog that affects versions 2.1.10 and earlier. This vulnerability could allow a remote user to retrieve all valid users registered in the application just by looking at the request response.
- CVE-2024-12663LOWCVSS 3.7EG 3.72024-12-16
A vulnerability classified as problematic was found in funnyzpc Mee-Admin up to 1.6. This vulnerability affects unknown code of the file /mee/login of the component Login. The manipulation of the argument username leads to observable respo…
- CVE-2024-13028LOWCVSS 3.7EG 3.72024-12-29
A vulnerability, which was classified as problematic, has been found in Antabot White-Jotter up to 0.2.2. This issue affects some unknown processing of the file /login. The manipulation of the argument username leads to observable response…
- CVE-2024-13198LOWCVSS 3.7EG 3.72025-01-09
A vulnerability classified as problematic has been found in langhsu Mblog Blog System 3.5.0. Affected is an unknown function of the file /login. The manipulation leads to observable response discrepancy. It is possible to launch the attack…
- CVE-2024-24766MEDIUMCVSS 6.2EG 6.22024-03-06
CasaOS-UserService provides user management functionalities to CasaOS. Starting in version 0.4.4.3 and prior to version 0.4.7, the Casa OS Login page disclosed the username enumeration vulnerability in the login page. An attacker can enume…
Map vulnerabilities like CWE-204 to your infrastructure
EchelonGraph correlates every CVE — across CWE-204 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →