Show filters
63 Total Results
Displaying 1-10 of 63
Sort by:
Attacker Value
Unknown

CVE-2020-35586

Disclosure Date: December 23, 2020 (last updated February 22, 2025)
In Solstice Pod before 3.3.0 (or Open4.3), the Administrator password can be enumerated using brute-force attacks via the /Config/service/initModel?password= Solstice Open Control API because there is no complexity requirement (e.g., it might be all digits or all lowercase letters).
Attacker Value
Unknown

CVE-2020-35585

Disclosure Date: December 23, 2020 (last updated February 22, 2025)
In Solstice Pod before 3.3.0 (or Open4.3), the screen key can be enumerated using brute-force attacks via the /lookin/info Solstice Open Control API because there are only 1.7 million possibilities.
Attacker Value
Unknown

CVE-2020-35590

Disclosure Date: December 21, 2020 (last updated February 22, 2025)
LimitLoginAttempts.php in the limit-login-attempts-reloaded plugin before 2.17.4 for WordPress allows a bypass of (per IP address) rate limits because the X-Forwarded-For header can be forged. When the plugin is configured to accept an arbitrary header for the client source IP address, a malicious user is not limited to perform a brute force attack, because the client IP header accepts any arbitrary string. When randomizing the header input, the login count does not ever reach the maximum allowed retries.
Attacker Value
Unknown

CVE-2020-28206

Disclosure Date: December 02, 2020 (last updated February 22, 2025)
An issue was discovered in Bitrix24 Bitrix Framework (1c site management) 20.0. An "User enumeration and Improper Restriction of Excessive Authentication Attempts" vulnerability exists in the admin login form, allowing a remote user to enumerate users in the administrator group. This also allows brute-force attacks on the passwords of users not in the administrator group.
Attacker Value
Unknown

CVE-2020-29136

Disclosure Date: November 27, 2020 (last updated February 22, 2025)
In cPanel before 90.0.17, 2FA can be bypassed via a brute-force approach (SEC-575).
Attacker Value
Unknown

CVE-2020-29042

Disclosure Date: November 26, 2020 (last updated February 22, 2025)
An issue was discovered in BigBlueButton through 2.2.29. A brute-force attack may occur because an unlimited number of codes can be entered for a meeting that is protected by an access code.
Attacker Value
Unknown

CVE-2020-28212

Disclosure Date: November 19, 2020 (last updated February 22, 2025)
A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists in PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) (all versions) that could cause unauthorized command execution when a brute force attack is done over Modbus.
Attacker Value
Unknown

CVE-2020-27423

Disclosure Date: November 16, 2020 (last updated February 22, 2025)
Anuko Time Tracker v1.19.23.5311 lacks rate limit on the password reset module which allows attacker to perform Denial of Service attack on any legitimate user's mailbox
Attacker Value
Unknown

CVE-2020-27747

Disclosure Date: October 29, 2020 (last updated February 22, 2025)
An issue was discovered in Click Studios Passwordstate 8.9 (Build 8973).If the user of the system has assigned himself a PIN code for entering from a mobile device using the built-in generator (4 digits), a remote attacker has the opportunity to conduct a brute force attack on this PIN code. As result, remote attacker retrieves all passwords from another systems, available for affected account.
Attacker Value
Unknown

CVE-2020-15906

Disclosure Date: October 22, 2020 (last updated February 22, 2025)
tiki-login.php in Tiki before 21.2 sets the admin password to a blank value after 50 invalid login attempts.