CWE-208 · 199 kayıt
Observable Timing Discrepancy
Bu sınıftaki CVE’ler
199 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2021-43298İstismar yok | The code that performs password matching when using 'Basic' HTTP authentication does not use a constant-time memcmp and has no rate-limitingembedthis · goahead · CWE-208 | Kritik9,8 | — | %2,3 | 25 Oca 2022 |
39İzleyin | CVE-2023-41313İstismar yok | Apache Doris: Timing Attack weaknessapache · doris · CWE-208 | Kritik9,8 | — | %1,0 | 12 Mar 2024 |
39İzleyin | CVE-2021-21575İstismar yok | Dell BSAFE Micro Edition Suite, versions before 4.5.2, contain an Observable Timing Discrepancy Vulnerability.dell · bsafe micro-edition-suite · CWE-208 | Kritik9,8 | — | %0,5 | 2 Şub 2024 |
38İzleyin | GHSA-xfqg-p48g-hh94İstismar yok | Login timing attack in ezsystems/ezpublish-kernelPackagist · ezsystems/ezpublish-kernel · CWE-208 | Kritik9,5 | — | — | 2 Haz 2022 |
38İzleyin | GHSA-2x4v-g8cx-jxrqİstismar yok | Login timing attack in ibexa/corePackagist · ibexa/core · CWE-208 | Kritik9,5 | — | — | 2 Haz 2022 |
38İzleyin | GHSA-342c-vcff-2ff2İstismar yok | Login timing attack in ezsystems/ezplatform-kernelPackagist · ezsystems/ezplatform-kernel · CWE-208 | Kritik9,5 | — | — | 2 Haz 2022 |
37İzleyin | CVE-2026-77987İstismar yok | GitHub Enterprise Server notebook viewer vulnerable to Server-side request forgerygithub · enterprise server · CWE-208 | Kritik9,3 | — | %0,9 | 22 Eyl 2026 |
36İzleyin | CVE-2026-63132İstismar yok | OpenBao's Recovery Mode Vulnerable To Token Leakage via Timing Attackopenbao · openbao · CWE-208 | Kritik9,2 | — | %0,5 | 6 gün önce |
35İzleyin | CVE-2025-53940İstismar yok | Quiet uses insecure, inconsistent verification on local backend tokentryquiet · quiet · CWE-208 | Yüksek8,5 | — | %3,6 | 24 Tem 2025 |
35İzleyin | CVE-2026-23519İstismar yok | RustCrypto cmov: thumbv6m-none-eabi compiler emits non-constant time assembly when using cmovnzrustcrypto · cmov · CWE-208 | Yüksek8,9 | — | %0,6 | 15 Oca 2026 |
34İzleyin | CVE-2024-42512İstismar yok | Vulnerability in the OPC UA .NET Standard Stack before 1.5.374.158 allows an unauthorized attacker to bypass application authentication whenopcfoundation · ua .net standard stack · CWE-208 | Yüksek8,6 | — | %0,6 | 10 Şub 2025 |
34İzleyin | CVE-2024-47178İstismar yok | basic-auth-connect's callback uses time unsafe string comparisonexpressjs · basic-auth-connect · CWE-208 | Yüksek8,7 | — | %0,5 | 30 Eyl 2024 |
34İzleyin | CVE-2026-72700İstismar yok | Grav before 3.9.1 Timing Attack via Non-Constant-Time Token Comparisongetgrav · grav · CWE-208 | Yüksek8,7 | — | %0,4 | 24 Ağu 2026 |
34İzleyin | CVE-2026-43606İstismar yok | Observable Timing Discrepancy in the AMD Vitis Libraries ECDSA secp256k1 component could allow attackers with local access to potentially peamd · vitis™ libraries - security module · CWE-208 | Yüksek8,5 | — | %0,2 | 11 Ağu 2026 |
