CWE-203 · 662 kayıt
Observable Discrepancy
Bu sınıftaki CVE’ler
662 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
52Planlayın | CVE-2024-39891Silahlaştırılmış | In the Twilio Authy API, accessed by Authy Android before 25.1.0 and Authy iOS before 26.1.0, an unauthenticated endpoint provided access totwilio · authy · CWE-203 | Orta5,3 | KEV | %1,7 | 2 Tem 2024 |
50Planlayın | CVE-2017-5753Kavram kanıtı | Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an atintel · atom c · CWE-203 | Orta5,6 | — | %93,8 | 4 Oca 2018 |
44Planlayın | CVE-2017-5715Kavram kanıtı | Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of informationintel · atom c · CWE-203 | Orta5,6 | — | %74,0 | 4 Oca 2018 |
43Planlayın | CVE-2003-0190Silahlaştırılmış | OpenSSH-portable (OpenSSH) 3.6.1p1 and earlier with PAM support enabled immediately sends an error message when a user does not exist, whichopenbsd · openssh · CWE-203 | Orta5,0 | — | %76,8 | 12 May 2003 |
42Planlayın | CVE-2019-10071İstismar yok | The code which checks HMAC in form submissions used String.equals() for comparisons, which results in a timing side channel for the comparisapache · tapestry · CWE-203 | Kritik9,8 | — | %8,8 | 16 Eyl 2019 |
40Planlayın | CVE-2018-3639Kavram kanıtı | Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memintel · atom c · CWE-203 | Orta5,5 | — | %60,6 | 22 May 2018 |
40Planlayın | CVE-2022-23303Kavram kanıtı | The implementations of SAE in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side channel attacks as a result of cachew1.fi · hostapd · CWE-203 | Kritik9,8 | — | %3,1 | 16 Oca 2022 |
40Planlayın | CVE-2022-23304İstismar yok | The implementations of EAP-pwd in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side-channel attacks as a result of cw1.fi · hostapd · CWE-203 | Kritik9,8 | — | %1,9 | 16 Oca 2022 |
39İzleyin | CVE-2018-1000884İstismar yok | Vesta CP version Prior to commit f6f6f9cfbbf2979e301956d1c6ab5c44386822c0 -- any release prior to 0.9.8-18 contains a CWE-208 / Information vestacp · vesta control panel · CWE-203 | Kritik9,8 | — | %1,3 | 20 Ara 2018 |
39İzleyin | CVE-2024-23771İstismar yok | darkhttpd before 1.15 uses strcmp (which is not constant time) to verify authentication, which makes it easier for remote attackers to bypasunix4lyfe · darkhttpd · CWE-203 | Kritik9,8 | — | %1,1 | 22 Oca 2024 |
39İzleyin | CVE-2024-25189İstismar yok | libjwt 1.15.3 uses strcmp (which is not constant time) to verify authentication, which makes it easier to bypass authentication via a timinglibjwt · libjwt · CWE-203 | Kritik9,8 | — | %1,0 | 8 Şub 2024 |
39İzleyin | CVE-2024-25190İstismar yok | l8w8jwt 2.2.1 uses memcmp (which is not constant time) to verify authentication, which makes it easier to bypass authentication via a timingglitchedpolygons · l8w8jwt · CWE-203 | Kritik9,8 | — | %0,9 | 8 Şub 2024 |
39İzleyin | CVE-2023-40756İstismar yok | User enumeration is found in PHPJabbers Callback Widget v1.0.phpjabbers · callback widget · CWE-203 | Kritik9,8 | — | %0,9 | 28 Ağu 2023 |
39İzleyin | CVE-2024-25191İstismar yok | php-jwt 1.0.0 uses strcmp (which is not constant time) to verify authentication, which makes it easier to bypass authentication via a timingzihanggao · php-jwt · CWE-203 | Kritik9,8 | — | %0,9 | 8 Şub 2024 |
39İzleyin | CVE-2024-25714İstismar yok | In Rhonabwy through 1.1.13, HMAC signature verification uses a strcmp function that is vulnerable to side-channel attacks, because it stops rhonabwy project · rhonabwy · CWE-203 | Kritik9,8 | — | %0,8 | 10 Şub 2024 |
39İzleyin | CVE-2023-50708İstismar yok | yii2-authclient vulnerable to possible timing attack on string comparison in OAuth1, OAuth2 and OpenID Connect implementationyiiframework · yii2-authclient · CWE-203 | Kritik9,8 | — | %0,7 | 22 Ara 2023 |
39İzleyin | CVE-2025-27667İstismar yok | Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Administrative User Email Enumeratiprinterlogic · vasion print · CWE-203 | Kritik9,8 | — | %0,7 | 5 Mar 2025 |
37İzleyin | CVE-2022-40895İstismar yok | In certain Nedi products, a vulnerability in the web UI of NeDi login & Community login could allow an unauthenticated, remote attacker to anedi · nedi · CWE-203 | Kritik9,1 | — | %1,8 | 6 Eki 2022 |
