Fallos del tipo CWE-307

411 resultados
CVE-2024-48143CRITICALA lack of rate limiting in the OTP validation component of Digitory Multi Channel Integrated POS v1.0 allows attackers to gain access to theEPSS 0.4%CVE-2025-6004MEDIUMVault Userpass and LDAP User Lockout BypassEPSS 0.4%CVE-2025-69246MEDIUMLack of bruteforce protection in Raytha CMSEPSS 0.4%CVE-2023-48276MEDIUMWordPress WP Forms Puzzle Captcha plugin <= 4.1 - Captcha Bypass vulnerabilityEPSS 0.4%CVE-2024-8429MEDIUMImproper Authentication in Digital Operation Services' WiFiBuradaEPSS 0.4%CVE-2025-53968HIGHEVMAPA Improper Restriction of Excessive Authentication AttemptsEPSS 0.4%CVE-2024-5682MEDIUMUser Enumeration in Yordam Information Technology's Yordam Library Automation SystemEPSS 0.4%CVE-2023-48290MEDIUMWordPress Form Maker by 10Web plugin <= 1.15.20 - Captcha Bypass Vulnerability vulnerabilityEPSS 0.4%CVE-2023-23730MEDIUMWordPress Spectra – WordPress Gutenberg Blocks plugin <= 2.3.0 - Captcha Bypass VulnerabilityEPSS 0.4%CVE-2024-35747MEDIUMWordPress Contact Form Builder, Contact Widget plugin <= 2.1.7 - Bypass Vulnerability vulnerabilityEPSS 0.4%CVE-2025-42600HIGHBrute Force Attack Vulnerability in Meon KYC solutionsEPSS 0.4%CVE-2026-30959MEDIUMOneUptime has WhatsApp Resend Verification Authorization BypassEPSS 0.4%CVE-2026-22629LOWAn improper restriction of excessive authentication attempts vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4 EPSS 0.4%CVE-2025-4319CRITICALImproper Access Control in Birebirsoft's SufirmamEPSS 0.4%CVE-2025-46606MEDIUMDell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 contain an improper restEPSS 0.4%CVE-2025-62257MEDIUMPassword enumeration vulnerability in Liferay Portal 7.4.0 through 7.4.3.119, and older unsupported versions, and Liferay DXP 2024.Q1.1 throEPSS 0.4%CVE-2026-36959HIGHU-SPEED N300 router V1.0.0 does not implement rate limiting or account lockout protections on the /api/login endpoint. This allows an attackEPSS 0.4%CVE-2026-22278HIGHDell PowerScale OneFS versions prior to 9.13.0.0 contains an improper restriction of excessive authentication attempts vulnerability. An unaEPSS 0.4%CVE-2025-48014HIGHImproper Restriction of Excessive Authentication AttemptsEPSS 0.4%CVE-2026-33580MEDIUMOpenClaw < 2026.3.28 - Brute Force Attack via Missing Rate Limiting on Webhook Shared Secret AuthenticationEPSS 0.4%