CWE-799— Improper Control of Interaction Frequency
The product does not properly limit the number or frequency of interactions that it has with an actor, such as the number of incoming requests.— MITRE CWE catalog
87 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-799page 1 of 2
- CVE-2025-54321CRITICALCVSS 9.8EG 9.82025-11-18
In Ascertia SigningHub through 8.6.8, there is a lack of rate limiting on the reset password function, leading to an email bombing vulnerability. An authenticated attacker can exploit this by automating reset password requests.
- CVE-2024-6890CRITICALCVSS 8.8EG 9.82024-08-07
Password reset tokens are generated using an insecure source of randomness. Attackers who know the username of the Journyx installation user can bruteforce the password reset and change the administrator password.
- CVE-2025-9004CRITICALCVSS 9.1EG 9.12025-08-15
A vulnerability was found in mtons mblog up to 3.5.0. This issue affects some unknown processing of the file /settings/password. The manipulation leads to improper restriction of excessive authentication attempts. The attack may be initiat…
- CVE-2026-32729HIGHCVSS 8.8EG 8.82026-03-16
Runtipi is a personal homeserver orchestrator. Prior to 4.8.1, The Runtipi /api/auth/verify-totp endpoint does not enforce any rate limiting, attempt counting, or account lockout mechanism. An attacker who has obtained a user's valid crede…
- CVE-2025-29998HIGHCVSS 8.2EG 8.22025-03-13
This vulnerability exists in the CAP back office application due to missing rate limiting on OTP requests in an API endpoint. An authenticated remote attacker could exploit this vulnerability by sending multiple OTP request through vulnera…
- CVE-2026-7402HIGHCVSS 8.1EG 8.12026-04-30
Improper Control of Interaction Frequency vulnerability in MeWare Software Development Inc. PDKS allows Flooding. This issue affects PDKS: from V16.20200313 before VMYR_3.5.2025117.
- CVE-2026-24017HIGHCVSS 8.1EG 8.12026-03-10
An Improper Control of Interaction Frequency vulnerability [CWE-799] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4.0 through 7.4.10, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through…
- CVE-2026-2110HIGHCVSS 8.1EG 8.12026-02-07
A security flaw has been discovered in Tasin1025 SwiftBuy up to 0f5011372e8d1d7edfd642d57d721c9fadc54ec7. Affected by this vulnerability is an unknown functionality of the file /login.php. Performing a manipulation results in improper rest…
- CVE-2025-12547HIGHCVSS 8.1EG 8.12025-10-31
A vulnerability was identified in LogicalDOC Community Edition up to 9.2.1. This vulnerability affects unknown code of the file /login.jsp of the component Admin Login Page. Such manipulation leads to improper restriction of excessive auth…
- CVE-2021-41177HIGHCVSS 8.1EG 8.12021-10-25
Nextcloud is an open-source, self-hosted productivity platform. Prior to versions 20.0.13, 21.0.5, and 22.2.0, Nextcloud Server did not implement a database backend for rate-limiting purposes. Any component of Nextcloud using rate-limits (…
- CVE-2026-30972HIGHCVSS 7.5EG 7.52026-03-10
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior o 9.5.2-alpha.10 and 8.6.23, Parse Server's rate limiting middleware is applied at the Express middleware layer, but the batch re…
- CVE-2025-57816HIGHCVSS 7.5EG 7.52025-09-08
Fides is an open-source privacy engineering platform. Prior to version 2.69.1, the Fides Webserver API's built-in IP-based rate limiting is ineffective in environments with CDNs, proxies or load balancers. The system incorrectly applies ra…
- CVE-2024-47654HIGHCVSS 7.5EG 7.52024-10-04
This vulnerability exists in Shilpi Client Dashboard due to lack of rate limiting and Captcha protection for OTP requests in certain API endpoint. An unauthenticated remote attacker could exploit this vulnerability by sending multiple OTP …
- CVE-2024-45788HIGHCVSS 7.5EG 7.52024-09-11
This vulnerability exists in Reedos aiM-Star version 2.0.1 due to missing rate limiting on OTP requests in certain API endpoints. An authenticated remote attacker could exploit this vulnerability by sending multiple OTP request through vul…
- CVE-2024-35246HIGHCVSS 7.5EG 7.52024-06-20
An attacker may be able to cause a denial-of-service condition by sending many packets repeatedly.
- CVE-2024-32943HIGHCVSS 7.5EG 7.52024-06-20
An attacker may be able to cause a denial-of-service condition by sending many SSH packets repeatedly.
