CWE-307
CVEs classified under CWE-307, newest first.
63 CVEsRSS
CVE-2021-41435Critical· 9.8A brute-force protection bypass in CAPTCHA protection in ASUS ROG Rapture GT-AX11000, RT-AX3000, RT-AX55, RT-AX56U, RT-AX56U_V2, RT-AX58U, RT-AX82U, RT-AX82U GUNDAM EDITION, RT-AX86 Series(RT-AX86U/RT-AX86S), RT-AX86U ZAKU II EDITION, RT…
A brute-force protection bypass in CAPTCHA protection in ASUS ROG Rapture GT-AX11000, RT-AX3000, RT-AX55, RT-AX56U, RT-AX56U_V2, RT-AX58U, RT-AX82U, RT-AX82U GUNDAM EDITION, RT-AX86 Series(RT-AX86U/RT-AX86S), RT-AX86U ZAKU II EDITION, RT…
▾ Midnightasus · gt-ax11000_firmwareEPSS 6.5%via NVD
CVE-2021-29023Medium· 5.3InvoicePlane 1.5.11 doesn't have any rate-limiting for password reset and the reset token is generated using a weak mechanism that is predictable.
InvoicePlane 1.5.11 doesn't have any rate-limiting for password reset and the reset token is generated using a weak mechanism that is predictable.
▾ Sunlitinvoiceplane · invoiceplaneEPSS 1.2%via NVD
CVE-2018-12649Critical· 9.8An issue was discovered in app/Controller/UsersController.php in MISP 2.4.92
An issue was discovered in app/Controller/UsersController.php in MISP 2.4.92. An adversary can bypass the brute-force protection by using a PUT HTTP method instead of a POST HTTP method in the login part, because this protection was only…
▾ Midnightmisp-project · mispEPSS 1.5%via NVD