37İzleyin | CVE-2026-72699İstismar yok | Grav Login Plugin before 3.9.1 Email Enumeration via Registrationgetgrav · grav-plugin-login · CWE-203 | Kritik9,3 | — | %0,3 | 24 Ağu 2026 |
36İzleyin | CVE-2023-26556İstismar yok | io.finnet tss-lib before 2.0.0 can leak a secret key via a timing side-channel attack because it relies on the scalar-multiplication implemeiofinnet · tss-lib · CWE-203 | Kritik9,1 | — | %0,9 | 21 Nis 2023 |
36İzleyin | CVE-2026-74961İstismar yok | Side-channel in the Web Audio componentmozilla · firefox · CWE-203 | Kritik9,1 | — | %0,4 | 18 Ağu 2026 |
36İzleyin | GHSA-346h-749j-r28wİstismar yok | PHPECC vulnerable to multiple cryptographic side-channel attacksPackagist · mdanter/ecc · CWE-203 | Kritik9,1 | — | — | 25 Nis 2024 |
35İzleyin | CVE-2017-6168Silahlaştırılmış | On BIG-IP versions 11.6.0-11.6.2 (fixed in 11.6.2 HF1), 12.0.0-12.1.2 HF1 (fixed in 12.1.2 HF2), or 13.0.0-13.0.0 HF2 (fixed in 13.0.0 HF3) f5 · big-ip ltm · CWE-203 | Yüksek7,4 | — | %19,6 | 17 Kas 2017 |
35İzleyin | CVE-2022-20866Kavram kanıtı | Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software RSA Private Key Leak Vulnerabilitycisco · adaptive security appliance software · CWE-203 | Yüksek7,5 | — | %17,4 | 10 Ağu 2022 |
35İzleyin | CVE-2024-6420Kavram kanıtı | Hide My WP Ghost < 5.2.02 - Hidden Login Page Disclosurewpplugins · hide my wp ghost · CWE-203 | Yüksek8,6 | — | %1,8 | 23 Tem 2024 |
- CVE-2024-3989152Planlayın
In the Twilio Authy API, accessed by Authy Android before 25.1.0 and Authy iOS before 26.1.0, an unauthenticated endpoint provided access to
OrtaCVSS 5,3KEVSilahlaştırılmışEPSS %2twilio · authy2 Tem 2024
- CVE-2017-575350Planlayın
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an at
OrtaCVSS 5,6Kavram kanıtıEPSS %94intel · atom c4 Oca 2018
- CVE-2017-571544Planlayın
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information
OrtaCVSS 5,6Kavram kanıtıEPSS %74intel · atom c4 Oca 2018
- CVE-2003-019043Planlayın
OpenSSH-portable (OpenSSH) 3.6.1p1 and earlier with PAM support enabled immediately sends an error message when a user does not exist, which
OrtaCVSS 5,0SilahlaştırılmışEPSS %77openbsd · openssh12 May 2003
- CVE-2019-1007142Planlayın
The code which checks HMAC in form submissions used String.equals() for comparisons, which results in a timing side channel for the comparis
KritikCVSS 9,8İstismar yokEPSS %9apache · tapestry16 Eyl 2019
- CVE-2018-363940Planlayın
Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior mem
OrtaCVSS 5,5Kavram kanıtıEPSS %61intel · atom c22 May 2018
- CVE-2022-2330340Planlayın
The implementations of SAE in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side channel attacks as a result of cache
KritikCVSS 9,8Kavram kanıtıEPSS %3w1.fi · hostapd16 Oca 2022
- CVE-2022-2330440Planlayın
The implementations of EAP-pwd in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side-channel attacks as a result of c
KritikCVSS 9,8İstismar yokEPSS %2w1.fi · hostapd16 Oca 2022
- CVE-2018-100088439İzleyin
Vesta CP version Prior to commit f6f6f9cfbbf2979e301956d1c6ab5c44386822c0 -- any release prior to 0.9.8-18 contains a CWE-208 / Information
KritikCVSS 9,8İstismar yokEPSS %1vestacp · vesta control panel20 Ara 2018
- CVE-2024-2377139İzleyin
darkhttpd before 1.15 uses strcmp (which is not constant time) to verify authentication, which makes it easier for remote attackers to bypas
KritikCVSS 9,8İstismar yokEPSS %1unix4lyfe · darkhttpd22 Oca 2024
- CVE-2024-2518939İzleyin
libjwt 1.15.3 uses strcmp (which is not constant time) to verify authentication, which makes it easier to bypass authentication via a timing
KritikCVSS 9,8İstismar yokEPSS %1libjwt · libjwt8 Şub 2024
- CVE-2024-2519039İzleyin
l8w8jwt 2.2.1 uses memcmp (which is not constant time) to verify authentication, which makes it easier to bypass authentication via a timing
KritikCVSS 9,8İstismar yokEPSS %1glitchedpolygons · l8w8jwt8 Şub 2024
- CVE-2023-4075639İzleyin
User enumeration is found in PHPJabbers Callback Widget v1.0.
