Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
brute force vulnerabilities and exploits
(subscribe to this query)
9.8
CVSSv3
CVE-2019-5421
Plataformatec Devise version 4.5.0 and previous versions, using the lockable module contains a CWE-367 vulnerability in The `Devise::Models::Lockable` class, more specifically at the `#increment_failed_attempts` method. File location: lib/devise/models/lockable.rb that can result...
Plataformatec Devise
5.3
CVSSv3
CVE-2022-31118
Nextcloud server is an open source personal cloud solution. In affected versions an attacker could brute force to find if federated sharing is being used and potentially try to brute force access tokens for federated shares (`a-zA-Z0-9` ^ 15). It is recommended that the Nextcloud...
Nextcloud Nextcloud Server
9.8
CVSSv3
CVE-2018-11082
Cloud Foundry UAA, all versions before 4.20.0 and Cloud Foundry UAA Release, all versions before 61.0, allows brute forcing of MFA codes. A remote unauthenticated malicious user in possession of a valid username and password can brute force MFA to login as the targeted user.
Pivotal Software Cloudfoundry Uaa Release
Pivotal Software Cloudfoundry Uaa
5.5
CVSSv3
CVE-2022-48067
An information disclosure vulnerability in Totolink A830R V4.1.2cu.5182 allows malicious users to obtain the root password via a brute-force attack.
Totolink A830r Firmware 4.1.2cu.5182
7.5
CVSSv3
CVE-2023-23755
An issue exists in Joomla! 4.2.0 up to and including 4.3.1. The lack of rate limiting allowed brute force attacks against MFA methods.
Joomla Joomla\\!
9.8
CVSSv3
CVE-2023-27152
DECISO OPNsense 23.1 does not impose rate limits for authentication, allowing malicious users to perform a brute-force attack to bypass authentication.
Opnsense Opnsense 23.1
5.3
CVSSv3
CVE-2023-47102
UrBackup Server 2.5.31 allows brute-force enumeration of user accounts because a failure message confirms that a username is not valid.
Urbackup Urbackup Server 2.5.31
8.8
CVSSv3
CVE-2016-3650
Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allows remote authenticated users to discover credentials via a brute-force attack.
Symantec Endpoint Protection Manager
7.5
CVSSv3
CVE-2023-35697
Improper Restriction of Excessive Authentication Attempts in the SICK ICR890-4 could allow a remote malicious user to brute-force user credentials.
Sick Icr890-4 Firmware
9.8
CVSSv3
CVE-2022-2321
Improper Restriction of Excessive Authentication Attempts in GitHub repository heroiclabs/nakama before 3.13.0. This results in login brute-force attacks.
Heroiclabs Nakama
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
blind SQL injection
CVE-2006-4304
CVE-2023-26603
CVE-2024-28327
CVE-2023-50363
CVE-2024-21905
template injection
CVE-2024-3400
cross-site request forgery
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
5
6
7
8
9
10
NEXT »