CWE-799
62 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-799page 1 of 2
- CVE-2016-6543MEDIUMCVSS 5.9EG 5.92018-07-13
A captured MAC/device ID of an iTrack Easy can be registered under multiple user accounts allowing access to getgps GPS data, which can allow unauthenticated parties to track the device.
- CVE-2020-5141MEDIUMCVSS 6.5EG 6.52020-10-12
A vulnerability in SonicOS allows a remote unauthenticated attacker to brute force Virtual Assist ticket ID in the firewall SSLVPN service. This vulnerability affected SonicOS Gen 5 version 5.9.1.7, 5.9.1.13, Gen 6 version 6.5.4.7, 6.5.1.1…
- CVE-2021-32678LOWCVSS 3.7EG 3.72021-07-12
Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.0.11, and 21.0.3, ratelimits are not applied to OCS API responses. This affects any OCS API controller (`OCSController`) using the `@BruteF…
- CVE-2021-32703MEDIUMCVSS 5.3EG 5.32021-07-12
Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, there was a lack of ratelimiting on the shareinfo endpoint. This may have allowed an attacker to enumerate potentially val…
- CVE-2021-32705MEDIUMCVSS 5.3EG 5.32021-07-12
Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, there was a lack of ratelimiting on the public DAV endpoint. This may have allowed an attacker to enumerate potentially va…
- CVE-2021-32741MEDIUMCVSS 5.3EG 5.32021-07-12
Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, there was a lack of ratelimiting on the public share link mount endpoint. This may have allowed an attacker to enumerate p…
- CVE-2021-37191MEDIUMCVSS 4.3EG 4.32021-09-14
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). An unauthenticated attacker in the same network of the affected system could brute force the usernames from the affected software.
- CVE-2021-37910LOWCVSS 3.7EG 3.72021-11-12
ASUS routers Wi-Fi protected access protocol (WPA2 and WPA3-SAE) has improper control of Interaction frequency vulnerability, an unauthenticated attacker can remotely disconnect other users' connections by sending specially crafted SAE aut…
- CVE-2021-41177HIGHCVSS 8.1EG 8.12021-10-25
Nextcloud is an open-source, self-hosted productivity platform. Prior to versions 20.0.13, 21.0.5, and 22.2.0, Nextcloud Server did not implement a database backend for rate-limiting purposes. Any component of Nextcloud using rate-limits (…
- CVE-2023-27279MEDIUMCVSS 6.5EG 6.52024-04-19
IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a user to cause a denial of service due to missing API rate limiting. IBM X-Force ID: 248533.
- CVE-2023-2758LOWCVSS 3.7EG 3.72023-05-31
A denial of service vulnerability exists in Contec CONPROSYS HMI System versions 3.5.2 and prior. When there is a time-zone mismatch in certain configuration files, a remote, unauthenticated attacker may deny logins for an extended period …
- CVE-2023-35621HIGHCVSS 7.5EG 7.52023-12-12
Microsoft Dynamics 365 Finance and Operations Denial of Service Vulnerability
- CVE-2023-38068MEDIUMCVSS 6.5EG 6.52023-07-12
In JetBrains YouTrack before 2023.1.16597 captcha was not properly validated for Helpdesk forms
- CVE-2023-40332MEDIUMCVSS 5.3EG 5.32024-06-04
Improper Control of Interaction Frequency vulnerability in Lester ‘GaMerZ’ Chan WP-PostRatings allows Functionality Misuse.This issue affects WP-PostRatings: from n/a through 1.91.
- CVE-2023-40673MEDIUMCVSS 6.5EG 6.52024-06-04
: Improper Control of Interaction Frequency vulnerability in cartpauj Cartpauj Register Captcha allows Functionality Misuse.This issue affects Cartpauj Register Captcha: from n/a through 1.0.02.
- CVE-2023-51544MEDIUMCVSS 5.3EG 5.32024-06-04
Improper Control of Interaction Frequency vulnerability in Metagauss RegistrationMagic allows Functionality Misuse.This issue affects RegistrationMagic: from n/a through 5.2.5.0.
- CVE-2024-0094MEDIUMCVSS 5.5EG 5.52024-06-13
NVIDIA vGPU software for Linux contains a vulnerability in the Virtual GPU Manager, where an untrusted guest VM can cause improper control of the interaction frequency in the host. A successful exploit of this vulnerability might lead to d…
- CVE-2024-11126LOWCVSS 3.1EG 3.12024-11-12
A vulnerability was found in Digistar AG-30 Plus 2.6b. It has been classified as problematic. Affected is an unknown function of the component Login Page. The manipulation leads to improper restriction of excessive authentication attempts.…
- CVE-2024-13274MEDIUMCVSS 5.3EG 5.32025-01-09
Improper Control of Interaction Frequency vulnerability in Drupal Open Social allows Functionality Misuse.This issue affects Open Social: from 0.0.0 before 12.3.8, from 12.4.0 before 12.4.5.
