CWE-203: Observable Discrepancy
The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.
198 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-40732 — User enumeration vulnerability in Daily Expense Manager
- CVE-2026-28490 — Authlib Vulnerable to JWE RSA1_5 Bleichenbacher Padding Oracle
- CVE-2024-28885 — Observable discrepancy in some Intel(R) QAT Engine for OpenSSL software before version v1.6.1 may allow information disc
- CVE-2026-78955 — Observable discrepancy in PerformanceAPIs in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potential
- CVE-2026-87623 — Observable discrepancy in DOM in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engine
- CVE-2026-87620 — Observable discrepancy in SVG in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive info
- CVE-2026-87478 — Observable discrepancy in Autofill in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive
- CVE-2026-87459 — Observable discrepancy in Select in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive i
- CVE-2026-72699 — Grav Login Plugin before 3.9.1 Email Enumeration via Registration
- CVE-2025-6386 — Timing Attack Vulnerability in parisneo/lollms
- CVE-2025-41252 — Username enumeration vulnerability
- CVE-2025-1468 — CODESYS Control V3 - OPC UA Server Authentication bypass
- CVE-2024-5124 — Timing Attack Vulnerability in gaizhenbiao/chuanhuchatgpt
- CVE-2024-23342 — python-ecdsa vulnerable to Minerva attack on P-256
- CVE-2026-59640 — OpenPGP CFB quick-check oracle active on symmetric/session-key paths
- CVE-2026-56339 — Capgo - Unauthenticated Organization Existence Enumeration via rescind_invitation RPC
- CVE-2023-54357 — Joomla com_booking 2.4.9 Information Disclosure via Account Enumeration
- CVE-2024-0436 — Prevent timing attack for single-user password check
- CVE-2024-9513 — Netadmin Software NetAdmin IAM HTTP POST Request ReturnUserQuestionsFilled information exposure
- CVE-2026-79028 — Observable discrepancy in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive
Recently published
- CVE-2026-87459 — Observable discrepancy in Select in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive i
- CVE-2026-87620 — Observable discrepancy in SVG in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive info
- CVE-2026-87619 — Observable discrepancy in Prefetch in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak cross-origi
- CVE-2026-87566 — Observable discrepancy in Layout in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak sensitive inf
- CVE-2026-87623 — Observable discrepancy in DOM in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engine
- CVE-2026-87518 — Observable discrepancy in Safebrowsing in Google Chrome on on iOS prior to 153.0.8010.36 allowed a remote attacker who h
- CVE-2026-87516 — Observable discrepancy in Navigation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak cross-ori
- CVE-2026-87539 — Observable discrepancy in Network in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain cross-orig
- CVE-2026-87478 — Observable discrepancy in Autofill in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive
- CVE-2026-53933 — Maravel-Framework Vulnerable to Side-Channel Information Disclosure (Error Oracle) via Dynamic Route Fuzzing
- CVE-2026-78617 — WatchGuard Dimension Web UI Authentication Brute-Force Due to Missing Rate Limiting
- CVE-2026-11754 — User Enumeration in Seres Software's syWEB
- CVE-2026-55227 — Observable object existence disclosure in private Weblate projects via globally scoped object lookups
- CVE-2026-79181 — Observable discrepancy in Glic in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive inf
- CVE-2026-78949 — Observable discrepancy in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to o
- CVE-2026-79242 — Observable discrepancy in HTML in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive inf
- CVE-2026-79287 — Observable discrepancy in Forms in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive in
- CVE-2026-78936 — Observable discrepancy in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to o
- CVE-2026-78955 — Observable discrepancy in PerformanceAPIs in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potential
- CVE-2026-79028 — Observable discrepancy in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive