CVE-2022-37144High· 8.8▾ TwilightThe PlexTrac platform prior to API version 1.17.0 does not restrict excessive MFA TOTP submission attempts. An unauthenticated remote attacker in possession of a valid username and password can bruteforce their way past MFA protections t…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 48.4 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 6.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.8%
0.8% → 0.9%
The PlexTrac platform prior to API version 1.17.0 does not restrict excessive MFA TOTP submission attempts. An unauthenticated remote attacker in possession of a valid username and password can bruteforce their way past MFA protections to login as the targeted user.
plextrac < 1.17.0Upgrade past the affected range:
plextrac 1.17.0Connected by shared product, vendor, weakness, or advisory.
CVE-2022-37145High· 7.5The PlexTrac platform prior to version 1.17.0 does not restrict excessive authentication attempts for accounts configured to use the PlexTrac authentication provider
CVE-2022-37146Medium· 5.3The PlexTrac platform prior to version 1.28.0 allows for username enumeration via HTTP response times on invalid login attempts for users configured to use the PlexTrac authentication provider
CVE-2026-85734Critical· 9.1LightRAG provides simple and fast retrieval-augmented generation
CVE-2026-56682Medium· 5.39Router is an AI router & token saver
CVE-2026-46649Critical· 9.1Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks
CVE-2026-58271Medium· 6.8Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing