Vulnerabilities > Improper Restriction of Excessive Authentication Attempts

DATE CVE VULNERABILITY TITLE RISK
2022-08-08 CVE-2022-35490 Improper Restriction of Excessive Authentication Attempts vulnerability in Zammad 5.2.0
Zammad 5.2.0 is vulnerable to privilege escalation.
network
low complexity
zammad CWE-307
critical
9.8
2022-08-04 CVE-2022-31118 Improper Restriction of Excessive Authentication Attempts vulnerability in Nextcloud Server
Nextcloud server is an open source personal cloud solution.
network
low complexity
nextcloud CWE-307
5.3
2022-08-02 CVE-2022-35925 Improper Restriction of Excessive Authentication Attempts vulnerability in Joinbookwyrm Bookwyrm
BookWyrm is a social network for tracking reading.
network
low complexity
joinbookwyrm CWE-307
critical
9.8
2022-07-28 CVE-2021-22640 Improper Restriction of Excessive Authentication Attempts vulnerability in Ovarro products
An attacker can decrypt the Ovarro TBox login password by communication capture and brute force attacks.
network
low complexity
ovarro CWE-307
critical
9.8
2022-07-21 CVE-2022-31234 Improper Restriction of Excessive Authentication Attempts vulnerability in Dell products
Dell EMC PowerStore, contain(s) an Improper Restriction of Excessive Authentication Attempts Vulnerability in PowerStore Manager GUI.
network
low complexity
dell CWE-307
critical
9.8
2022-07-18 CVE-2022-24689 Improper Restriction of Excessive Authentication Attempts vulnerability in DSK Dsknet 2.16.136.0/2.17.136.5
An issue was discovered in DSK DSKNet 2.16.136.0 and 2.17.136.5.
network
low complexity
dsk CWE-307
5.3
2022-07-14 CVE-2022-22452 Improper Restriction of Excessive Authentication Attempts vulnerability in IBM Security Verify Governance 10.0
IBM Security Verify Identity Manager 10.0 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials.
network
low complexity
ibm CWE-307
7.5
2022-07-05 CVE-2022-2321 Improper Restriction of Excessive Authentication Attempts vulnerability in Heroiclabs Nakama
Improper Restriction of Excessive Authentication Attempts in GitHub repository heroiclabs/nakama prior to 3.13.0.
network
low complexity
heroiclabs CWE-307
critical
9.8
2022-06-30 CVE-2022-22487 Improper Restriction of Excessive Authentication Attempts vulnerability in IBM Spectrum Protect Server
An IBM Spectrum Protect storage agent could allow a remote attacker to perform a brute force attack by allowing unlimited attempts to login to the storage agent without locking the administrative ID.
network
low complexity
ibm CWE-307
critical
9.8
2022-06-30 CVE-2022-22496 Improper Restriction of Excessive Authentication Attempts vulnerability in IBM Spectrum Protect Server
While a user account for the IBM Spectrum Protect Server 8.1.0.000 through 8.1.14 is being established, it may be configured to use SESSIONSECURITY=TRANSITIONAL.
low complexity
ibm CWE-307
6.5