CWE-307— Improper Restriction of Excessive Authentication Attempts
The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.— MITRE CWE catalog
643 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-307page 11 of 13
- CVE-2025-64310CRITICALCVSS 9.8EG 9.82025-11-21
EPSON WebConfig and Epson Web Control for SEIKO EPSON Projector Products do not restrict excessive authentication attempts. An administrative user's password may be identified through a brute force attack.
- CVE-2025-64526MEDIUMCVSS 5.3EG 5.32026-05-14
Strapi is an open source headless content management system. In Strapi versions prior to 5.45.0, the rate-limit middleware in the users-permissions plugin derived its rate-limit key in part from `ctx.request.body.email`, including on route…
- CVE-2025-6533MEDIUMCVSS 5.9EG 5.92025-06-24
A vulnerability, which was classified as critical, has been found in xxyopen/201206030 novel-plus up to 5.1.3. Affected by this issue is the function ajaxLogin of the file novel-admin/src/main/java/com/java2nb/system/controller/LoginContro…
- CVE-2025-65427MEDIUMCVSS 6.5EG 6.52025-12-16
An issue was discovered in Dbit N300 T1 Pro Easy Setup Wireless Wi-Fi Router on firmware version V1.0.0 does not implement rate limiting to /api/login allowing attackers to brute force password enumerations.
- CVE-2025-66204HIGHCVSS 8.1EG 8.12025-12-09
WBCE CMS is a content management system. Version 1.6.4 contains a brute-force protection bypass where an attacker can indefinitely reset the counter by modifying `X-Forwarded-For` on each request, gaining unlimited password guessing attemp…
- CVE-2025-66413MEDIUMCVSS 6.5EG 6.52026-03-10
Git for Windows is the Windows port of Git. Prior to 2.53.0(2), it is possible to obtain a user's NTLM hash by tricking them into cloning from a malicious server. Since NTLM hashing is weak, it is possible for the attacker to brute-force t…
- CVE-2025-66482MEDIUMCVSS 6.5EG 6.52025-12-16
Misskey is an open source, federated social media platform. Attackers who use an untrusted reverse proxy or not using a reverse proxy at all can bypass IP rate limiting by adding a forged X-Forwarded-For header. Starting with version 2025.…
- CVE-2025-67090MEDIUMCVSS 5.1EG 5.12026-01-08
The LuCI web interface on Gl Inet GL.Inet AX1800 Version 4.6.4 & 4.6.8 are vulnerable. Fix available in version 4.8.2 GL.Inet AX1800 Version 4.6.4 & 4.6.8 lacks rate limiting or account lockout mechanisms on the authentication endpoint (`/…
- CVE-2025-67091MEDIUMCVSS 6.5EG 6.52026-01-08
An issue in GL Inet GL.Inet AX1800 Version 4.6.4 & 4.6.8 are vulnerable. GL.Inet AX1800 Version 4.6.4 & 4.6.8 in the GL.iNet custom opkg wrapper script located at /usr/libexec/opkg-call. The script is executed with root privileges when tri…
- CVE-2025-67853HIGHCVSS 7.5EG 7.52026-02-03
A flaw was found in Moodle. A remote attacker could exploit a lack of proper rate limiting in the confirmation email service. This vulnerability allows attackers to more easily enumerate or guess user credentials, facilitating brute-force …
- CVE-2025-69246CRITICALCVSS 9.8EG 9.82026-03-16
Raytha CMS does not have any brute force protection mechanism implemented. It allows an attacker to send multiple automated logon requests without triggering lockout, throttling, or step-up challenges. This issue was fixed in version 1.4.…
- CVE-2025-69615CRITICALCVSS 9.1EG 9.12026-03-10
Incorrect Access Control via missing 2FA rate-limiting allowing unlimited brute-force retries and full MFA bypass with no user interaction required. Affected Product: Deutsche Telekom AG Telekom Account Management Portal, versions before 2…
- CVE-2025-7393CRITICALCVSS 9.8EG 9.82025-07-21
Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Mail Login allows Brute Force.This issue affects Mail Login: from 3.0.0 before 3.2.0, from 4.0.0 before 4.2.0.
