Vulnerabilities (CVE)

Filtered by CWE-204
Total 143 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-20556 1 Ibm 1 Cognos Controller 2026-06-17 N/A 5.3 MEDIUM
IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 could allow a remote user to enumerate usernames due to differentiating error messages on existing usernames. IBM X-Force ID: 199181.
CVE-2019-25338 1 Dokuwiki 1 Dokuwiki 2026-06-17 N/A 5.3 MEDIUM
DokuWiki 2018-04-22b contains a username enumeration vulnerability in its password reset functionality that allows attackers to identify valid user accounts. Attackers can submit different usernames to the password reset endpoint and distinguish between existing and non-existing accounts by analyzing the server's error response messages.
CVE-2019-19030 1 Linuxfoundation 1 Harbor 2026-06-17 N/A 5.3 MEDIUM
Cloud Native Computing Foundation Harbor before 1.10.3 and 2.x before 2.0.1 allows resource enumeration because unauthenticated API calls reveal (via the HTTP status code) whether a resource exists.