Vulnerabilities > Improper Restriction of Excessive Authentication Attempts

DATE CVE VULNERABILITY TITLE RISK
2023-06-15 CVE-2022-32757 Improper Restriction of Excessive Authentication Attempts vulnerability in IBM Security Directory Suite VA
IBM Security Directory Suite VA 8.0.1 through 8.0.1.19 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials.
network
low complexity
ibm CWE-307
7.5
2023-06-13 CVE-2022-42478 Improper Restriction of Excessive Authentication Attempts vulnerability in Fortinet Fortisiem
An Improper Restriction of Excessive Authentication Attempts [CWE-307] in FortiSIEM below 7.0.0 may allow a non-privileged user with access to several endpoints to brute force attack these endpoints.
network
low complexity
fortinet CWE-307
8.8
2023-06-09 CVE-2023-3173 Improper Restriction of Excessive Authentication Attempts vulnerability in Froxlor
Improper Restriction of Excessive Authentication Attempts in GitHub repository froxlor/froxlor prior to 2.0.20.
network
low complexity
froxlor CWE-307
critical
9.8
2023-06-08 CVE-2023-34243 Improper Restriction of Excessive Authentication Attempts vulnerability in Tgstation13 Tgstation-Server
TGstation is a toolset to manage production BYOND servers.
network
low complexity
tgstation13 CWE-307
5.3
2023-06-01 CVE-2023-33754 Improper Restriction of Excessive Authentication Attempts vulnerability in Inpiazza Cloud Wifi
The captive portal in Inpiazza Cloud WiFi versions prior to v4.2.17 does not enforce limits on the number of attempts for password recovery, allowing attackers to brute force valid user accounts to gain access to login credentials.
network
low complexity
inpiazza CWE-307
6.5
2023-05-30 CVE-2023-23755 Improper Restriction of Excessive Authentication Attempts vulnerability in Joomla Joomla!
An issue was discovered in Joomla! 4.2.0 through 4.3.1.
network
low complexity
joomla CWE-307
7.5
2023-05-26 CVE-2023-32319 Improper Restriction of Excessive Authentication Attempts vulnerability in Nextcloud Server
Nextcloud server is an open source personal cloud implementation.
network
low complexity
nextcloud CWE-307
6.5
2023-05-25 CVE-2023-32074 Improper Restriction of Excessive Authentication Attempts vulnerability in Nextcloud User Oidc
user_oidc app is an OpenID Connect user backend for Nextcloud.
network
low complexity
nextcloud CWE-307
critical
9.8
2023-05-05 CVE-2023-2531 Improper Restriction of Excessive Authentication Attempts vulnerability in Azuracast
Improper Restriction of Excessive Authentication Attempts in GitHub repository azuracast/azuracast prior to 0.18.3.
network
low complexity
azuracast CWE-307
critical
9.8
2023-04-25 CVE-2023-28847 Improper Restriction of Excessive Authentication Attempts vulnerability in Nextcloud Server
Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform.
network
low complexity
nextcloud CWE-307
7.5