34İzleyin | GHSA-qv5f-57gw-vx3hİstismar yok | Duplicate Advisory: Authorization Bypass in OPC UA .NET Standard StackNuGet · OPCFoundation.NetStandard.Opc.Ua · CWE-208 | Yüksek8,6 | — | — | 10 Şub 2025 |
33İzleyin | CVE-2026-16731İstismar yok | Authentication and authorization bypass via cryptographic timing side-channel attack in StationScoutomicron electronics gmbh · omicron stationscout · CWE-208 | Yüksek8,3 | — | %0,4 | 6 Ağu 2026 |
32İzleyin | CVE-2024-29995İstismar yok | Windows Kerberos Elevation of Privilege Vulnerabilitymicrosoft · windows 10 1507 · CWE-208 | Yüksek8,1 | — | %1,5 | 13 Ağu 2024 |
32İzleyin | CVE-2026-47783İstismar yok | In memcached before 1.6.42, username data for SASL password database authentication has a timing side channel because a loop exits as soon amemcached · memcached · CWE-208 | Yüksek8,1 | — | %1,3 | 20 May 2026 |
32İzleyin | CVE-2026-28464İstismar yok | OpenClaw < 2026.2.12 - Timing Attack in Hooks Token Authenticationopenclaw · openclaw · CWE-208 | Yüksek8,2 | — | %0,7 | 5 Mar 2026 |
32İzleyin | CVE-2023-25529İstismar yok | NVIDIA DGX H100 BMC and DGX A100 BMC contains a vulnerability in the host KVM daemon, where an unauthenticated attacker may cause a leak of nvidia · dgx h100 firmware · CWE-208 | Yüksek8,1 | — | %0,6 | 19 Eyl 2023 |
32İzleyin | CVE-2026-47784İstismar yok | In memcached before 1.6.42, password data for SASL password database authentication has a timing side channel because memcmp is used by saslmemcached · memcached · CWE-208 | Yüksek8,1 | — | %0,6 | 20 May 2026 |
32İzleyin | CVE-2024-31074İstismar yok | Observable timing discrepancy in some Intel(R) QAT Engine for OpenSSL software before version v1.6.1 may allow information disclosure via neCWE-208 | Yüksek8,2 | — | %0,5 | 13 Kas 2024 |
32İzleyin | CVE-2026-3337İstismar yok | Timing Side-Channel in AES-CCM Tag Verification in AWS-LCamazon · aws-lc-fips-sys · CWE-208 | Yüksek8,2 | — | %0,5 | 2 Mar 2026 |
32İzleyin | CVE-2026-41588İstismar yok | RELATE: Timing Attack Vulnerability in course/auth.py — check_sign_in_key()inducer · relate · CWE-208 | Yüksek8,1 | — | %0,5 | 8 May 2026 |
32İzleyin | CVE-2026-32935İstismar yok | phpseclib's AES-CBC unpadding susceptible to padding oracle timing attackphpseclib · phpseclib · CWE-208 | Yüksek8,2 | — | %0,4 | 19 Mar 2026 |
- CVE-2021-4329840Planlayın
The code that performs password matching when using 'Basic' HTTP authentication does not use a constant-time memcmp and has no rate-limiting
KritikCVSS 9,8İstismar yokEPSS %2embedthis · goahead25 Oca 2022
- CVE-2023-4131339İzleyin
Apache Doris: Timing Attack weakness
KritikCVSS 9,8İstismar yokEPSS %1apache · doris12 Mar 2024
- CVE-2021-2157539İzleyin
Dell BSAFE Micro Edition Suite, versions before 4.5.2, contain an Observable Timing Discrepancy Vulnerability.
