Vulnerabilities (CVE)

Filtered by CWE-799
Total 67 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-8475 2026-06-17 N/A 6.5 MEDIUM
Authentication Bypass by Assumed-Immutable Data vulnerability in Digital Operation Services WiFiBurada allows Manipulating User-Controlled Variables. This issue affects WiFiBurada: before 1.0.5.
CVE-2024-6890 1 Journyx 1 Journyx 2026-06-17 N/A 8.8 HIGH
Password reset tokens are generated using an insecure source of randomness. Attackers who know the username of the Journyx installation user can bruteforce the password reset and change the administrator password.
CVE-2024-57603 1 Mayswind 1 Ezbookkeeping 2026-06-17 N/A 6.3 MEDIUM
An issue in MaysWind ezBookkeeping 0.7.0 allows a remote attacker to escalate privileges via the lack of rate limiting.
CVE-2024-51557 1 63moons 2 Aero, Wave 2.0 2026-06-17 N/A 6.5 MEDIUM
This vulnerability exists in the Wave 2.0 due to missing rate limiting on OTP requests in an API endpoint. An authenticated remote attacker could exploit this vulnerability by sending multiple OTP request through vulnerable API endpoint which could lead to the OTP bombing/flooding on the targeted system.
CVE-2024-48942 1 Syracom 1 Secure Login 2026-06-17 N/A 5.9 MEDIUM
The Syracom Secure Login (2FA) plugin for Jira, Confluence, and Bitbucket through 3.1.4.5 allows remote attackers to easily brute-force the 2FA PIN via the plugins/servlet/twofactor/public/pinvalidation endpoint. The last 30 and the next 30 tokens are valid.
CVE-2024-47654 1 Shilpisoft 1 Client Dashboard 2026-06-17 N/A 7.5 HIGH
This vulnerability exists in Shilpi Client Dashboard due to lack of rate limiting and Captcha protection for OTP requests in certain API endpoint. An unauthenticated remote attacker could exploit this vulnerability by sending multiple OTP request through vulnerable API endpoints, which could lead to the OTP bombing on the targeted system.
CVE-2024-47065 1 Meshtastic 1 Meshtastic Firmware 2026-06-17 N/A 6.5 MEDIUM
Meshtastic is an open source mesh networking solution. Prior to 2.5.1, traceroute responses from the remote node are not rate limited. Given that there are SNR measurements attributed to each received transmission, this is a guaranteed way to get a remote station to reliably and continuously respond. You could easily get 100 samples in a short amount of time (estimated 2 minutes), whereas passively doing the same could take hours or days. There are secondary effects that non-ratelimited traceroute does also allow a 2:1 reflected DoS of the network as well, but these concerns are less than the problem with positional confidentiality (other DoS routes exist). This vulnerability is fixed in 2.5.1.
CVE-2024-45788 1 Reedos 1 Aim-star 2026-06-17 N/A 7.5 HIGH
This vulnerability exists in Reedos aiM-Star version 2.0.1 due to missing rate limiting on OTP requests in certain API endpoints. An authenticated remote attacker could exploit this vulnerability by sending multiple OTP request through vulnerable API endpoints which could lead to the OTP bombing/flooding on the targeted system.
CVE-2024-35246 1 Westermo 2 L210-f2g Lynx, L210-f2g Lynx Firmware 2026-06-17 N/A 7.5 HIGH
An attacker may be able to cause a denial-of-service condition by sending many packets repeatedly.
CVE-2024-34695 2026-06-17 N/A 6.3 MEDIUM
WOWS Karma is a reputation system for Wargaming's World of Warships. A user is able to click multiple times on "create" on a post creation prompt before the modal closes, which triggers sending several post creation API requests at once. Due to timing, sending multiple posts simultaneously requests bypasses the cooldown validation, however are not refreshing a user's metrics more than once, due to concurrent karma updates. This issue is fixed in 0.17.4.1.
CVE-2024-32943 1 Westermo 2 L210-f2g, L210-f2g Firmware 2026-06-17 N/A 7.5 HIGH
An attacker may be able to cause a denial-of-service condition by sending many SSH packets repeatedly.
CVE-2024-24873 2026-06-17 N/A 5.3 MEDIUM
: Improper Control of Interaction Frequency vulnerability in CodePeople CP Polls allows Flooding.This issue affects CP Polls: from n/a through 1.0.71.
CVE-2024-13274 1 Getopensocial 1 Open Social 2026-06-17 N/A 5.3 MEDIUM
Improper Control of Interaction Frequency vulnerability in Drupal Open Social allows Functionality Misuse.This issue affects Open Social: from 0.0.0 before 12.3.8, from 12.4.0 before 12.4.5.
CVE-2024-11126 2026-06-17 1.8 LOW 3.1 LOW
A vulnerability was found in Digistar AG-30 Plus 2.6b. It has been classified as problematic. Affected is an unknown function of the component Login Page. The manipulation leads to improper restriction of excessive authentication attempts. The complexity of an attack is rather high. The exploitability is told to be difficult. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2024-0094 2026-06-17 N/A 5.5 MEDIUM
NVIDIA vGPU software for Linux contains a vulnerability in the Virtual GPU Manager, where an untrusted guest VM can cause improper control of the interaction frequency in the host. A successful exploit of this vulnerability might lead to denial of service.
CVE-2023-51544 1 Metagauss 1 Registrationmagic 2026-06-17 N/A 5.3 MEDIUM
Improper Control of Interaction Frequency vulnerability in Metagauss RegistrationMagic allows Functionality Misuse.This issue affects RegistrationMagic: from n/a through 5.2.5.0.
CVE-2023-40673 2026-06-17 N/A 6.5 MEDIUM
: Improper Control of Interaction Frequency vulnerability in cartpauj Cartpauj Register Captcha allows Functionality Misuse.This issue affects Cartpauj Register Captcha: from n/a through 1.0.02.
CVE-2023-40332 1 Lesterchan 1 Wp-postratings 2026-06-17 N/A 5.3 MEDIUM
Improper Control of Interaction Frequency vulnerability in Lester ‘GaMerZ’ Chan WP-PostRatings allows Functionality Misuse.This issue affects WP-PostRatings: from n/a through 1.91.
CVE-2023-38068 1 Jetbrains 1 Youtrack 2026-06-17 N/A 6.5 MEDIUM
In JetBrains YouTrack before 2023.1.16597 captcha was not properly validated for Helpdesk forms
CVE-2023-35621 1 Microsoft 1 Dynamics 365 2026-06-17 N/A 7.5 HIGH
Microsoft Dynamics 365 Finance and Operations Denial of Service Vulnerability