VYPR

CWE-799

Improper Control of Interaction Frequency

ClassIncomplete

Description

The product does not properly limit the number or frequency of interactions that it has with an actor, such as the number of incoming requests.

This can allow the actor to perform actions more frequently than expected. The actor could be a human or an automated process such as a virus or bot. This could be used to cause a denial of service, compromise program logic (such as limiting humans to a single vote), or other consequences. For example, an authentication routine might not limit the number of times an attacker can guess a password. Or, a web site might conduct a poll but only expect humans to vote a maximum of once a day.

Hierarchy (View 1000)

Parents

CVEs mapped to this weakness (74)

page 2 of 4
  • CVE-2023-27279MedApr 19, 2024
    risk 0.42cvss 6.5epss 0.01

    IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a user to cause a denial of service due to missing API rate limiting. IBM X-Force ID: 248533.

  • CVE-2023-38068MedJul 12, 2023
    risk 0.42cvss 6.5epss 0.01

    In JetBrains YouTrack before 2023.1.16597 captcha was not properly validated for Helpdesk forms

  • CVE-2020-5141MedOct 12, 2020
    risk 0.42cvss 6.5epss 0.01

    A vulnerability in SonicOS allows a remote unauthenticated attacker to brute force Virtual Assist ticket ID in the firewall SSLVPN service. This vulnerability affected SonicOS Gen 5 version 5.9.1.7, 5.9.1.13, Gen 6 version 6.5.4.7, 6.5.1.12, 6.0.5.3, SonicOSv 6.5.4.v and Gen 7…

  • CVE-2016-11069HigJun 19, 2020
    risk 0.42cvss 7.5epss 0.01

    An issue was discovered in Mattermost Server before 3.2.0. It mishandles brute-force attempts at password change.

  • CVE-2024-57603MedFeb 12, 2025
    risk 0.41cvss 6.3epss 0.00

    An issue in MaysWind ezBookkeeping 0.7.0 allows a remote attacker to escalate privileges via the lack of rate limiting.

  • CVE-2016-6543MedJul 13, 2018
    risk 0.39cvss 5.9epss 0.02

    A captured MAC/device ID of an iTrack Easy can be registered under multiple user accounts allowing access to getgps GPS data, which can allow unauthenticated parties to track the device.

  • CVE-2024-48942MedOct 10, 2024
    risk 0.38cvss 5.9epss 0.00

    The Syracom Secure Login (2FA) plugin for Jira, Confluence, and Bitbucket through 3.1.4.5 allows remote attackers to easily brute-force the 2FA PIN via the plugins/servlet/twofactor/public/pinvalidation endpoint. The last 30 and the next 30 tokens are valid.

  • CVE-2024-9199MedSep 26, 2024
    risk 0.38cvss 5.8epss 0.00

    Rate limit vulnerability in Clibo Manager v1.1.9.2 that could allow an attacker to send a large number of emails to the victim in a short time, affecting availability and leading to a denial of service (DoS).

  • CVE-2024-0094MedJun 13, 2024
    risk 0.36cvss 5.5epss 0.00

    NVIDIA vGPU software for Linux contains a vulnerability in the Virtual GPU Manager, where an untrusted guest VM can cause improper control of the interaction frequency in the host. A successful exploit of this vulnerability might lead to denial of service.

  • CVE-2018-17184MedNov 6, 2018
    risk 0.35cvss 5.4epss 0.01

    A malicious user with enough administration entitlements can inject html-like elements containing JavaScript statements into Connector names, Report names, AnyTypeClass keys and Policy descriptions. When another user with enough administration entitlements edits one of the…

  • CVE-2025-13212MedMar 16, 2026
    risk 0.34cvss 5.3epss 0.00

    IBM Aspera Console 3.3.0 through 3.4.8 could allow an authenticated user to cause a denial of service in the email service due to improper control of interaction frequency.

  • CVE-2025-13211MedDec 11, 2025
    risk 0.34cvss 5.3epss 0.00

    IBM Aspera Orchestrator 4.0.0 through 4.1.0 could allow an authenticated user to cause a denial of service in the email service due to improper control of interaction frequency.

  • CVE-2025-12310MedOct 27, 2025
    risk 0.34cvss 5.3epss 0.00

    A security vulnerability has been detected in VirtFusion up to 6.0.2. This vulnerability affects unknown code of the file /account/_settings of the component Email Change Handler. The manipulation leads to improper restriction of excessive authentication attempts. The attack can…

  • CVE-2025-32378MedApr 9, 2025
    risk 0.34cvss 5.3epss 0.00

    Shopware is an open source e-commerce software platform. Prior to 6.6.10.3 or 6.5.8.17, the default settings for double-opt-in allow for mass unsolicited newsletter sign-ups without confirmation. Default settings are Newsletter: Double Opt-in set to active, Newsletter: Double…

  • CVE-2023-51544MedJun 4, 2024
    risk 0.34cvss 5.3epss 0.00

    Improper Control of Interaction Frequency vulnerability in Metagauss RegistrationMagic allows Functionality Misuse.This issue affects RegistrationMagic: from n/a through 5.2.5.0.

  • CVE-2023-40332MedJun 4, 2024
    risk 0.34cvss 5.3epss 0.00

    Improper Control of Interaction Frequency vulnerability in Lester ‘GaMerZ’ Chan WP-PostRatings allows Functionality Misuse.This issue affects WP-PostRatings: from n/a through 1.91.

  • CVE-2024-24873MedMay 17, 2024
    risk 0.34cvss 5.3epss 0.00

    : Improper Control of Interaction Frequency vulnerability in CodePeople CP Polls allows Flooding.This issue affects CP Polls: from n/a through 1.0.71.

  • CVE-2024-34695MedMay 14, 2024
    risk 0.34cvss 6.3epss 0.01

    WOWS Karma is a reputation system for Wargaming's World of Warships. A user is able to click multiple times on "create" on a post creation prompt before the modal closes, which triggers sending several post creation API requests at once. Due to timing, sending multiple posts…

  • CVE-2025-26524MedFeb 14, 2025
    risk 0.33cvss epss 0.00

    This vulnerability exists in RupeeWeb trading platform due to missing rate limiting on OTP requests in certain API endpoints. An authenticated remote attacker could exploit this vulnerability by sending multiple OTP request through vulnerable API endpoints which could lead to…

  • CVE-2025-55268MedMar 26, 2026
    risk 0.28cvss 4.3epss 0.00

    HCL Aftermarket DPC is affected by Spamming Vulnerability which can allow the actor to excessive spamming can consume server bandwidth and processing resources which may lead to Denial of Service.