CWE-203Base

Observable Discrepancy

Incomplete in the CWE catalog · 193 CVEs mapped

193
CVEs mapped
5.3
Median CVSS
What it is

The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.

Recent examples
none
CVE-2026-78617

CVE-2026-78617 - UNKNOWN Severity Vulnerability

WatchGuard Dimension's web login endpoint does not enforce effective rate-limiting or account lockout by default allowing a remote attacker to perform automated password guessing against user accounts. If the account lockout setting is enabled, brute-force attempts are blocked after a defined number of failed attempts, but this setting is not enabled by default.

no explanation yet
0%
epss
5.3cvss
CVE-2026-37064

CVE-2026-37064 - MEDIUM Severity Vulnerability

User enumeration in /vfm-admin/ajax/usr-check.php in Veno File Manager Project 4.4.9 allows an unauthenticated attacker to enumerate the application users via sending a specially crafted POST request to the affected endpoint with a chosen 'user_name' parameter to test if the user exists.

MEDIUMno explanation yet
0%
epss
5.3cvss
CVE-2026-11754

CVE-2026-11754 - MEDIUM Severity Vulnerability

Observable discrepancy vulnerability in Seres Software syWEB allows Account Footprinting. This issue affects syWEB: through 27082026. NOTE: The vendor was contacted and it was learned that the product is not supported.

MEDIUMno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-203
Abstraction
Base
Structure
Simple
Status
Incomplete