boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-204

Weakness type CWE-204 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
22220

Monthly trend

▃▃█▆

2026-05 3 · 2026-06 3 · 2026-07 9 · 2026-08 7

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2018-253509.336.3userSpice 4.3.24 Username Enumeration via existingUsernameCheck.php
CVE-2026-199652.932.9automad Password Reset Endpoint UserController.php requestPasswordResetToken response d…
CVE-2026-146725.332.7PostgreSQL observable response discrepancy with non-default scram_iterations provides u…
CVE-2026-600079.131.7
CVE-2026-615036.927.5Rejetto HFS < 3.2.1 Username Enumeration via Login Response Differences
CVE-2026-733065.325.0Budibase: Account Enumeration via Login Lockout Response Differential
CVE-2026-544456.921.8Vantage6: Set admin user and password from environment or configuration
CVE-2026-547686.920.3WPGraphQL has deprecated `user` field on SendPasswordResetEmailPayload that leaks user …
CVE-2026-534222.318.2SFTP REALPATH path-existence oracle allowing filesystem enumeration outside configured …
CVE-2026-157479.117.3Mojolicious versions from 4.59 before 9.48 for Perl expose a stable representation of t…
CVE-2026-725885.316.8bluewave-labs Checkmate - User Enumeration via Differential HTTP Response in Password R…
CVE-2026-422185.316.7XRDP is vulnerable to a server timing attack, leading to user enumeration
CVE-2026-447533.712.8Information Disclosure vulnerability in SAP HANA Extended Application Services classic …
CVE-2026-439266.312.4FOSSBilling's password reset confirmation endpoint lacks rate limiting
CVE-2026-539086.911.7User Enumeration in MCO
CVE-2026-452945.311.6FreeScout: User Account Enumeration via Password Reset Response Differentiation
CVE-2026-539475.311.0Ghost: Member existence leak via magic link sign-in response
CVE-2026-559985.310.9Cluster Existence Oracle via Unauthenticated Import Endpoint
CVE-2024-235745.39.9
CVE-2026-142025.39.9Username Enumeration via Differential Login Responses in Bilin Software's HUMANIST Digi…

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
bilin software and informatics consultancy1
bluewave-labs1
budibase1
cyrusimap1
eclipse foundation1
erlang1
fossbilling1
freescout-help-desk1
hclsoftware1
mycomplianceoffice1
neutrinolabs1
rejetto1
sap_se1
sri1
suse1