- CVE-2023-35621HIGHCVSS 7.5EG 7.52023-12-12
Microsoft Dynamics 365 Finance and Operations Denial of Service Vulnerability
- CVE-2026-33434HIGHCVSS 7.1EG 7.12026-07-16
Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 4.6.0 and above, prior to 4.14.5, a logic error in CheckRateLimitsMiddleware.dispatch() causes the /events endpoint rate check to unc…
- CVE-2026-5233HIGHCVSS 7.1EG 7.12026-06-15
Improper Control of Interaction Frequency vulnerability in MIA Technology Inc. Pizzy Library allows Flooding. This issue affects Pizzy Library: from 1.0.0.26250 before 1.3.9.26250.
- CVE-2026-84461MEDIUMCVSS 6.9EG 6.92026-09-25
Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, the two-factor login step let an attacker try unlimited password guesses for any account without triggering Zammad's normal lockout or rate limiting. The r…
- CVE-2026-85586MEDIUMCVSS 6.9EG 6.92026-09-04
phpMyFAQ versions before 4.1.8 fail to validate CAPTCHA when the store parameter is set to 'now' in question submission requests. Unauthenticated attackers can bypass CAPTCHA protection and submit unlimited questions directly, causing data…
- CVE-2026-97300MEDIUMCVSS 6.5EG 6.52026-10-06
Unauthenticated Broken Access Control in WP Event Solution <= 4.1.25 versions.
- CVE-2026-54738MEDIUMCVSS 6.5EG 6.52026-08-19
Lemmy is a link aggregator and forum for the fediverse. Prior to 0.19.19 and 1.0.0-beta.1, actix-web ConnectionInfo::realip_remote_addr reads the first value of X-Forwarded-For as the client address used by raw_ip_key in crates/utils/src/r…
- CVE-2025-13211MEDIUMCVSS 6.5EG 6.52025-12-11
IBM Aspera Orchestrator 4.0.0 through 4.1.0 could allow an authenticated user to cause a denial of service in the email service due to improper control of interaction frequency.
- CVE-2024-47065MEDIUMCVSS 6.5EG 6.52025-07-11
Meshtastic is an open source mesh networking solution. Prior to 2.5.1, traceroute responses from the remote node are not rate limited. Given that there are SNR measurements attributed to each received transmission, this is a guaranteed way…
- CVE-2024-8475MEDIUMCVSS 6.5EG 6.52024-12-17
Authentication Bypass by Assumed-Immutable Data vulnerability in Digital Operation Services WiFiBurada allows Manipulating User-Controlled Variables. This issue affects WiFiBurada: before 1.0.5.
- CVE-2024-51557MEDIUMCVSS 6.5EG 6.52024-11-04
This vulnerability exists in the Wave 2.0 due to missing rate limiting on OTP requests in an API endpoint. An authenticated remote attacker could exploit this vulnerability by sending multiple OTP request through vulnerable API endpoint wh…
- CVE-2023-40673MEDIUMCVSS 6.5EG 6.52024-06-04
: Improper Control of Interaction Frequency vulnerability in cartpauj Cartpauj Register Captcha allows Functionality Misuse.This issue affects Cartpauj Register Captcha: from n/a through 1.0.02.
- CVE-2023-27279MEDIUMCVSS 6.5EG 6.52024-04-19
IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a user to cause a denial of service due to missing API rate limiting. IBM X-Force ID: 248533.
- CVE-2023-38068MEDIUMCVSS 6.5EG 6.52023-07-12
In JetBrains YouTrack before 2023.1.16597 captcha was not properly validated for Helpdesk forms
- CVE-2020-5141MEDIUMCVSS 6.5EG 6.52020-10-12
A vulnerability in SonicOS allows a remote unauthenticated attacker to brute force Virtual Assist ticket ID in the firewall SSLVPN service. This vulnerability affected SonicOS Gen 5 version 5.9.1.7, 5.9.1.13, Gen 6 version 6.5.4.7, 6.5.1.1…
- CVE-2026-22216MEDIUMCVSS 5.3EG 6.52026-03-13
wpDiscuz before 7.6.47 contains a missing rate limiting vulnerability that allows unauthenticated attackers to subscribe arbitrary email addresses to post notifications by sending POST requests to the wpdAddSubscription handler in class.Wp…
- CVE-2024-57603MEDIUMCVSS 6.3EG 6.32025-02-12
An issue in MaysWind ezBookkeeping 0.7.0 allows a remote attacker to escalate privileges via the lack of rate limiting.
