CWE-645 · 8 records
Overly Restrictive Account Lockout Mechanism
CVEs in this class
8 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
60This week | CVE-2023-4346Weaponized | KNX devices that use KNX Connection Authorization and support Option 1 are, depending on the implementation, vulnerable to being locked andknx · connection authorization · CWE-645 | High7.5 | KEV | 1.3% | Aug 29, 2023 |
30Monitor | CVE-2026-25907No exploit | Dell PowerScale OneFS, version 9.13.0.0, contains an overly restrictive account lockout mechanism vulnerability.dell · powerscale onefs · CWE-645 | High7.5 | — | 0.5% | Mar 4, 2026 |
28Monitor | CVE-2026-53982No exploit | Cap-go Console < 12.28.2 Account Deletion DoS via Device Identifier Associationcap-go · capgo · CWE-645 | High7.1 | — | 0.6% | Jun 12, 2026 |
25Monitor | CVE-2024-37028No exploit | BIG-IP Next Central Manager vulnerabilityf5 · big-ip next central manager · CWE-645 | Medium6.3 | — | 0.4% | Aug 14, 2024 |
21Monitor | CVE-2024-1722No exploit | Keycloak-core: dos via account lockoutredhat · keycloak · CWE-645 | Medium5.3 | — | 0.8% | Feb 28, 2024 |
21Monitor | CVE-2025-5241No exploit | Denial-of-Service Vulnerability in MELSEC iQ-F Seriesmitsubishi electric corporation · melsec iq-f series fx5u-32mt/es · CWE-645 | Medium5.3 | — | 0.4% | Jul 10, 2025 |
21Monitor | CVE-2025-31947No exploit | Repeated LDAP login failures can lock an LDAP accountmattermost · mattermost server · CWE-645 | Medium5.3 | — | 0.3% | May 15, 2025 |
14Monitor | GHSA-3hrr-xwvg-hxvrNo exploit | Duplicate Advisory: Keycloak DoS via account lockoutMaven · org.keycloak:keycloak-core · CWE-645 | Low3.7 | — | — | Feb 29, 2024 |
- CVE-2023-434660This week
KNX devices that use KNX Connection Authorization and support Option 1 are, depending on the implementation, vulnerable to being locked and
HighCVSS 7.5KEVWeaponizedEPSS 1%knx · connection authorizationAug 29, 2023
- CVE-2026-2590730Monitor
Dell PowerScale OneFS, version 9.13.0.0, contains an overly restrictive account lockout mechanism vulnerability.
HighCVSS 7.5No exploitEPSS 0%dell · powerscale onefsMar 4, 2026
- CVE-2026-5398228Monitor
Cap-go Console < 12.28.2 Account Deletion DoS via Device Identifier Association
HighCVSS 7.1No exploitEPSS 1%cap-go · capgoJun 12, 2026
- CVE-2024-3702825Monitor
BIG-IP Next Central Manager vulnerability
MediumCVSS 6.3No exploitEPSS 0%f5 · big-ip next central managerAug 14, 2024
- CVE-2024-172221Monitor
Keycloak-core: dos via account lockout
MediumCVSS 5.3No exploitEPSS 1%redhat · keycloakFeb 28, 2024
- CVE-2025-524121Monitor
Denial-of-Service Vulnerability in MELSEC iQ-F Series
MediumCVSS 5.3No exploitEPSS 0%mitsubishi electric corporation · melsec iq-f series fx5u-32mt/esJul 10, 2025
- CVE-2025-3194721Monitor
Repeated LDAP login failures can lock an LDAP account
MediumCVSS 5.3No exploitEPSS 0%mattermost · mattermost serverMay 15, 2025
- GHSA-3hrr-xwvg-hxvr14Monitor
Duplicate Advisory: Keycloak DoS via account lockout
LowCVSS 3.7No exploitMaven · org.keycloak:keycloak-coreFeb 29, 2024