- CVE-2024-24873MEDIUMCVSS 5.3EG 5.32024-05-17
: Improper Control of Interaction Frequency vulnerability in CodePeople CP Polls allows Flooding.This issue affects CP Polls: from n/a through 1.0.71.
- CVE-2024-32943HIGHCVSS 7.5EG 7.52024-06-20
An attacker may be able to cause a denial-of-service condition by sending many SSH packets repeatedly.
- CVE-2024-34695MEDIUMCVSS 6.3EG 6.32024-05-14
WOWS Karma is a reputation system for Wargaming's World of Warships. A user is able to click multiple times on "create" on a post creation prompt before the modal closes, which triggers sending several post creation API requests at once. D…
- CVE-2024-35246HIGHCVSS 7.5EG 7.52024-06-20
An attacker may be able to cause a denial-of-service condition by sending many packets repeatedly.
- CVE-2024-45788HIGHCVSS 7.5EG 7.52024-09-11
This vulnerability exists in Reedos aiM-Star version 2.0.1 due to missing rate limiting on OTP requests in certain API endpoints. An authenticated remote attacker could exploit this vulnerability by sending multiple OTP request through vul…
- CVE-2024-47065MEDIUMCVSS 6.5EG 6.52025-07-11
Meshtastic is an open source mesh networking solution. Prior to 2.5.1, traceroute responses from the remote node are not rate limited. Given that there are SNR measurements attributed to each received transmission, this is a guaranteed way…
- CVE-2024-47654HIGHCVSS 7.5EG 7.52024-10-04
This vulnerability exists in Shilpi Client Dashboard due to lack of rate limiting and Captcha protection for OTP requests in certain API endpoint. An unauthenticated remote attacker could exploit this vulnerability by sending multiple OTP …
- CVE-2024-48942MEDIUMCVSS 5.9EG 5.92024-10-10
The Syracom Secure Login (2FA) plugin for Jira, Confluence, and Bitbucket through 3.1.4.5 allows remote attackers to easily brute-force the 2FA PIN via the plugins/servlet/twofactor/public/pinvalidation endpoint. The last 30 and the next 3…
- CVE-2024-51557MEDIUMCVSS 6.5EG 6.52024-11-04
This vulnerability exists in the Wave 2.0 due to missing rate limiting on OTP requests in an API endpoint. An authenticated remote attacker could exploit this vulnerability by sending multiple OTP request through vulnerable API endpoint wh…
- CVE-2024-57603MEDIUMCVSS 6.3EG 6.32025-02-12
An issue in MaysWind ezBookkeeping 0.7.0 allows a remote attacker to escalate privileges via the lack of rate limiting.
- CVE-2024-6890HIGHCVSS 8.8EG 9.82024-08-07
Password reset tokens are generated using an insecure source of randomness. Attackers who know the username of the Journyx installation user can bruteforce the password reset and change the administrator password.
- CVE-2024-8475MEDIUMCVSS 6.5EG 6.52024-12-17
Authentication Bypass by Assumed-Immutable Data vulnerability in Digital Operation Services WiFiBurada allows Manipulating User-Controlled Variables. This issue affects WiFiBurada: before 1.0.5.
- CVE-2024-9199MEDIUMCVSS 5.8EG 5.82024-09-26
Rate limit vulnerability in Clibo Manager v1.1.9.2 that could allow an attacker to send a large number of emails to the victim in a short time, affecting availability and leading to a denial of service (DoS).