- CVE-2024-34695MEDIUMCVSS 6.3EG 6.32024-05-14
WOWS Karma is a reputation system for Wargaming's World of Warships. A user is able to click multiple times on "create" on a post creation prompt before the modal closes, which triggers sending several post creation API requests at once. D…
- CVE-2026-1685MEDIUMCVSS 5.9EG 5.92026-01-30
A vulnerability was identified in D-Link DIR-823X 250416. This vulnerability affects the function sub_40AC74 of the component Login. Such manipulation leads to improper restriction of excessive authentication attempts. The attack may be pe…
- CVE-2024-48942MEDIUMCVSS 5.9EG 5.92024-10-10
The Syracom Secure Login (2FA) plugin for Jira, Confluence, and Bitbucket through 3.1.4.5 allows remote attackers to easily brute-force the 2FA PIN via the plugins/servlet/twofactor/public/pinvalidation endpoint. The last 30 and the next 3…
- CVE-2016-6543MEDIUMCVSS 5.9EG 5.92018-07-13
A captured MAC/device ID of an iTrack Easy can be registered under multiple user accounts allowing access to getgps GPS data, which can allow unauthenticated parties to track the device.
- CVE-2024-9199MEDIUMCVSS 5.8EG 5.82024-09-26
Rate limit vulnerability in Clibo Manager v1.1.9.2 that could allow an attacker to send a large number of emails to the victim in a short time, affecting availability and leading to a denial of service (DoS).
- CVE-2024-0094MEDIUMCVSS 5.5EG 5.52024-06-13
NVIDIA vGPU software for Linux contains a vulnerability in the Virtual GPU Manager, where an untrusted guest VM can cause improper control of the interaction frequency in the host. A successful exploit of this vulnerability might lead to d…
- CVE-2026-100603MEDIUMCVSS 5.4EG 5.42026-09-26
ClawHub (openclaw/clawhub) application/backend contains a flaw in the skill report moderation flow: four distinct ordinary authenticated accounts can report a visible skill and trigger automatic hiding (moderationStatus: hidden) of that sk…
- CVE-2026-107830MEDIUMCVSS 5.3EG 5.32026-10-08
Jivejdon from commit e0306088 through commit ee67a65e lacks rate limiting on the unauthenticated /account/smsVRAction endpoint handled by SmsQQAction, allowing unlimited SMS sending. Attackers can load newAccount.jsp to set session attribu…
- CVE-2026-82924MEDIUMCVSS 5.3EG 5.32026-10-06
Improper Control of Interaction Frequency vulnerability in Pusula Communication, IT, and Internet Industry and Trade Co. Ltd. Expert Mail allows Brute Force. This issue affects Expert Mail: through 2026-09-18.
- CVE-2025-13882MEDIUMCVSS 5.3EG 5.32026-09-18
IBM Sterling Partner Engagement Manager Essentials Edition 6.3.0.0 through 6.3.0.2, and 6.2.4.0 through 6.2.4.4 and IBM Sterling Partner Engagement Manager Standard Edition 6.2.4.0 through 6.2.4.4 could allow an unauthenticated user to ca…
- CVE-2026-54594MEDIUMCVSS 5.3EG 5.32026-09-17
OmniBlocks is a monorepo for the OmniBlocks project. Prior to the June 6, 2026 workflow remediation, .github/workflows/disc.yml runs for the issues opened event and the issues edited event and invokes the createDiscussion mutation whenever…
- CVE-2024-23565MEDIUMCVSS 5.3EG 5.32026-07-17
HCL Aftermarket EPC is vulnerable to email flooding as the application does not have a proper mail limitation mechanism at Forget Password functionality. The actor could b e a human or an automated process such as a virus or bot. This coul…
- CVE-2026-41346MEDIUMCVSS 5.3EG 5.32026-04-23
OpenClaw 2026.2.26 before 2026.3.31 enforces pending pairing-request caps per channel file instead of per account, allowing attackers to exhaust the shared pending window. Remote attackers can submit pairing requests from other accounts to…
- CVE-2026-41343MEDIUMCVSS 5.3EG 5.32026-04-23
OpenClaw before 2026.3.31 lacks a shared pre-auth concurrency budget on the public LINE webhook path, allowing attackers to cause transient availability loss. Remote attackers can flood the webhook endpoint with concurrent requests before …
- CVE-2025-55268MEDIUMCVSS 5.3EG 5.32026-03-26
HCL Aftermarket DPC is affected by Spamming Vulnerability which can allow the actor to excessive spamming can consume server bandwidth and processing resources which may lead to Denial of Service.
- CVE-2025-12310MEDIUMCVSS 5.3EG 5.32025-10-27
A security vulnerability has been detected in VirtFusion up to 6.0.2. This vulnerability affects unknown code of the file /account/_settings of the component Email Change Handler. The manipulation leads to improper restriction of excessive…
- CVE-2025-32378MEDIUMCVSS 5.3EG 5.32025-04-09
Shopware is an open source e-commerce software platform. Prior to 6.6.10.3 or 6.5.8.17, the default settings for double-opt-in allow for mass unsolicited newsletter sign-ups without confirmation. Default settings are Newsletter: Double Opt…
Map vulnerabilities like CWE-799 to your infrastructure
EchelonGraph correlates every CVE — across CWE-799 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →