← Back
CWE-203

751 CVEs • Abstraction: Base

Observable Discrepancy

The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor, which exposes security-relevant information about the state of the product, such as whether a particular operation was successful or not.

JSON object

Loading...

CVEs (751)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Mtons
1Mblog
Jun 17, 2026
Jan 9, 2025
6.3 MEDIUM· v4
3.7 LOW· v3
2.6 LOW· v2
A vulnerability classified as problematic has been found in langhsu Mblog Blog System 3.5.0. Affected is an unknown function of the file /login. The manipulation leads to observable response discrepancy. It is possible t...Show more
A vulnerability classified as problematic has been found in langhsu Mblog Blog System 3.5.0. Affected is an unknown function of the file /login. The manipulation leads to observable response discrepancy. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.Show less
-
-
Jun 17, 2026
Jan 6, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
An access control issue in the component /juis_boxinfo.xml of AVM FRITZ!Box 7530 AX v7.59 allows attackers to obtain sensitive information without authentication. NOTE: this is disputed by the Supplier because it cannot...Show more
An access control issue in the component /juis_boxinfo.xml of AVM FRITZ!Box 7530 AX v7.59 allows attackers to obtain sensitive information without authentication. NOTE: this is disputed by the Supplier because it cannot be reproduced, and the issue report focuses on an unintended configuration with direct Internet exposure.Show less
1Antabot
1White Jotter
Jun 17, 2026
Dec 29, 2024
6.3 MEDIUM· v4
3.7 LOW· v3
2.6 LOW· v2
A vulnerability, which was classified as problematic, has been found in Antabot White-Jotter up to 0.2.2. This issue affects some unknown processing of the file /login. The manipulation of the argument username leads to...Show more
A vulnerability, which was classified as problematic, has been found in Antabot White-Jotter up to 0.2.2. This issue affects some unknown processing of the file /login. The manipulation of the argument username leads to observable response discrepancy. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used.Show less
1Gnu
1Grub2
Jun 17, 2026
Dec 29, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
GNU GRUB (aka GRUB2) through 2.12 does not use a constant-time algorithm for grub_crypto_memcmp and thus allows side-channel attacks.
-
-
Jun 17, 2026
Dec 27, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
An issue was discovered in Kurmi Provisioning Suite before 7.9.0.35, 7.10.x through 7.10.0.18, and 7.11.x through 7.11.0.15. An Observable Response Discrepancy vulnerability in the sendPasswordReinitLink action of the un...Show more
An issue was discovered in Kurmi Provisioning Suite before 7.9.0.35, 7.10.x through 7.10.0.18, and 7.11.x through 7.11.0.15. An Observable Response Discrepancy vulnerability in the sendPasswordReinitLink action of the unlogged.do page allows remote attackers to test whether a username is valid or not. This allows confirmation of valid usernames.Show less
1Honor
1Magicos
Jun 17, 2026
Dec 26, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak.
1Honor
1Magicos
Jun 17, 2026
Dec 26, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptions.
1Honor
1Magicos
Jun 17, 2026
Dec 26, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak.
1Honor
1Magicos
Jun 17, 2026
Dec 26, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak.
1Honor
1Magicos
Jun 17, 2026
Dec 26, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak.
1Honor
1Magicos
Jun 17, 2026
Dec 26, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak.
1Honor
1Magicos
Jun 17, 2026
Dec 26, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak.
1Honor
1Magicos
Jun 17, 2026
Dec 26, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak.
1Honor
1Magicos
Jun 17, 2026
Dec 26, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak.
1Miniorange
1Page Restriction
Jun 17, 2026
Dec 20, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
The Page Restriction WordPress (WP) – Protect WP Pages/Post plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.6 via the WordPress core search feature. This mak...Show more
The Page Restriction WordPress (WP) – Protect WP Pages/Post plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.6 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract sensitive data from posts that have been restricted to higher-level roles such as administrator.Show less
-
-
Jun 17, 2026
Dec 16, 2024
6.3 MEDIUM· v4
3.7 LOW· v3
2.6 LOW· v2
A vulnerability classified as problematic was found in funnyzpc Mee-Admin up to 1.6. This vulnerability affects unknown code of the file /mee/login of the component Login. The manipulation of the argument username leads...Show more
A vulnerability classified as problematic was found in funnyzpc Mee-Admin up to 1.6. This vulnerability affects unknown code of the file /mee/login of the component Login. The manipulation of the argument username leads to observable response discrepancy. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used.Show less
1Apple
1Macos
Jun 17, 2026
Dec 12, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2. An app may be able to access user-sensitive data.
-
-
Jun 17, 2026
Dec 4, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Dependency-Track is a Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain. Performing a login request against the /api/v1/user/login endpoint with a username tha...Show more
Dependency-Track is a Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain. Performing a login request against the /api/v1/user/login endpoint with a username that exist in the system takes significantly longer than performing the same action with a username that is not known by the system. The observable difference in request duration can be leveraged by actors to enumerate valid names of managed users. LDAP and OpenID Connect users are not affected. The issue has been fixed in Dependency-Track 4.12.2.Show less
1Google
1Android
Jun 17, 2026
Nov 19, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
In the LG LAF component, there is a special command that allowed modification of certain partitions. This could lead to bypass of secure boot. User interaction is not needed for exploitation.
1Cisco
1Unified Computing System
Jun 17, 2026
Nov 18, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
A vulnerability in Cisco Integrated Management Controller could allow an unauthenticated, remote attacker to enumerate valid usernames within the vulnerable application. The vulnerability is due to differences in a...Show more
A vulnerability in Cisco Integrated Management Controller could allow an unauthenticated, remote attacker to enumerate valid usernames within the vulnerable application. The vulnerability is due to differences in authentication responses sent back from the application as part of an authentication attempt. An attacker could exploit this vulnerability by sending authentication requests to the affected application. A successful exploit could allow the attacker to confirm the names of administrative user accounts for use in further attacks.There are no workarounds that address this vulnerability.Show less