- CVE-2025-10761LOWCVSS 3.7EG 3.72025-09-21
A vulnerability has been found in Harness 3.3.0. Affected is an unknown function of the file /api/v1/login of the component Login Endpoint. The manipulation leads to improper restriction of excessive authentication attempts. Remote exploit…
- CVE-2025-11441LOWCVSS 3.7EG 3.72025-10-08
A vulnerability was identified in JhumanJ OpnForm up to 1.9.3. The affected element is an unknown function of the component HTTP Header Handler. The manipulation of the argument X-Forwarded-For leads to improper restriction of excessive au…
- CVE-2025-12310MEDIUMCVSS 5.3EG 5.32025-10-27
A security vulnerability has been detected in VirtFusion up to 6.0.2. This vulnerability affects unknown code of the file /account/_settings of the component Email Change Handler. The manipulation leads to improper restriction of excessive…
- CVE-2025-12547LOWCVSS 3.7EG 3.72025-10-31
A vulnerability was identified in LogicalDOC Community Edition up to 9.2.1. This vulnerability affects unknown code of the file /login.jsp of the component Admin Login Page. Such manipulation leads to improper restriction of excessive auth…
- CVE-2025-13211MEDIUMCVSS 5.3EG 5.32025-12-11
IBM Aspera Orchestrator 4.0.0 through 4.1.0 could allow an authenticated user to cause a denial of service in the email service due to improper control of interaction frequency.
- CVE-2025-1629LOWCVSS 3.5EG 3.52025-02-24
A vulnerability was found in Excitel Broadband Private my Excitel App 3.13.0 on Android. It has been classified as problematic. Affected is an unknown function of the component One-Time Password Handler. The manipulation leads to improper …
- CVE-2025-26524MEDIUMCVSS 5.1EG 0.02025-02-14
This vulnerability exists in RupeeWeb trading platform due to missing rate limiting on OTP requests in certain API endpoints. An authenticated remote attacker could exploit this vulnerability by sending multiple OTP request through vulnera…
- CVE-2025-29998HIGHCVSS 8.2EG 0.02025-03-13
This vulnerability exists in the CAP back office application due to missing rate limiting on OTP requests in an API endpoint. An authenticated remote attacker could exploit this vulnerability by sending multiple OTP request through vulnera…
- CVE-2025-32378MEDIUMCVSS 5.3EG 5.32025-04-09
Shopware is an open source e-commerce software platform. Prior to 6.6.10.3 or 6.5.8.17, the default settings for double-opt-in allow for mass unsolicited newsletter sign-ups without confirmation. Default settings are Newsletter: Double Opt…
- CVE-2025-3555LOWCVSS 3.7EG 3.72025-04-14
A vulnerability classified as problematic has been found in ScriptAndTools eCommerce-website-in-PHP 3.0. Affected is an unknown function of the file /login.php. The manipulation leads to improper restriction of excessive authentication att…
- CVE-2025-3556LOWCVSS 3.7EG 3.72025-04-14
A vulnerability classified as problematic was found in ScriptAndTools eCommerce-website-in-PHP 3.0. Affected by this vulnerability is an unknown functionality of the file /admin/login.php. The manipulation leads to improper restriction of …
- CVE-2025-48016MEDIUMCVSS 4.3EG 4.32025-05-20
OpenFlow discovery protocol can exhaust resources because it is not rate limited
- CVE-2025-52570LOWCVSS 1.7EG 0.02025-06-24
Letmein is an authenticating port knocker. Prior to version 10.2.1, The connection limiter is implemented incorrectly. It allows an arbitrary amount of simultaneously incoming connections (TCP, UDP and Unix socket) for the services letmein…
- CVE-2025-52880MEDIUMCVSS 4.2EG 4.22025-06-24
Komga is a media server for comics, mangas, BDs, magazines and eBooks. A Cross-Site Scripting (XSS) vulnerability has been discovered in versions 1.8.0 through 1.21.3 when serving EPUB resources, either directly from the API, or when readi…
- CVE-2025-54321CRITICALCVSS 9.8EG 9.82025-11-18
In Ascertia SigningHub through 8.6.8, there is a lack of rate limiting on the reset password function, leading to an email bombing vulnerability. An authenticated attacker can exploit this by automating reset password requests.
- CVE-2025-57816HIGHCVSS 7.5EG 7.52025-09-08
Fides is an open-source privacy engineering platform. Prior to version 2.69.1, the Fides Webserver API's built-in IP-based rate limiting is ineffective in environments with CDNs, proxies or load balancers. The system incorrectly applies ra…
- CVE-2025-5864LOWCVSS 3.7EG 3.72025-06-09
A vulnerability was found in Tenda TDSEE App up to 1.7.12. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /app/ConfirmSmsCode of the component Password Reset Confirmation Code Ha…
- CVE-2025-7882LOWCVSS 3.1EG 3.12025-07-20
A vulnerability was found in Mercusys MW301R 1.0.2 Build 190726 Rel.59423n. It has been rated as problematic. This issue affects some unknown processing of the component Login. The manipulation leads to improper restriction of excessive au…
Map vulnerabilities like CWE-799 to your infrastructure
EchelonGraph correlates every CVE — across CWE-799 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →