CWE-307— Improper Restriction of Excessive Authentication Attempts
The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.— MITRE CWE catalog
689 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-307page 1 of 14
- CVE-2026-73056CRITICALCVSS 9.8EG 9.82026-08-16
SiYuan kernel versions before 3.7.4 contain an improper restriction of excessive authentication attempts vulnerability in the CheckAuth() middleware. The middleware accepts the API token (Conf.Api.Token) via an Authorization header (Token/…
- CVE-2026-73046CRITICALCVSS 9.8EG 9.82026-08-15
SiYuan before v3.7.4 improperly restricts excessive authentication attempts in the CheckAuth() middleware. The HTTP Basic Authentication branch, which guards nearly the entire /api/* surface, accepts the workspace access code (Conf.AccessA…
- CVE-2026-6853CRITICALCVSS 9.8EG 9.82026-06-12
Improper restriction of excessive authentication attempts vulnerability in Başbelen Group Food Cafe Businesses Industry and Trade Ltd. Co. Pause+ Mobile App allows Authentication Bypass. This issue affects Pause+ Mobile App: from v1.0.6 …
- CVE-2026-8760CRITICALCVSS 9.8EG 9.82026-05-27
The Login with OTP plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.6. This is due to an incomplete fix for CVE-2024-11178: the rate-limit/lockout check added to `otpl_login_action()` was …
- CVE-2026-44596CRITICALCVSS 9.8EG 9.82026-05-27
Yamcs is a mission control framework. Prior to 5.12.7, the authentication endpoint POST /auth/token in yamcs-core, handled by yamcs-core/src/main/java/org/yamcs/http/auth/AuthHandler.java, lacked any rate limiting, account lockout, or fail…
- CVE-2020-37228CRITICALCVSS 9.8EG 9.82026-05-16
iDS6 DSSPro Digital Signage System 6.2 contains a CAPTCHA security bypass vulnerability that allows attackers to bypass authentication by requesting the autoLoginVerifyCode object. Attackers can retrieve valid CAPTCHA codes via the login e…
- CVE-2025-31991CRITICALCVSS 9.8EG 9.82026-04-13
Rate Limiting for attempting a user login is not being properly enforced, making HCL DevOps Velocity susceptible to brute-force attacks past the unsuccessful login attempt limit. This vulnerability is fixed in 5.1.7.
- CVE-2026-33879CRITICALCVSS 9.8EG 9.82026-03-27
Federated Learning and Interoperability Platform (FLIP) is an open-source platform for federated training and evaluation of medical imaging AI models across healthcare institutions. The FLIP login page in versions 0.1.1 and prior has no ra…
- CVE-2026-33640CRITICALCVSS 9.8EG 9.82026-03-26
Outline is a service that allows for collaborative documentation. Outline implements an Email OTP login flow for users not associated with an Identity Provider. Starting in version 0.86.0 and prior to version 1.6.0, Outline does not invali…
- CVE-2026-31851CRITICALCVSS 9.8EG 9.82026-03-23
Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 does not implement rate limiting or account lockout mechanisms on authentication interfaces. An attacker can perform unlimited authentication attempts against endpoints that …
- CVE-2025-69246CRITICALCVSS 9.8EG 9.82026-03-16
Raytha CMS does not have any brute force protection mechanism implemented. It allows an attacker to send multiple automated logon requests without triggering lockout, throttling, or step-up challenges. This issue was fixed in version 1.4.…
- CVE-2026-30789CRITICALCVSS 9.8EG 9.82026-03-05
Use of Password Hash With Insufficient Computational Effort, Improper Restriction of Excessive Authentication Attempts vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Client login, p…
- CVE-2026-26305CRITICALCVSS 9.8EG 9.82026-02-27
The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks by suppressing or mis-routing legitima…
- CVE-2026-24445CRITICALCVSS 9.8EG 9.82026-02-27
The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks by suppressing or mis-routing legitima…
- CVE-2026-25945CRITICALCVSS 9.8EG 9.82026-02-27
The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks by suppressing or mis-routing legitima…
- CVE-2026-25114CRITICALCVSS 9.8EG 9.82026-02-27
The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks by suppressing or mis-routing legitima…
- CVE-2026-25113CRITICALCVSS 9.8EG 9.82026-02-27
The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks by suppressing or mis-routing legitima…
- CVE-2026-20792CRITICALCVSS 9.8EG 9.82026-02-27
The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks by suppressing or misrouting legitimat…
- CVE-2026-24436CRITICALCVSS 9.8EG 9.82026-01-26
Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) do not enforce rate limiting or account lockout mechanisms on authentication endpoints. This allows attackers to perform unrestricted brute-force attempts again…
- CVE-2026-22278CRITICALCVSS 9.8EG 9.82026-01-22
Dell PowerScale OneFS versions prior to 9.13.0.0 contains an improper restriction of excessive authentication attempts vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to U…
- CVE-2025-12995CRITICALCVSS 9.8EG 9.82025-12-04
Medtronic CareLink Network allows an unauthenticated remote attacker to perform a brute force attack on an API endpoint that could be used to determine a valid password under certain circumstances. This issue affects CareLink Network: befo…
- CVE-2025-64310CRITICALCVSS 9.8EG 9.82025-11-21
EPSON WebConfig and Epson Web Control for SEIKO EPSON Projector Products do not restrict excessive authentication attempts. An administrative user's password may be identified through a brute force attack.
