CWE-799
Improper Control of Interaction Frequency
Description
The product does not properly limit the number or frequency of interactions that it has with an actor, such as the number of incoming requests.
Hierarchy (View 1000)
CVEs mapped to this weakness (74)
page 1 of 4| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-54321 | Cri | 0.64 | 9.8 | 0.00 | Nov 18, 2025 | In Ascertia SigningHub through 8.6.8, there is a lack of rate limiting on the reset password function, leading to an email bombing vulnerability. An authenticated attacker can exploit this by automating reset password requests. | ||
| CVE-2024-6890 | Hig | 0.57 | 8.8 | 0.01 | Aug 7, 2024 | Password reset tokens are generated using an insecure source of randomness. Attackers who know the username of the Journyx installation user can bruteforce the password reset and change the administrator password. | ||
| CVE-2026-7402 | Hig | 0.53 | 8.1 | 0.00 | Apr 30, 2026 | Improper Control of Interaction Frequency vulnerability in MeWare Software Development Inc. PDKS allows Flooding. This issue affects PDKS: from V16.20200313 before VMYR_3.5.2025117. | ||
| CVE-2026-24017 | Hig | 0.53 | 8.1 | 0.01 | Mar 10, 2026 | An Improper Control of Interaction Frequency vulnerability [CWE-799] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4.0 through 7.4.10, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow a remote… | ||
| CVE-2025-29998 | Hig | 0.53 | — | 0.00 | Mar 13, 2025 | This vulnerability exists in the CAP back office application due to missing rate limiting on OTP requests in an API endpoint. An authenticated remote attacker could exploit this vulnerability by sending multiple OTP request through vulnerable API endpoint which could lead to the… | ||
| CVE-2024-47654 | Hig | 0.49 | 7.5 | 0.00 | Oct 4, 2024 | This vulnerability exists in Shilpi Client Dashboard due to lack of rate limiting and Captcha protection for OTP requests in certain API endpoint. An unauthenticated remote attacker could exploit this vulnerability by sending multiple OTP request through vulnerable API… | ||
| CVE-2024-45788 | Hig | 0.49 | 7.5 | 0.01 | Sep 11, 2024 | This vulnerability exists in Reedos aiM-Star version 2.0.1 due to missing rate limiting on OTP requests in certain API endpoints. An authenticated remote attacker could exploit this vulnerability by sending multiple OTP request through vulnerable API endpoints which could lead… | ||
| CVE-2024-35246 | Hig | 0.49 | 7.5 | 0.00 | Jun 20, 2024 | An attacker may be able to cause a denial-of-service condition by sending many packets repeatedly. | ||
| CVE-2024-32943 | Hig | 0.49 | 7.5 | 0.00 | Jun 20, 2024 | An attacker may be able to cause a denial-of-service condition by sending many SSH packets repeatedly. | ||
| CVE-2023-35621 | Hig | 0.49 | 7.5 | 0.02 | Dec 12, 2023 | Microsoft Dynamics 365 Finance and Operations Denial of Service Vulnerability | ||
| CVE-2021-33563 | Hig | 0.49 | 7.5 | 0.01 | May 24, 2021 | Koel before 5.1.4 lacks login throttling, lacks a password strength policy, and shows whether a failed login attempt had a valid username. This might make brute-force attacks easier. | ||
| CVE-2026-5233 | Hig | 0.46 | 7.1 | 0.00 | Jun 15, 2026 | Improper Control of Interaction Frequency vulnerability in MIA Technology Inc. Pizzy Library allows Flooding. This issue affects Pizzy Library: from 1.0.0.26250 before 1.3.9.26250. | ||
| CVE-2026-32729 | Hig | 0.46 | 8.1 | 0.00 | Mar 16, 2026 | Runtipi is a personal homeserver orchestrator. Prior to 4.8.1, The Runtipi /api/auth/verify-totp endpoint does not enforce any rate limiting, attempt counting, or account lockout mechanism. An attacker who has obtained a user's valid credentials (via phishing, credential… | ||
| CVE-2026-22216 | Med | 0.42 | 6.5 | 0.00 | Mar 13, 2026 | wpDiscuz before 7.6.47 contains a missing rate limiting vulnerability that allows unauthenticated attackers to subscribe arbitrary email addresses to post notifications by sending POST requests to the wpdAddSubscription handler in class.WpdiscuzHelperAjax.php. Attackers can… | ||
| CVE-2026-30972 | Hig | 0.42 | 7.5 | 0.00 | Mar 10, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior o 9.5.2-alpha.10 and 8.6.23, Parse Server's rate limiting middleware is applied at the Express middleware layer, but the batch request endpoint (/batch) processes… | ||
| CVE-2025-57816 | Hig | 0.42 | 7.5 | 0.00 | Sep 8, 2025 | Fides is an open-source privacy engineering platform. Prior to version 2.69.1, the Fides Webserver API's built-in IP-based rate limiting is ineffective in environments with CDNs, proxies or load balancers. The system incorrectly applies rate limits based on directly connected… | ||
| CVE-2024-47065 | Med | 0.42 | 6.5 | 0.00 | Jul 11, 2025 | Meshtastic is an open source mesh networking solution. Prior to 2.5.1, traceroute responses from the remote node are not rate limited. Given that there are SNR measurements attributed to each received transmission, this is a guaranteed way to get a remote station to reliably and… | ||
| CVE-2024-8475 | Med | 0.42 | 6.5 | 0.00 | Dec 17, 2024 | Authentication Bypass by Assumed-Immutable Data vulnerability in Digital Operation Services WiFiBurada allows Manipulating User-Controlled Variables. This issue affects WiFiBurada: before 1.0.5. | ||
| CVE-2024-51557 | Med | 0.42 | 6.5 | 0.00 | Nov 4, 2024 | This vulnerability exists in the Wave 2.0 due to missing rate limiting on OTP requests in an API endpoint. An authenticated remote attacker could exploit this vulnerability by sending multiple OTP request through vulnerable API endpoint which could lead to the OTP… | ||
| CVE-2023-40673 | Med | 0.42 | 6.5 | 0.00 | Jun 4, 2024 | : Improper Control of Interaction Frequency vulnerability in cartpauj Cartpauj Register Captcha allows Functionality Misuse.This issue affects Cartpauj Register Captcha: from n/a through 1.0.02. |
- risk 0.64cvss 9.8epss 0.00
In Ascertia SigningHub through 8.6.8, there is a lack of rate limiting on the reset password function, leading to an email bombing vulnerability. An authenticated attacker can exploit this by automating reset password requests.
- risk 0.57cvss 8.8epss 0.01
Password reset tokens are generated using an insecure source of randomness. Attackers who know the username of the Journyx installation user can bruteforce the password reset and change the administrator password.
- risk 0.53cvss 8.1epss 0.00
Improper Control of Interaction Frequency vulnerability in MeWare Software Development Inc. PDKS allows Flooding. This issue affects PDKS: from V16.20200313 before VMYR_3.5.2025117.
- risk 0.53cvss 8.1epss 0.01
An Improper Control of Interaction Frequency vulnerability [CWE-799] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4.0 through 7.4.10, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow a remote…
- risk 0.53cvss —epss 0.00
This vulnerability exists in the CAP back office application due to missing rate limiting on OTP requests in an API endpoint. An authenticated remote attacker could exploit this vulnerability by sending multiple OTP request through vulnerable API endpoint which could lead to the…
- risk 0.49cvss 7.5epss 0.00
This vulnerability exists in Shilpi Client Dashboard due to lack of rate limiting and Captcha protection for OTP requests in certain API endpoint. An unauthenticated remote attacker could exploit this vulnerability by sending multiple OTP request through vulnerable API…
- risk 0.49cvss 7.5epss 0.01
This vulnerability exists in Reedos aiM-Star version 2.0.1 due to missing rate limiting on OTP requests in certain API endpoints. An authenticated remote attacker could exploit this vulnerability by sending multiple OTP request through vulnerable API endpoints which could lead…
- risk 0.49cvss 7.5epss 0.00
An attacker may be able to cause a denial-of-service condition by sending many packets repeatedly.
- risk 0.49cvss 7.5epss 0.00
An attacker may be able to cause a denial-of-service condition by sending many SSH packets repeatedly.
- risk 0.49cvss 7.5epss 0.02
Microsoft Dynamics 365 Finance and Operations Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.01
Koel before 5.1.4 lacks login throttling, lacks a password strength policy, and shows whether a failed login attempt had a valid username. This might make brute-force attacks easier.
- risk 0.46cvss 7.1epss 0.00
Improper Control of Interaction Frequency vulnerability in MIA Technology Inc. Pizzy Library allows Flooding. This issue affects Pizzy Library: from 1.0.0.26250 before 1.3.9.26250.
- risk 0.46cvss 8.1epss 0.00
Runtipi is a personal homeserver orchestrator. Prior to 4.8.1, The Runtipi /api/auth/verify-totp endpoint does not enforce any rate limiting, attempt counting, or account lockout mechanism. An attacker who has obtained a user's valid credentials (via phishing, credential…
- risk 0.42cvss 6.5epss 0.00
wpDiscuz before 7.6.47 contains a missing rate limiting vulnerability that allows unauthenticated attackers to subscribe arbitrary email addresses to post notifications by sending POST requests to the wpdAddSubscription handler in class.WpdiscuzHelperAjax.php. Attackers can…
- risk 0.42cvss 7.5epss 0.00
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior o 9.5.2-alpha.10 and 8.6.23, Parse Server's rate limiting middleware is applied at the Express middleware layer, but the batch request endpoint (/batch) processes…
- risk 0.42cvss 7.5epss 0.00
Fides is an open-source privacy engineering platform. Prior to version 2.69.1, the Fides Webserver API's built-in IP-based rate limiting is ineffective in environments with CDNs, proxies or load balancers. The system incorrectly applies rate limits based on directly connected…
- risk 0.42cvss 6.5epss 0.00
Meshtastic is an open source mesh networking solution. Prior to 2.5.1, traceroute responses from the remote node are not rate limited. Given that there are SNR measurements attributed to each received transmission, this is a guaranteed way to get a remote station to reliably and…
- risk 0.42cvss 6.5epss 0.00
Authentication Bypass by Assumed-Immutable Data vulnerability in Digital Operation Services WiFiBurada allows Manipulating User-Controlled Variables. This issue affects WiFiBurada: before 1.0.5.
- risk 0.42cvss 6.5epss 0.00
This vulnerability exists in the Wave 2.0 due to missing rate limiting on OTP requests in an API endpoint. An authenticated remote attacker could exploit this vulnerability by sending multiple OTP request through vulnerable API endpoint which could lead to the OTP…
- risk 0.42cvss 6.5epss 0.00
: Improper Control of Interaction Frequency vulnerability in cartpauj Cartpauj Register Captcha allows Functionality Misuse.This issue affects Cartpauj Register Captcha: from n/a through 1.0.02.