Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-204 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 22 | 22 | 0 |
▃▃█▆
2026-05 3 · 2026-06 3 · 2026-07 9 · 2026-08 7
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2018-25350 | 9.3 | 36.3 | — | userSpice 4.3.24 Username Enumeration via existingUsernameCheck.php |
| CVE-2026-19965 | 2.9 | 32.9 | — | automad Password Reset Endpoint UserController.php requestPasswordResetToken response d… |
| CVE-2026-14672 | 5.3 | 32.7 | — | PostgreSQL observable response discrepancy with non-default scram_iterations provides u… |
| CVE-2026-60007 | 9.1 | 31.7 | — | — |
| CVE-2026-61503 | 6.9 | 27.5 | — | Rejetto HFS < 3.2.1 Username Enumeration via Login Response Differences |
| CVE-2026-73306 | 5.3 | 25.0 | — | Budibase: Account Enumeration via Login Lockout Response Differential |
| CVE-2026-54445 | 6.9 | 21.8 | — | Vantage6: Set admin user and password from environment or configuration |
| CVE-2026-54768 | 6.9 | 20.3 | — | WPGraphQL has deprecated `user` field on SendPasswordResetEmailPayload that leaks user … |
| CVE-2026-53422 | 2.3 | 18.2 | — | SFTP REALPATH path-existence oracle allowing filesystem enumeration outside configured … |
| CVE-2026-15747 | 9.1 | 17.3 | — | Mojolicious versions from 4.59 before 9.48 for Perl expose a stable representation of t… |
| CVE-2026-72588 | 5.3 | 16.8 | — | bluewave-labs Checkmate - User Enumeration via Differential HTTP Response in Password R… |
| CVE-2026-42218 | 5.3 | 16.7 | — | XRDP is vulnerable to a server timing attack, leading to user enumeration |
| CVE-2026-44753 | 3.7 | 12.8 | — | Information Disclosure vulnerability in SAP HANA Extended Application Services classic … |
| CVE-2026-43926 | 6.3 | 12.4 | — | FOSSBilling's password reset confirmation endpoint lacks rate limiting |
| CVE-2026-53908 | 6.9 | 11.7 | — | User Enumeration in MCO |
| CVE-2026-45294 | 5.3 | 11.6 | — | FreeScout: User Account Enumeration via Password Reset Response Differentiation |
| CVE-2026-53947 | 5.3 | 11.0 | — | Ghost: Member existence leak via magic link sign-in response |
| CVE-2026-55998 | 5.3 | 10.9 | — | Cluster Existence Oracle via Unauthenticated Import Endpoint |
| CVE-2024-23574 | 5.3 | 9.9 | — | — |
| CVE-2026-14202 | 5.3 | 9.9 | — | Username Enumeration via Differential Login Responses in Bilin Software's HUMANIST Digi… |
| Vendor | CVEs |
|---|---|
| bilin software and informatics consultancy | 1 |
| bluewave-labs | 1 |
| budibase | 1 |
| cyrusimap | 1 |
| eclipse foundation | 1 |
| erlang | 1 |
| fossbilling | 1 |
| freescout-help-desk | 1 |
| hclsoftware | 1 |
| mycomplianceoffice | 1 |
| neutrinolabs | 1 |
| rejetto | 1 |
| sap_se | 1 |
| sri | 1 |
| suse | 1 |