plextrac has 3 CVEs on record. The median CVSS is 7.5 (high).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.5
- Publish → KEV
- —
- Last 90 days
- 0 prev 0
Worst active — by depth score
CVE-2022-37144High· 8.8The PlexTrac platform prior to API version 1.17.0 does not restrict excessive MFA TOTP submission attempts49CVE-2022-37145High· 7.5The PlexTrac platform prior to version 1.17.0 does not restrict excessive authentication attempts for accounts configured to use the PlexTrac authentication provider41CVE-2022-37146Medium· 5.3The PlexTrac platform prior to version 1.28.0 allows for username enumeration via HTTP response times on invalid login attempts for users configured to use the PlexTrac authentication provider29
plextrac vulnerabilities
CVEs affecting plextrac, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
CVE-2022-37146Medium· 5.3The PlexTrac platform prior to version 1.28.0 allows for username enumeration via HTTP response times on invalid login attempts for users configured to use the PlexTrac authentication provider
The PlexTrac platform prior to version 1.28.0 allows for username enumeration via HTTP response times on invalid login attempts for users configured to use the PlexTrac authentication provider. Login attempts for valid, unlocked users co…
CVE-2022-37145High· 7.5The PlexTrac platform prior to version 1.17.0 does not restrict excessive authentication attempts for accounts configured to use the PlexTrac authentication provider
The PlexTrac platform prior to version 1.17.0 does not restrict excessive authentication attempts for accounts configured to use the PlexTrac authentication provider. An unauthenticated remote attacker could perform a bruteforce attack o…
CVE-2022-37144High· 8.8The PlexTrac platform prior to API version 1.17.0 does not restrict excessive MFA TOTP submission attempts
The PlexTrac platform prior to API version 1.17.0 does not restrict excessive MFA TOTP submission attempts. An unauthenticated remote attacker in possession of a valid username and password can bruteforce their way past MFA protections t…