İçeriğe atla
Noroxi

CWE-307 · 628 kayıt

Improper Restriction of Excessive Authentication Attempts

Bu sınıftaki CVE’ler

628 kayıt

  • CVE-2019-17240
    51Planlayın

    bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many different forged X-

    KritikCVSS 9,8Kavram kanıtıEPSS %40

    bludit · bludit6 Eki 2019

  • CVE-2020-15906
    47Planlayın

    tiki-login.php in Tiki before 21.2 sets the admin password to a blank value after 50 invalid login attempts.

    KritikCVSS 9,8Kavram kanıtıEPSS %27

    tiki · tiki22 Eki 2020

  • CVE-2025-4094
    44Planlayın

    Digits < 8.4.6.1 - Auth Bypass via OTP Bruteforcing

    KritikCVSS 9,8Kavram kanıtıEPSS %16

    unitedover · digits21 May 2025

  • CVE-2024-39225
    43Planlayın

    GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16,

    KritikCVSS 9,8İstismar yokEPSS %14

    gl-inet · mt6000 firmware6 Ağu 2024

  • CVE-2023-27100
    42Planlayın

    Improper restriction of excessive authentication attempts in the SSHGuard component of Netgate pfSense Plus software v22.05.1 and pfSense CE

    KritikCVSS 9,8Kavram kanıtıEPSS %10

    netgate · pfsense plus22 Mar 2023

  • CVE-2001-1291
    42Planlayın

    The telnet server for 3Com hardware such as PS40 SuperStack II does not delay or disconnect remote attackers who provide an incorrect userna

    KritikCVSS 9,8Kavram kanıtıEPSS %9

    3com · superstack ii ps hub 40 firmware12 Tem 2001

  • CVE-2001-1339
    41Planlayın

    Beck IPC GmbH IPC@CHIP telnet service does not delay or disconnect users from the service when bad passwords are entered, which makes it eas

    KritikCVSS 9,8Kavram kanıtıEPSS %7

    anybus · ipc\@chip firmware24 May 2001

  • CVE-2021-41435
    41Planlayın

    A brute-force protection bypass in CAPTCHA protection in ASUS ROG Rapture GT-AX11000, RT-AX3000, RT-AX55, RT-AX56U, RT-AX56U_V2, RT-AX58U, R

    KritikCVSS 9,8İstismar yokEPSS %6

    asus · gt-ax11000 firmware19 Kas 2021

  • CVE-2017-7898
    41Planlayın

    An Improper Restriction of Excessive Authentication Attempts issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1100 progr

    KritikCVSS 9,8İstismar yokEPSS %5

    rockwellautomation · 1763-l16awa series a29 Haz 2017

  • CVE-2023-29301
    40Planlayın

    Adobe ColdFusion Improper Restriction of Excessive Authentication Attempts Security feature bypass

    YüksekCVSS 7,5İstismar yokEPSS %35

    adobe · coldfusion12 Tem 2023

  • CVE-2020-7995
    40Planlayın

    The htdocs/index.php?mainmenu=home login page in Dolibarr 10.0.6 allows an unlimited rate of failed authentication attempts.

    KritikCVSS 9,8İstismar yokEPSS %5

    dolibarr · dolibarr erp\/crm26 Oca 2020

  • CVE-2020-35590
    40Planlayın

    LimitLoginAttempts.php in the limit-login-attempts-reloaded plugin before 2.17.4 for WordPress allows a bypass of (per IP address) rate limi

    KritikCVSS 9,8Kavram kanıtıEPSS %4

    limitloginattempts · limit login attempts reloaded21 Ara 2020

  • CVE-2021-27514
    40Planlayın

    EyesOfNetwork 5.3-10 uses an integer of between 8 and 10 digits for the session ID, which might be leveraged for brute-force authentication

    KritikCVSS 9,8İstismar yokEPSS %4

    eyesofnetwork · eyesofnetwork21 Şub 2021

  • CVE-1999-1324
    40Planlayın

    VAXstations running Open VMS 5.3 through 5.5-2 with VMS DECwindows or MOTIF do not properly disable access to user accounts that exceed the

    KritikCVSS 9,8İstismar yokEPSS %3

    hp · openvms vax31 Ara 1999

  • CVE-2018-1373
    40Planlayın

    IBM Security Guardium Big Data Intelligence (SonarG) 3.1 uses an inadequate account lockout setting that could allow a remote attacker to br

    KritikCVSS 9,8İstismar yokEPSS %3

    ibm · security guardium big data intelligence2 Mar 2018

  • CVE-2018-5469
    40Planlayın

    An Improper Restriction of Excessive Authentication Attempts issue was discovered in Belden Hirschmann RS, RSR, RSB, MACH100, MACH1000, MACH

    KritikCVSS 9,8İstismar yokEPSS %3

    belden · hirschmann rs20-0900mmm2tdau6 Mar 2018

  • CVE-2020-28212
    40Planlayın

    A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists in PLC Simulator on EcoStruxureª Control Expert (n

    KritikCVSS 9,8İstismar yokEPSS %3

    schneider-electric · ecostruxure control expert19 Kas 2020

  • CVE-2019-6524
    40Planlayın

    Moxa IKS and EDS do not implement sufficient measures to prevent multiple failed authentication attempts, which may allow an attacker to dis

    KritikCVSS 9,8İstismar yokEPSS %3

    moxa · iks-g6824a firmware5 Mar 2019

  • CVE-2020-6852
    40Planlayın

    CACAGOO Cloud Storage Intelligent Camera TV-288ZD-2MP with firmware 3.4.2.0919 has weak authentication of TELNET access, leading to root pri

    KritikCVSS 9,8İstismar yokEPSS %2

    cacagoo · tv-288zd-2mp firmware2 Nis 2020

  • CVE-2023-36434
    40Planlayın

    Windows IIS Server Elevation of Privilege Vulnerability

    KritikCVSS 9,8İstismar yokEPSS %2

    microsoft · windows 10 150710 Eki 2023

  • CVE-2019-12941
    40Planlayın

    AutoPi Wi-Fi/NB and 4G/LTE devices before 2019-10-15 allows an attacker to perform a brute-force attack or dictionary attack to gain access

    KritikCVSS 9,8İstismar yokEPSS %2

    autopi · wi-fi\/nb firmware14 Eki 2019

  • CVE-2020-4567
    40Planlayın

    IBM Tivoli Key Lifecycle Manager 3.0.1 and 4.0 uses an inadequate account lockout setting that could allow a remote attacker to brute force

    KritikCVSS 9,8İstismar yokEPSS %2

    ibm · security key lifecycle manager29 Tem 2020

  • CVE-2016-9124
    40Planlayın

    Revive Adserver before 3.2.3 suffers from Improper Restriction of Excessive Authentication Attempts.

    KritikCVSS 9,8İstismar yokEPSS %2

    revive-adserver · revive adserver27 Mar 2017

  • CVE-2018-1475
    40Planlayın

    IBM BigFix Platform 9.2 and 9.5 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credent

    KritikCVSS 9,8İstismar yokEPSS %2

    ibm · bigfix platform27 Nis 2018

  • CVE-2026-44596
    40Planlayın

    Yamcs: No Rate Limiting on Authentication Endpoint

    KritikCVSS 9,8Kavram kanıtıEPSS %2

    spaceapplications · yamcs16 Tem 2026

Tüm zafiyet sınıfları