İçeriğe atla
Noroxi

CWE-203 · 662 kayıt

Observable Discrepancy

Bu sınıftaki CVE’ler

662 kayıt

  • CVE-2024-39891
    52Planlayın

    In the Twilio Authy API, accessed by Authy Android before 25.1.0 and Authy iOS before 26.1.0, an unauthenticated endpoint provided access to

    OrtaCVSS 5,3KEVSilahlaştırılmışEPSS %2

    twilio · authy2 Tem 2024

  • CVE-2017-5753
    50Planlayın

    Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an at

    OrtaCVSS 5,6Kavram kanıtıEPSS %94

    intel · atom c4 Oca 2018

  • CVE-2017-5715
    44Planlayın

    Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information

    OrtaCVSS 5,6Kavram kanıtıEPSS %74

    intel · atom c4 Oca 2018

  • CVE-2003-0190
    43Planlayın

    OpenSSH-portable (OpenSSH) 3.6.1p1 and earlier with PAM support enabled immediately sends an error message when a user does not exist, which

    OrtaCVSS 5,0SilahlaştırılmışEPSS %77

    openbsd · openssh12 May 2003

  • CVE-2019-10071
    42Planlayın

    The code which checks HMAC in form submissions used String.equals() for comparisons, which results in a timing side channel for the comparis

    KritikCVSS 9,8İstismar yokEPSS %9

    apache · tapestry16 Eyl 2019

  • CVE-2018-3639
    40Planlayın

    Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior mem

    OrtaCVSS 5,5Kavram kanıtıEPSS %61

    intel · atom c22 May 2018

  • CVE-2022-23303
    40Planlayın

    The implementations of SAE in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side channel attacks as a result of cache

    KritikCVSS 9,8Kavram kanıtıEPSS %3

    w1.fi · hostapd16 Oca 2022

  • CVE-2022-23304
    40Planlayın

    The implementations of EAP-pwd in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side-channel attacks as a result of c

    KritikCVSS 9,8İstismar yokEPSS %2

    w1.fi · hostapd16 Oca 2022

  • Vesta CP version Prior to commit f6f6f9cfbbf2979e301956d1c6ab5c44386822c0 -- any release prior to 0.9.8-18 contains a CWE-208 / Information

    KritikCVSS 9,8İstismar yokEPSS %1

    vestacp · vesta control panel20 Ara 2018

  • CVE-2024-23771
    39İzleyin

    darkhttpd before 1.15 uses strcmp (which is not constant time) to verify authentication, which makes it easier for remote attackers to bypas

    KritikCVSS 9,8İstismar yokEPSS %1

    unix4lyfe · darkhttpd22 Oca 2024

  • CVE-2024-25189
    39İzleyin

    libjwt 1.15.3 uses strcmp (which is not constant time) to verify authentication, which makes it easier to bypass authentication via a timing

    KritikCVSS 9,8İstismar yokEPSS %1

    libjwt · libjwt8 Şub 2024

  • CVE-2024-25190
    39İzleyin

    l8w8jwt 2.2.1 uses memcmp (which is not constant time) to verify authentication, which makes it easier to bypass authentication via a timing

    KritikCVSS 9,8İstismar yokEPSS %1

    glitchedpolygons · l8w8jwt8 Şub 2024

  • CVE-2023-40756
    39İzleyin

    User enumeration is found in PHPJabbers Callback Widget v1.0.

    KritikCVSS 9,8İstismar yokEPSS %1

    phpjabbers · callback widget28 Ağu 2023

  • CVE-2024-25191
    39İzleyin

    php-jwt 1.0.0 uses strcmp (which is not constant time) to verify authentication, which makes it easier to bypass authentication via a timing

    KritikCVSS 9,8İstismar yokEPSS %1

    zihanggao · php-jwt8 Şub 2024

  • CVE-2024-25714
    39İzleyin

    In Rhonabwy through 1.1.13, HMAC signature verification uses a strcmp function that is vulnerable to side-channel attacks, because it stops

    KritikCVSS 9,8İstismar yokEPSS %1

    rhonabwy project · rhonabwy10 Şub 2024

  • CVE-2023-50708
    39İzleyin

    yii2-authclient vulnerable to possible timing attack on string comparison in OAuth1, OAuth2 and OpenID Connect implementation

    KritikCVSS 9,8İstismar yokEPSS %1

    yiiframework · yii2-authclient22 Ara 2023

  • CVE-2025-27667
    39İzleyin

    Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Administrative User Email Enumerati

    KritikCVSS 9,8İstismar yokEPSS %1

    printerlogic · vasion print5 Mar 2025

  • CVE-2022-40895
    37İzleyin

    In certain Nedi products, a vulnerability in the web UI of NeDi login & Community login could allow an unauthenticated, remote attacker to a

    KritikCVSS 9,1İstismar yokEPSS %2

    nedi · nedi6 Eki 2022

  • CVE-2026-72699
    37İzleyin

    Grav Login Plugin before 3.9.1 Email Enumeration via Registration

    KritikCVSS 9,3İstismar yokEPSS %0

    getgrav · grav-plugin-login24 Ağu 2026

  • CVE-2023-26556
    36İzleyin

    io.finnet tss-lib before 2.0.0 can leak a secret key via a timing side-channel attack because it relies on the scalar-multiplication impleme

    KritikCVSS 9,1İstismar yokEPSS %1

    iofinnet · tss-lib21 Nis 2023

  • CVE-2026-74961
    36İzleyin

    Side-channel in the Web Audio component

    KritikCVSS 9,1İstismar yokEPSS %0

    mozilla · firefox18 Ağu 2026

  • PHPECC vulnerable to multiple cryptographic side-channel attacks

    KritikCVSS 9,1İstismar yok

    Packagist · mdanter/ecc25 Nis 2024

  • CVE-2017-6168
    35İzleyin

    On BIG-IP versions 11.6.0-11.6.2 (fixed in 11.6.2 HF1), 12.0.0-12.1.2 HF1 (fixed in 12.1.2 HF2), or 13.0.0-13.0.0 HF2 (fixed in 13.0.0 HF3)

    YüksekCVSS 7,4SilahlaştırılmışEPSS %20

    f5 · big-ip ltm17 Kas 2017

  • CVE-2022-20866
    35İzleyin

    Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software RSA Private Key Leak Vulnerability

    YüksekCVSS 7,5Kavram kanıtıEPSS %17

    cisco · adaptive security appliance software10 Ağu 2022

  • CVE-2024-6420
    35İzleyin

    Hide My WP Ghost < 5.2.02 - Hidden Login Page Disclosure

    YüksekCVSS 8,6Kavram kanıtıEPSS %2

    wpplugins · hide my wp ghost23 Tem 2024

Tüm zafiyet sınıfları