Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-208 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 44 | 44 | 0 |
▄▇█▇
2026-05 6 · 2026-06 12 · 2026-07 14 · 2026-08 12
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-47783 | 8.1 | 67.3 | — | — |
| CVE-2026-8794 | 6.9 | 49.5 | — | PaperCut NG/MF: User enumeration via timing attack |
| CVE-2026-47784 | 8.1 | 43.6 | — | — |
| CVE-2025-49506 | 7.5 | 32.8 | — | Apache Portable Runtime Utility: apr_password_validate() vulnerable to timing attack |
| CVE-2026-47373 | 7.5 | 32.6 | — | Crypt::SaltedHash versions through 0.09 for Perl is susceptible to timing attacks |
| CVE-2026-44061 | 5.9 | 32.2 | — | DES-ECB auth with timing side channel |
| CVE-2026-5419 | 3.7 | 31.3 | — | Gnutls: gnutls: information disclosure via timing side-channel in pkcs#7 padding removal |
| CVE-2026-48859 | 6.3 | 28.7 | — | SSH server timing side-channel in ssh_auth:check_password/3 allows unauthenticated user… |
| CVE-2026-48166 | 5.3 | 27.6 | — | Filament: Timing-based user enumeration on login page |
| CVE-2026-54411 | 6.9 | 26.3 | — | Linux-PAM pam_userdb Observable Timing Discrepancy in Plaintext Password Comparison |
| CVE-2026-13183 | 7.5 | 24.9 | — | RadAsyncUpload Upload Metadata Timing Oracle Vulnerability in Telerik UI for ASP.NET AJAX |
| CVE-2017-20240 | 5.9 | 24.8 | — | Crypt::PBKDF2 versions before 0.261630 for Perl are vulnerable to timing attacks |
| CVE-2026-6656 | 7.5 | 24.5 | — | Crypt::Password versions through 0.28 for Perl are susceptible to timing attacks |
| CVE-2026-15041 | 3.7 | 22.6 | — | 389-ds-base: 389-ds-base: non-constant-time comparison in pbkdf2-sha256 password verifi… |
| CVE-2026-13758 | 3.7 | 22.1 | — | CryptX versions before 0.088_001 for Perl compare AEAD authentication tags in non-const… |
| CVE-2026-16731 | 8.3 | 20.0 | — | Authentication and authorization bypass via cryptographic timing side-channel attack in… |
| CVE-2024-14041 | 8.2 | 19.9 | — | ML-KEM (Kyber) decapsulation leaks private key information through non-constant-time di… |
| CVE-2026-54685 | 5.3 | 19.2 | — | FileBrowser Quantum has Username Enumeration via Authentication Timing Side-Channel |
| CVE-2026-16315 | 8.1 | 17.7 | — | Authentication and authorization bypass via cryptographic timing side-channel attack in… |
| CVE-2026-59218 | 5.3 | 15.5 | — | Open WebUI: Account enumeration via observable login timing discrepancy |
| Vendor | CVEs |
|---|---|
| amd | 3 |
| op-tee | 3 |
| memcached | 2 |
| oberon microsystems | 2 |
| omicron electronics | 2 |
| red hat | 2 |
| apache | 1 |
| arodland | 1 |
| coollabsio | 1 |
| drsteve | 1 |
| erlang | 1 |
| filamentphp | 1 |
| 1 | |
| gtsteffaniak | 1 |
| hclsoftware | 1 |