Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-204
Weakness type CWE-204 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 43 | 43 | 0 |
Monthly trend
▂▁▁▁▃▃▆█▇▂
2026-01 1 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 3 · 2026-06 3 · 2026-07 9 · 2026-08 13 · 2026-09 12 · 2026-10 2
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-69519 | 8.6 | 62.4 | — | Azure Stack HCI Information Disclosure Vulnerability |
| CVE-2026-66002 | 6.9 | 55.9 | — | Frappe: User Enumeration via PDDR |
| CVE-2026-54739 | 6.9 | 46.3 | — | Lemmy: Login Endpoint User Enumeration via HTTP Response Code Differential |
| CVE-2026-60007 | 9.1 | 44.2 | — | — |
| CVE-2026-19965 | 2.9 | 40.2 | — | automad Password Reset Endpoint UserController.php requestPasswordResetToken response d… |
| CVE-2026-81033 | 6.9 | 39.5 | — | Automatisch through 0.15.0 User Enumeration via Forgot-Password Response Discrepancy |
| CVE-2026-54445 | 6.9 | 39.2 | — | Vantage6: Set admin user and password from environment or configuration |
| CVE-2026-84307 | 3.7 | 37.6 | — | Filament: Password validity disclosure for accounts denied panel access on login page |
| CVE-2026-54768 | 6.9 | 36.5 | — | WPGraphQL has deprecated `user` field on SendPasswordResetEmailPayload that leaks user … |
| CVE-2026-73306 | 5.3 | 35.8 | — | Budibase: Account Enumeration via Login Lockout Response Differential |
| CVE-2026-61503 | 6.9 | 35.7 | — | Rejetto HFS < 3.2.1 Username Enumeration via Login Response Differences |
| CVE-2026-89173 | 6.9 | 35.7 | — | Kingdom Communication Associated|Smart Video Intercom System - Sensitive Data Exposure |
| CVE-2018-25350 | 9.3 | 35.4 | — | userSpice 4.3.24 Username Enumeration via existingUsernameCheck.php |
| CVE-2026-27462 | 7.5 | 35.3 | — | Combodo iTop: User enumeration via password reset |
| CVE-2026-72588 | 5.3 | 34.1 | — | bluewave-labs Checkmate - User Enumeration via Differential HTTP Response in Password R… |
| CVE-2026-42218 | 5.3 | 33.8 | — | XRDP is vulnerable to a server timing attack, leading to user enumeration |
| CVE-2026-86758 | 7.1 | 33.2 | — | Snipe-IT before 8.7.0 License Key Exposure via CSV Export |
| CVE-2026-75575 | 6.9 | 31.6 | — | Rocket.Chat Missing DDP Rate Limit on the sendForgotPasswordEmail Meteor Method |
| CVE-2026-53908 | 6.9 | 27.6 | — | User Enumeration in MCO |
| CVE-2026-43926 | 6.3 | 25.8 | — | FOSSBilling's password reset confirmation endpoint lacks rate limiting |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| red hat | 3 |
| automatisch | 1 |
| bilin software and informatics consultancy | 1 |
| bluewave-labs | 1 |
| budibase | 1 |
| combodo | 1 |
| cyrusimap | 1 |
| dernekplus | 1 |
| discord | 1 |
| eclipse foundation | 1 |
| elastic | 1 |
| erlang | 1 |
| filamentphp | 1 |
| fossbilling | 1 |
| frappe | 1 |