KritikCVSS 9,8İstismar yokEPSS %1dell · bsafe micro-edition-suite2 Şub 2024
- GHSA-xfqg-p48g-hh9438İzleyin
Login timing attack in ezsystems/ezpublish-kernel
KritikCVSS 9,5İstismar yokPackagist · ezsystems/ezpublish-kernel2 Haz 2022
- GHSA-2x4v-g8cx-jxrq38İzleyin
Login timing attack in ibexa/core
KritikCVSS 9,5İstismar yokPackagist · ibexa/core2 Haz 2022
- GHSA-342c-vcff-2ff238İzleyin
Login timing attack in ezsystems/ezplatform-kernel
KritikCVSS 9,5İstismar yokPackagist · ezsystems/ezplatform-kernel2 Haz 2022
- CVE-2026-7798737İzleyin
GitHub Enterprise Server notebook viewer vulnerable to Server-side request forgery
KritikCVSS 9,3İstismar yokEPSS %1github · enterprise server22 Eyl 2026
- CVE-2026-6313236İzleyin
OpenBao's Recovery Mode Vulnerable To Token Leakage via Timing Attack
KritikCVSS 9,2İstismar yokEPSS %0openbao · openbao6 gün önce
- CVE-2025-5394035İzleyin
Quiet uses insecure, inconsistent verification on local backend token
YüksekCVSS 8,5İstismar yokEPSS %4tryquiet · quiet24 Tem 2025
- CVE-2026-2351935İzleyin
RustCrypto cmov: thumbv6m-none-eabi compiler emits non-constant time assembly when using cmovnz
YüksekCVSS 8,9İstismar yokEPSS %1rustcrypto · cmov15 Oca 2026
- CVE-2024-4251234İzleyin
Vulnerability in the OPC UA .NET Standard Stack before 1.5.374.158 allows an unauthorized attacker to bypass application authentication when
YüksekCVSS 8,6İstismar yokEPSS %1opcfoundation · ua .net standard stack10 Şub 2025
- CVE-2024-4717834İzleyin
basic-auth-connect's callback uses time unsafe string comparison
YüksekCVSS 8,7İstismar yokEPSS %1expressjs · basic-auth-connect30 Eyl 2024
- CVE-2026-7270034İzleyin
Grav before 3.9.1 Timing Attack via Non-Constant-Time Token Comparison
YüksekCVSS 8,7İstismar yokEPSS %0getgrav · grav24 Ağu 2026
- CVE-2026-4360634İzleyin
Observable Timing Discrepancy in the AMD Vitis Libraries ECDSA secp256k1 component could allow attackers with local access to potentially pe
YüksekCVSS 8,5İstismar yokEPSS %0amd · vitis™ libraries - security module11 Ağu 2026
- GHSA-qv5f-57gw-vx3h34İzleyin
Duplicate Advisory: Authorization Bypass in OPC UA .NET Standard Stack
YüksekCVSS 8,6İstismar yokNuGet · OPCFoundation.NetStandard.Opc.Ua10 Şub 2025
- CVE-2026-1673133İzleyin
Authentication and authorization bypass via cryptographic timing side-channel attack in StationScout
YüksekCVSS 8,3İstismar yokEPSS %0omicron electronics gmbh · omicron stationscout6 Ağu 2026
- CVE-2024-2999532İzleyin
Windows Kerberos Elevation of Privilege Vulnerability
YüksekCVSS 8,1İstismar yokEPSS %1microsoft · windows 10 150713 Ağu 2024
- CVE-2026-4778332İzleyin
In memcached before 1.6.42, username data for SASL password database authentication has a timing side channel because a loop exits as soon a
YüksekCVSS 8,1İstismar yokEPSS %1memcached · memcached20 May 2026
- CVE-2026-2846432İzleyin
OpenClaw < 2026.2.12 - Timing Attack in Hooks Token Authentication
YüksekCVSS 8,2İstismar yokEPSS %1openclaw · openclaw5 Mar 2026
- CVE-2023-2552932İzleyin
NVIDIA DGX H100 BMC and DGX A100 BMC contains a vulnerability in the host KVM daemon, where an unauthenticated attacker may cause a leak of
YüksekCVSS 8,1İstismar yokEPSS %1nvidia · dgx h100 firmware19 Eyl 2023
- CVE-2026-4778432İzleyin
In memcached before 1.6.42, password data for SASL password database authentication has a timing side channel because memcmp is used by sasl
YüksekCVSS 8,1İstismar yokEPSS %1memcached · memcached20 May 2026
- CVE-2024-3107432İzleyin
Observable timing discrepancy in some Intel(R) QAT Engine for OpenSSL software before version v1.6.1 may allow information disclosure via ne
YüksekCVSS 8,2İstismar yokEPSS %113 Kas 2024
- CVE-2026-333732İzleyin
Timing Side-Channel in AES-CCM Tag Verification in AWS-LC
YüksekCVSS 8,2İstismar yokEPSS %0amazon · aws-lc-fips-sys2 Mar 2026
- CVE-2026-4158832İzleyin
RELATE: Timing Attack Vulnerability in course/auth.py — check_sign_in_key()
YüksekCVSS 8,1İstismar yokEPSS %0inducer · relate8 May 2026
- CVE-2026-3293532İzleyin
phpseclib's AES-CBC unpadding susceptible to padding oracle timing attack
YüksekCVSS 8,2İstismar yokEPSS %0phpseclib · phpseclib19 Mar 2026