Vulnerabilities > Improper Restriction of Excessive Authentication Attempts

DATE CVE VULNERABILITY TITLE RISK
2022-09-08 CVE-2022-37144 Improper Restriction of Excessive Authentication Attempts vulnerability in Plextrac
The PlexTrac platform prior to API version 1.17.0 does not restrict excessive MFA TOTP submission attempts.
network
low complexity
plextrac CWE-307
8.8
2022-09-08 CVE-2022-37145 Improper Restriction of Excessive Authentication Attempts vulnerability in Plextrac
The PlexTrac platform prior to version 1.17.0 does not restrict excessive authentication attempts for accounts configured to use the PlexTrac authentication provider.
network
low complexity
plextrac CWE-307
7.5
2022-08-12 CVE-2022-35932 Improper Restriction of Excessive Authentication Attempts vulnerability in Nextcloud Talk
Nextcloud Talk is a video and audio conferencing app for Nextcloud.
network
low complexity
nextcloud CWE-307
5.3
2022-08-10 CVE-2022-2457 Improper Restriction of Excessive Authentication Attempts vulnerability in Redhat Process Automation Manager 7.0/7.5.1
A flaw was found in Red Hat Process Automation Manager 7 where an attacker can benefit from a brute force attack against Administration Console as the application does not limit the number of unsuccessful login attempts.
network
low complexity
redhat CWE-307
critical
9.8
2022-08-08 CVE-2022-35490 Improper Restriction of Excessive Authentication Attempts vulnerability in Zammad 5.2.0
Zammad 5.2.0 is vulnerable to privilege escalation.
network
low complexity
zammad CWE-307
critical
9.8
2022-08-04 CVE-2022-31118 Improper Restriction of Excessive Authentication Attempts vulnerability in Nextcloud Server
Nextcloud server is an open source personal cloud solution.
network
low complexity
nextcloud CWE-307
5.3
2022-08-02 CVE-2022-35925 Improper Restriction of Excessive Authentication Attempts vulnerability in Joinbookwyrm Bookwyrm
BookWyrm is a social network for tracking reading.
network
low complexity
joinbookwyrm CWE-307
critical
9.8
2022-07-28 CVE-2021-22640 Improper Restriction of Excessive Authentication Attempts vulnerability in Ovarro products
An attacker can decrypt the Ovarro TBox login password by communication capture and brute force attacks.
network
low complexity
ovarro CWE-307
critical
9.8
2022-07-21 CVE-2022-31234 Improper Restriction of Excessive Authentication Attempts vulnerability in Dell products
Dell EMC PowerStore, contain(s) an Improper Restriction of Excessive Authentication Attempts Vulnerability in PowerStore Manager GUI.
network
low complexity
dell CWE-307
critical
9.8
2022-07-18 CVE-2022-24689 Improper Restriction of Excessive Authentication Attempts vulnerability in DSK Dsknet 2.16.136.0/2.17.136.5
An issue was discovered in DSK DSKNet 2.16.136.0 and 2.17.136.5.
network
low complexity
dsk CWE-307
5.3