Vulnerabilities > Improper Restriction of Excessive Authentication Attempts
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-01-22 | CVE-2022-45790 | Improper Restriction of Excessive Authentication Attempts vulnerability in Omron products The Omron FINS protocol has an authenticated feature to prevent access to memory regions. | 9.1 |
2024-01-11 | CVE-2023-50123 | Improper Restriction of Excessive Authentication Attempts vulnerability in Hozard Alarm System 1.0 The number of attempts to bring the Hozard Alarm system (alarmsystemen) v1.0 to a disarmed state is not limited. | 8.1 |
2023-12-20 | CVE-2023-6912 | Improper Restriction of Excessive Authentication Attempts vulnerability in M-Files Server Lack of protection against brute force attacks in M-Files Server before 23.12.13205.0 allows an attacker unlimited authentication attempts, potentially compromising targeted M-Files user accounts by guessing passwords. | 9.8 |
2023-12-20 | CVE-2023-27172 | Improper Restriction of Excessive Authentication Attempts vulnerability in Xpand-It Write-Back Manager 2.3.1 Xpand IT Write-back Manager v2.3.1 uses weak secret keys to sign JWT tokens. | 9.1 |
2023-12-19 | CVE-2023-6928 | Improper Restriction of Excessive Authentication Attempts vulnerability in Eurotel Etl3100 Firmware 01C01/01X37 EuroTel ETL3100 versions v01c01 and v01x37 does not limit the number of attempts to guess administrative credentials in remote password attacks to gain full control of the system. | 9.8 |
2023-12-18 | CVE-2023-6272 | Improper Restriction of Excessive Authentication Attempts vulnerability in Thememylogin 2FA The Theme My Login 2FA WordPress plugin before 1.2 does not rate limit 2FA validation attempts, which may allow an attacker to brute-force all possibilities, which shouldn't be too long, as the 2FA codes are 6 digits. | 9.8 |
2023-12-13 | CVE-2023-50444 | Improper Restriction of Excessive Authentication Attempts vulnerability in Primx Zed!, Zedmail and Zonecentral By default, .ZED containers produced by PRIMX ZED! for Windows before Q.2020.3 (ANSSI qualification submission); ZED! for Windows before Q.2021.2 (ANSSI qualification submission); ZONECENTRAL for Windows before Q.2021.2 (ANSSI qualification submission); ZONECENTRAL for Windows before 2023.5; ZEDMAIL for Windows before 2023.5; and ZED! for Windows, Mac, Linux before 2023.5 include an encrypted version of sensitive user information, which could allow an unauthenticated attacker to obtain it via brute force. | 7.5 |
2023-12-08 | CVE-2023-49443 | Improper Restriction of Excessive Authentication Attempts vulnerability in Html-Js Doracms 2.1.8 DoraCMS v2.1.8 was discovered to re-use the same code for verification of valid usernames and passwords. | 9.8 |
2023-12-04 | CVE-2023-24051 | Improper Restriction of Excessive Authentication Attempts vulnerability in Connectize Ac21000 G6 Firmware 641.139.1.1256 A client side rate limit issue discovered in Connectize AC21000 G6 641.139.1.1256 allows attackers to gain escalated privileges via brute force style attacks. | 9.8 |
2023-11-18 | CVE-2023-48028 | Improper Restriction of Excessive Authentication Attempts vulnerability in Kodcloud Kodbox 1.46.01 kodbox 1.46.01 has a security flaw that enables user enumeration. | 9.8 |