- CVE-2025-63807CRITICALCVSS 9.8EG 9.82025-11-20
An issue was discovered in weijiang1994 university-bbs (aka Blogin) in commit 9e06bab430bfc729f27b4284ba7570db3b11ce84 (2025-01-13). A weak verification code generation mechanism combined with missing rate limiting allows attackers to perf…
- CVE-2025-64102CRITICALCVSS 9.8EG 9.82025-10-29
Zitadel is open-source identity infrastructure software. Prior to 4.6.0, 3.4.3, and 2.71.18, an attacker can perform an online brute-force attack on OTP, TOTP, and passwords. While Zitadel allows preventing online brute force attacks in sc…
- CVE-2025-56221CRITICALCVSS 9.8EG 9.82025-10-17
A lack of rate limiting in the login mechanism of SigningHub v8.6.8 allows attackers to bypass authentication via a brute force attack.
- CVE-2025-8679CRITICALCVSS 9.8EG 9.82025-10-01
In ExtremeGuest Essentials before 25.5.0, captive-portal may permit unauthorized access via manual brute-force procedure. Under certain ExtremeGuest Essentials captive-portal SSID configurations, repeated manual login attempts may allow an…
- CVE-2025-1740CRITICALCVSS 9.8EG 9.82025-09-03
Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft MyRezzta allows Authentication Bypass, Password Recovery Exploitation, Brute Force. This issue affects MyRezzta: from s2.03.01 before v2.05.01.
- CVE-2025-7393CRITICALCVSS 9.8EG 9.82025-07-21
Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Mail Login allows Brute Force.This issue affects Mail Login: from 3.0.0 before 3.2.0, from 4.0.0 before 4.2.0.
- CVE-2024-9342CRITICALCVSS 9.8EG 9.82025-07-16
In Eclipse GlassFish versions before 8.0.3 it is possible to perform Login Brute Force attacks as there is no limitation in the number of failed login attempts. GlassFish 8.0.3 adds automatic attack protection documented in https://glassf…
- CVE-2025-43863CRITICALCVSS 9.8EG 9.82025-06-12
vantage6 is an open source framework built to enable, manage and deploy privacy enhancing technologies like Federated Learning and Multi-Party Computation. If attacker gets access to an authenticated session, they can try to brute-force th…
- CVE-2025-3709CRITICALCVSS 9.8EG 9.82025-05-02
Agentflow from Flowring Technology has an Account Lockout Bypass vulnerability, allowing unauthenticated remote attackers to exploit this vulnerability to perform password brute force attack.
- CVE-2025-25595CRITICALCVSS 9.8EG 9.82025-03-18
A lack of rate limiting in the login page of Safe App version a3.0.9 allows attackers to bypass authentication via a brute force attack.
- CVE-2024-57602CRITICALCVSS 9.8EG 9.82025-02-12
An issue in Alex Tselegidis EasyAppointments v.1.5.0 allows a remote attacker to escalate privileges via the index.php file.
- CVE-2024-46442CRITICALCVSS 9.8EG 9.82024-12-10
An issue in the BYD Dilink Headunit System v3.0 to v4.0 allows attackers to bypass authentication via a bruteforce attack.