KritikCVSS 9,8İstismar yokEPSS %1phpjabbers · callback widget28 Ağu 2023
- CVE-2024-2519139İzleyin
php-jwt 1.0.0 uses strcmp (which is not constant time) to verify authentication, which makes it easier to bypass authentication via a timing
KritikCVSS 9,8İstismar yokEPSS %1zihanggao · php-jwt8 Şub 2024
- CVE-2024-2571439İzleyin
In Rhonabwy through 1.1.13, HMAC signature verification uses a strcmp function that is vulnerable to side-channel attacks, because it stops
KritikCVSS 9,8İstismar yokEPSS %1rhonabwy project · rhonabwy10 Şub 2024
- CVE-2023-5070839İzleyin
yii2-authclient vulnerable to possible timing attack on string comparison in OAuth1, OAuth2 and OpenID Connect implementation
KritikCVSS 9,8İstismar yokEPSS %1yiiframework · yii2-authclient22 Ara 2023
- CVE-2025-2766739İzleyin
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Administrative User Email Enumerati
KritikCVSS 9,8İstismar yokEPSS %1printerlogic · vasion print5 Mar 2025
- CVE-2022-4089537İzleyin
In certain Nedi products, a vulnerability in the web UI of NeDi login & Community login could allow an unauthenticated, remote attacker to a
KritikCVSS 9,1İstismar yokEPSS %2nedi · nedi6 Eki 2022
- CVE-2026-7269937İzleyin
Grav Login Plugin before 3.9.1 Email Enumeration via Registration
KritikCVSS 9,3İstismar yokEPSS %0getgrav · grav-plugin-login24 Ağu 2026
- CVE-2023-2655636İzleyin
io.finnet tss-lib before 2.0.0 can leak a secret key via a timing side-channel attack because it relies on the scalar-multiplication impleme
KritikCVSS 9,1İstismar yokEPSS %1iofinnet · tss-lib21 Nis 2023
- CVE-2026-7496136İzleyin
Side-channel in the Web Audio component
KritikCVSS 9,1İstismar yokEPSS %0mozilla · firefox18 Ağu 2026
- GHSA-346h-749j-r28w36İzleyin
PHPECC vulnerable to multiple cryptographic side-channel attacks
KritikCVSS 9,1İstismar yokPackagist · mdanter/ecc25 Nis 2024
- CVE-2017-616835İzleyin
On BIG-IP versions 11.6.0-11.6.2 (fixed in 11.6.2 HF1), 12.0.0-12.1.2 HF1 (fixed in 12.1.2 HF2), or 13.0.0-13.0.0 HF2 (fixed in 13.0.0 HF3)
YüksekCVSS 7,4SilahlaştırılmışEPSS %20f5 · big-ip ltm17 Kas 2017
- CVE-2022-2086635İzleyin
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software RSA Private Key Leak Vulnerability
YüksekCVSS 7,5Kavram kanıtıEPSS %17cisco · adaptive security appliance software10 Ağu 2022
- CVE-2024-642035İzleyin
Hide My WP Ghost < 5.2.02 - Hidden Login Page Disclosure
YüksekCVSS 8,6Kavram kanıtıEPSS %2wpplugins · hide my wp ghost23 Tem 2024