Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
brute force vulnerabilities and exploits
(subscribe to this query)
9.8
CVSSv3
CVE-2019-5421
Plataformatec Devise version 4.5.0 and previous versions, using the lockable module contains a CWE-367 vulnerability in The `Devise::Models::Lockable` class, more specifically at the `#increment_failed_attempts` method. File location: lib/devise/models/lockable.rb that can result...
Plataformatec Devise
9.8
CVSSv3
CVE-2018-11082
Cloud Foundry UAA, all versions before 4.20.0 and Cloud Foundry UAA Release, all versions before 61.0, allows brute forcing of MFA codes. A remote unauthenticated malicious user in possession of a valid username and password can brute force MFA to login as the targeted user.
Pivotal Software Cloudfoundry Uaa Release
Pivotal Software Cloudfoundry Uaa
9.8
CVSSv3
CVE-2022-34615
Mealie 1.0.0beta3 employs weak password requirements which allows malicious users to potentially gain unauthorized access to the application via brute-force attacks.
Mealie Mealie 0.5.5
Mealie Mealie 1.0.0
8.8
CVSSv3
CVE-2016-3650
Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allows remote authenticated users to discover credentials via a brute-force attack.
Symantec Endpoint Protection Manager
5.3
CVSSv3
CVE-2023-47102
UrBackup Server 2.5.31 allows brute-force enumeration of user accounts because a failure message confirms that a username is not valid.
Urbackup Urbackup Server 2.5.31
7.5
CVSSv3
CVE-2023-35697
Improper Restriction of Excessive Authentication Attempts in the SICK ICR890-4 could allow a remote malicious user to brute-force user credentials.
Sick Icr890-4 Firmware
5.5
CVSSv3
CVE-2022-48067
An information disclosure vulnerability in Totolink A830R V4.1.2cu.5182 allows malicious users to obtain the root password via a brute-force attack.
Totolink A830r Firmware 4.1.2cu.5182
9.8
CVSSv3
CVE-2022-2321
Improper Restriction of Excessive Authentication Attempts in GitHub repository heroiclabs/nakama before 3.13.0. This results in login brute-force attacks.
Heroiclabs Nakama
9.8
CVSSv3
CVE-2018-12993
onefilecms.php in OneFileCMS through 2012-04-14 might allow malicious users to conduct brute-force attacks via the onefilecms_username and onefilecms_password fields.
Onefilecms Onefilecms
7.5
CVSSv3
CVE-2023-23755
An issue exists in Joomla! 4.2.0 up to and including 4.3.1. The lack of rate limiting allowed brute force attacks against MFA methods.
Joomla Joomla\\!
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-3012
CVE-2024-30200
XXE
CVE-2023-24955
CVE-2023-42931
CVE-2024-29231
remote code execution
cross-site scripting
CVE-2024-0677
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
5
6
7
8
9
10
NEXT »