- CVE-2024-5716CRITICALCVSS 9.8EG 9.82024-11-22
Logsign Unified SecOps Platform Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Logsign Unified SecOps Platform. Authentication is not required to exploi…
- CVE-2024-51558CRITICALCVSS 9.8EG 9.82024-11-04
This vulnerability exists in the Wave 2.0 due to missing restrictions for excessive failed authentication attempts on its API based login. A remote attacker could exploit this vulnerability by conducting a brute force attack against legit…
- CVE-2024-47656CRITICALCVSS 9.8EG 9.82024-10-04
This vulnerability exists in Shilpi Client Dashboard due to missing restrictions for incorrect login attempts on its API based login. A remote attacker could exploit this vulnerability by conducting a brute force attack on password, which …
- CVE-2024-41276CRITICALCVSS 9.8EG 9.82024-10-01
A vulnerability in Kaiten version 57.131.12 and earlier allows attackers to bypass the PIN code authentication mechanism. The application requires users to input a 6-digit PIN code sent to their email for authorization after entering their…
- CVE-2024-47088CRITICALCVSS 9.8EG 9.82024-09-19
This vulnerability exists in Apex Softcell LD Geo due to missing restrictions for excessive failed authentication attempts on its API based login. A remote attacker could exploit this vulnerability by conducting a brute force attack on log…
- CVE-2024-45790CRITICALCVSS 9.8EG 9.82024-09-11
This vulnerability exists in Reedos aiM-Star version 2.0.1 due to missing restrictions for excessive failed authentication attempts on its API based login. A remote attacker could exploit this vulnerability by conducting a brute force atta…
- CVE-2024-43042CRITICALCVSS 9.8EG 9.82024-08-16
Pluck CMS 4.7.18 does not restrict failed login attempts, allowing attackers to execute a brute force attack.
- CVE-2024-42466CRITICALCVSS 9.8EG 9.82024-08-16
Improper Restriction of Excessive Authentication Attempts vulnerability in upKeeper Solutions product upKeeper Manager allows Authentication Abuse.This issue affects upKeeper Manager: through 5.1.9.
- CVE-2024-42465CRITICALCVSS 9.8EG 9.82024-08-16
Improper Restriction of Excessive Authentication Attempts vulnerability in upKeeper Solutions product upKeeper Manager allows Authentication Abuse.This issue affects upKeeper Manager: through 5.1.9.
- CVE-2024-39225CRITICALCVSS 9.8EG 9.82024-08-06
GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16, XE300 v4.3.16, E750 v4.3.12, AP1300/S1300 v4.3.13, and XE3000/X3000 v4.4 were discovered to contai…
- CVE-2024-21652CRITICALCVSS 9.8EG 9.82024-03-18
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior to versions 2.8.13, 2.9.9, and 2.10.4, an attacker can exploit a chain of vulnerabilities, including a Denial of Service (DoS) flaw and in-memory data storage …
- CVE-2024-2051CRITICALCVSS 9.8EG 9.82024-03-18
CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could cause account takeover and unauthorized access to the system when an attacker conducts brute-force attacks against the login form.
- CVE-2023-33759CRITICALCVSS 9.8EG 9.82024-01-25
SpliceCom Maximiser Soft PBX v1.5 and before does not restrict excessive authentication attempts, allowing attackers to bypass authentication via a brute force attack.
- CVE-2023-49792CRITICALCVSS 9.8EG 9.82023-12-22
Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. In Nextcloud Server prior to versions 26.0.9 and 27.1.4; as well as Nextcloud Enterprise Server prior to versions 23.0.12.13, 24.0.12.9, 25.0.13.4, 26.0.9…
- CVE-2023-6912CRITICALCVSS 9.8EG 9.82023-12-20
Lack of protection against brute force attacks in M-Files Server before 23.12.13205.0 allows an attacker unlimited authentication attempts, potentially compromising targeted M-Files user accounts by guessing passwords.
- CVE-2023-6928CRITICALCVSS 9.8EG 9.82023-12-19
EuroTel ETL3100 versions v01c01 and v01x37 does not limit the number of attempts to guess administrative credentials in remote password attacks to gain full control of the system.
Map vulnerabilities like CWE-307 to your infrastructure
EchelonGraph correlates every CVE — across CWE-307 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →