VYPR

CWE-799

Improper Control of Interaction Frequency

ClassIncomplete

Description

The product does not properly limit the number or frequency of interactions that it has with an actor, such as the number of incoming requests.

This can allow the actor to perform actions more frequently than expected. The actor could be a human or an automated process such as a virus or bot. This could be used to cause a denial of service, compromise program logic (such as limiting humans to a single vote), or other consequences. For example, an authentication routine might not limit the number of times an attacker can guess a password. Or, a web site might conduct a poll but only expect humans to vote a maximum of once a day.

Hierarchy (View 1000)

Parents

CVEs mapped to this weakness (74)

page 1 of 4
  • CVE-2025-54321CriNov 18, 2025
    risk 0.64cvss 9.8epss 0.00

    In Ascertia SigningHub through 8.6.8, there is a lack of rate limiting on the reset password function, leading to an email bombing vulnerability. An authenticated attacker can exploit this by automating reset password requests.

  • CVE-2024-6890HigAug 7, 2024
    risk 0.57cvss 8.8epss 0.01

    Password reset tokens are generated using an insecure source of randomness. Attackers who know the username of the Journyx installation user can bruteforce the password reset and change the administrator password.

  • CVE-2026-7402HigApr 30, 2026
    risk 0.53cvss 8.1epss 0.00

    Improper Control of Interaction Frequency vulnerability in MeWare Software Development Inc. PDKS allows Flooding. This issue affects PDKS: from V16.20200313 before VMYR_3.5.2025117.

  • CVE-2026-24017HigMar 10, 2026
    risk 0.53cvss 8.1epss 0.01

    An Improper Control of Interaction Frequency vulnerability [CWE-799] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4.0 through 7.4.10, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow a remote…

  • CVE-2025-29998HigMar 13, 2025
    risk 0.53cvss epss 0.00

    This vulnerability exists in the CAP back office application due to missing rate limiting on OTP requests in an API endpoint. An authenticated remote attacker could exploit this vulnerability by sending multiple OTP request through vulnerable API endpoint which could lead to the…

  • CVE-2024-47654HigOct 4, 2024
    risk 0.49cvss 7.5epss 0.00

    This vulnerability exists in Shilpi Client Dashboard due to lack of rate limiting and Captcha protection for OTP requests in certain API endpoint. An unauthenticated remote attacker could exploit this vulnerability by sending multiple OTP request through vulnerable API…

  • CVE-2024-45788HigSep 11, 2024
    risk 0.49cvss 7.5epss 0.01

    This vulnerability exists in Reedos aiM-Star version 2.0.1 due to missing rate limiting on OTP requests in certain API endpoints. An authenticated remote attacker could exploit this vulnerability by sending multiple OTP request through vulnerable API endpoints which could lead…

  • CVE-2024-35246HigJun 20, 2024
    risk 0.49cvss 7.5epss 0.00

    An attacker may be able to cause a denial-of-service condition by sending many packets repeatedly.

  • CVE-2024-32943HigJun 20, 2024
    risk 0.49cvss 7.5epss 0.00

    An attacker may be able to cause a denial-of-service condition by sending many SSH packets repeatedly.

  • CVE-2023-35621HigDec 12, 2023
    risk 0.49cvss 7.5epss 0.02

    Microsoft Dynamics 365 Finance and Operations Denial of Service Vulnerability

  • CVE-2021-33563HigMay 24, 2021
    risk 0.49cvss 7.5epss 0.01

    Koel before 5.1.4 lacks login throttling, lacks a password strength policy, and shows whether a failed login attempt had a valid username. This might make brute-force attacks easier.

  • CVE-2026-5233HigJun 15, 2026
    risk 0.46cvss 7.1epss 0.00

    Improper Control of Interaction Frequency vulnerability in MIA Technology Inc. Pizzy Library allows Flooding. This issue affects Pizzy Library: from 1.0.0.26250 before 1.3.9.26250.

  • CVE-2026-32729HigMar 16, 2026
    risk 0.46cvss 8.1epss 0.00

    Runtipi is a personal homeserver orchestrator. Prior to 4.8.1, The Runtipi /api/auth/verify-totp endpoint does not enforce any rate limiting, attempt counting, or account lockout mechanism. An attacker who has obtained a user's valid credentials (via phishing, credential…

  • CVE-2026-22216MedMar 13, 2026
    risk 0.42cvss 6.5epss 0.00

    wpDiscuz before 7.6.47 contains a missing rate limiting vulnerability that allows unauthenticated attackers to subscribe arbitrary email addresses to post notifications by sending POST requests to the wpdAddSubscription handler in class.WpdiscuzHelperAjax.php. Attackers can…

  • CVE-2026-30972HigMar 10, 2026
    risk 0.42cvss 7.5epss 0.00

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior o 9.5.2-alpha.10 and 8.6.23, Parse Server's rate limiting middleware is applied at the Express middleware layer, but the batch request endpoint (/batch) processes…

  • CVE-2025-57816HigSep 8, 2025
    risk 0.42cvss 7.5epss 0.00

    Fides is an open-source privacy engineering platform. Prior to version 2.69.1, the Fides Webserver API's built-in IP-based rate limiting is ineffective in environments with CDNs, proxies or load balancers. The system incorrectly applies rate limits based on directly connected…

  • CVE-2024-47065MedJul 11, 2025
    risk 0.42cvss 6.5epss 0.00

    Meshtastic is an open source mesh networking solution. Prior to 2.5.1, traceroute responses from the remote node are not rate limited. Given that there are SNR measurements attributed to each received transmission, this is a guaranteed way to get a remote station to reliably and…

  • CVE-2024-8475MedDec 17, 2024
    risk 0.42cvss 6.5epss 0.00

    Authentication Bypass by Assumed-Immutable Data vulnerability in Digital Operation Services WiFiBurada allows Manipulating User-Controlled Variables. This issue affects WiFiBurada: before 1.0.5.

  • CVE-2024-51557MedNov 4, 2024
    risk 0.42cvss 6.5epss 0.00

    This vulnerability exists in the Wave 2.0 due to missing rate limiting on OTP requests in an API endpoint. An authenticated remote attacker could exploit this vulnerability by sending multiple OTP request through vulnerable API endpoint which could lead to the OTP…

  • CVE-2023-40673MedJun 4, 2024
    risk 0.42cvss 6.5epss 0.00

    : Improper Control of Interaction Frequency vulnerability in cartpauj Cartpauj Register Captcha allows Functionality Misuse.This issue affects Cartpauj Register Captcha: from n/a through 1.0.02.