GCM is uniquely brittle. DJB's Chapoly also falls to nonce misuse (there are NMR schemes, like SIV, but they aren't in wide use), but if you so much as breathe on GCM the wrong way you get key recovery. A good example of this is Furguson's GCM short-tag attack, which is one of Sean Devlin's Set 8 cryptopals exercises.
GCM is so bad that when Sean and Hanno gave their GCM talk at Black Hat last year, they were able to inject their slides directly into the TLS session of a GCHQ website and serve them from there.