Vulnerabilities > Improper Restriction of Excessive Authentication Attempts

DATE CVE VULNERABILITY TITLE RISK
2024-05-14 CVE-2024-3461 Improper Restriction of Excessive Authentication Attempts vulnerability in Kioware
KioWare for Windows (versions all through 8.35) allows to brute force the PIN number, which protects the application from being closed, as there are no mechanisms preventing a user from excessively guessing the number.
local
low complexity
kioware CWE-307
5.5
2024-04-26 CVE-2024-32868 Improper Restriction of Excessive Authentication Attempts vulnerability in Zitadel
ZITADEL provides users the possibility to use Time-based One-Time-Password (TOTP) and One-Time-Password (OTP) through SMS and Email.
network
low complexity
zitadel CWE-307
8.1
2024-04-24 CVE-2024-28825 Improper Restriction of Excessive Authentication Attempts vulnerability in Checkmk
Improper restriction of excessive authentication attempts on some authentication methods in Checkmk before 2.3.0b5 (beta), 2.2.0p26, 2.1.0p43, and in Checkmk 2.0.0 (EOL) facilitates password brute-forcing.
network
low complexity
checkmk CWE-307
critical
9.8
2024-03-18 CVE-2024-21662 Improper Restriction of Excessive Authentication Attempts vulnerability in Argoproj Argo CD
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes.
network
low complexity
argoproj CWE-307
critical
9.1
2024-03-18 CVE-2024-21652 Improper Restriction of Excessive Authentication Attempts vulnerability in Argoproj Argo CD
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes.
network
low complexity
argoproj CWE-307
critical
9.8
2024-03-06 CVE-2024-24767 Improper Restriction of Excessive Authentication Attempts vulnerability in Icewhale Casaos 0.4.5/0.4.6
CasaOS-UserService provides user management functionalities to CasaOS.
network
low complexity
icewhale CWE-307
critical
9.8
2024-02-19 CVE-2024-1345 Improper Restriction of Excessive Authentication Attempts vulnerability in Laborofficefree 19.10
Weak MySQL database root password in LaborOfficeFree affects version 19.10.
local
low complexity
laborofficefree CWE-307
5.5
2024-02-09 CVE-2023-45190 Improper Restriction of Excessive Authentication Attempts vulnerability in IBM Engineering Lifecycle Optimization 7.0.2/7.0.3
IBM Engineering Lifecycle Optimization 7.0.2 and 7.0.3 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers.
network
low complexity
ibm CWE-307
6.1
2024-01-25 CVE-2023-33759 Improper Restriction of Excessive Authentication Attempts vulnerability in Splicecom Maximiser Soft PBX
SpliceCom Maximiser Soft PBX v1.5 and before does not restrict excessive authentication attempts, allowing attackers to bypass authentication via a brute force attack.
network
low complexity
splicecom CWE-307
critical
9.8
2024-01-22 CVE-2022-45790 Improper Restriction of Excessive Authentication Attempts vulnerability in Omron products
The Omron FINS protocol has an authenticated feature to prevent access to memory regions.
network
low complexity
omron CWE-307
critical
9.1