- CVE-2025-7630MEDIUMCVSS 5.3EG 5.32026-02-18
Improper Restriction of Excessive Authentication Attempts, Improper Authentication vulnerability in Doruk Communication and Automation Industry and Trade Inc. Wispotter allows Password Brute Forcing, Brute Force. This issue affects Wispot…
- CVE-2025-7882LOWCVSS 3.1EG 3.12025-07-20
A vulnerability was found in Mercusys MW301R 1.0.2 Build 190726 Rel.59423n. It has been rated as problematic. This issue affects some unknown processing of the component Login. The manipulation leads to improper restriction of excessive au…
- CVE-2025-8118MEDIUMCVSS 6.5EG 6.52025-09-30
PAD CMS implements weak client-side brute-force protection by utilizing two cookies: login_count and login_timeout. Information about attempt count or timeout is not stored on the server, which allows a malicious attacker to bypass th…
- CVE-2025-8679CRITICALCVSS 9.8EG 9.82025-10-01
In ExtremeGuest Essentials before 25.5.0, captive-portal may permit unauthorized access via manual brute-force procedure. Under certain ExtremeGuest Essentials captive-portal SSID configurations, repeated manual login attempts may allow an…
- CVE-2025-8742LOWCVSS 3.7EG 3.72025-08-08
A vulnerability was found in macrozheng mall 1.0.3. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Admin Login. The manipulation leads to improper restriction of excessive authentica…
- CVE-2025-8927LOWCVSS 3.7EG 3.72025-08-13
A vulnerability was determined in mtons mblog up to 3.5.0. Affected by this issue is some unknown functionality of the file /email/send_code of the component Verification Code Handler. The manipulation of the argument email leads to improp…
- CVE-2025-9004CRITICALCVSS 9.1EG 9.12025-08-15
A vulnerability was found in mtons mblog up to 3.5.0. This issue affects some unknown processing of the file /settings/password. The manipulation leads to improper restriction of excessive authentication attempts. The attack may be initiat…
- CVE-2025-9551MEDIUMCVSS 6.5EG 6.52025-10-10
Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Protected Pages allows Brute Force.This issue affects Protected Pages: from 0.0.0 before 1.8.0, from 7.X-1.0 before 7.X-2.5.
- CVE-2026-0972HIGHCVSS 5.4EG 7.32026-04-21
HTML injection is possible in system generated emails in Fortra's GoAnywhere MFT prior to 7.10.0. Note: The title, details, and description of this CVE were corrected post-publishing.
- CVE-2026-10216LOWCVSS 3.7EG 3.72026-06-01
A vulnerability was detected in unitedbyai droidclaw up to 0.5.3. The affected element is an unknown function of the file server/src/routes/pairing.ts of the component claim Endpoint. The manipulation results in improper restriction of exc…
- CVE-2026-11779MEDIUMCVSS 5.3EG 5.32026-06-26
An Improper Authorization vulnerability exists in PayloadCMS version 3.84.1 due to insufficient access control on the account unlock operation.
- CVE-2026-11915MEDIUMCVSS 5.9EG 5.92026-07-10
vulnerability in Drupal Brute force attack protection allows . This issue affects Brute force attack protection versions: *.*.
- CVE-2026-1409MEDIUMCVSS 4.2EG 4.22026-01-26
A security vulnerability has been detected in Beetel 777VR1 up to 01.00.09/01.00.09_55. This issue affects some unknown processing of the component UART Interface. The manipulation leads to improper restriction of excessive authentication …
- CVE-2026-14254HIGHCVSS 8.3EG 8.32026-07-16
A race condition in the account lockout mechanism in Delphix Continous Data allowed the lockout threshold to be bypassed through concurrent authentication requests. Parallel login attempts were processed before the failed-login counter …
- CVE-2026-15079MEDIUMCVSS 5.4EG 5.42026-07-10
Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Login Disable allows Brute Force. This issue affects Login Disable versions: from 0.0.0 to 2.1.4.
- CVE-2026-15144MEDIUMCVSS 5.3EG 5.32026-07-29
@fastify/rate-limit before 11.2.0 keys rate-limit buckets by the verbatim client IP string returned from request.ip. Because a single IPv6 client can control a large address range (a /64 holds 2^64 distinct addresses) and the same address …
- CVE-2026-16347HIGHCVSS 8.8EG 8.82026-07-28
MikroTik RouterOS contains a weakness in its API authentication handling that lacks effective safeguards against excessive login attempts. The system does not enforce meaningful rate-limiting, account lockout, or source-based restrictions,…
- CVE-2026-16619HIGHCVSS 7.5EG 7.52026-08-06
The miniOrange 2FA WordPress plugin before 6.2.8 does not correctly limit the number of second-factor verification attempts, tracking them against a client-supplied identifier that is reissued on every login, allowing an attacker who alrea…
- CVE-2026-1685MEDIUMCVSS 5.9EG 5.92026-01-30
A vulnerability was identified in D-Link DIR-823X 250416. This vulnerability affects the function sub_40AC74 of the component Login. Such manipulation leads to improper restriction of excessive authentication attempts. The attack may be pe…
- CVE-2026-1816MEDIUMCVSS 6.3EG 6.32026-05-21
Improper restriction of excessive authentication attempts vulnerability in Turkiye Electricity Transmission Corporation (TEİAŞ) Mobile Application allows Brute Force. This issue affects Mobile Application: from 1.6.2 before 1.13.
- CVE-2026-19297CRITICALCVSS 9.1EG 9.12026-08-13
IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain unauthorized access to user accounts due to improper restriction of excessive authentication attempts.
- CVE-2026-19895LOWCVSS 3.7EG 3.72026-08-15
A vulnerability was detected in opensourcepos Open Source Point of Sale up to 3.4.2. This affects the function Login::index of the file app/Config/Filters.php of the component Login Endpoint. The manipulation results in improper restrictio…
- CVE-2026-19897LOWCVSS 3.7EG 3.72026-08-15
A vulnerability has been found in mangroup dtale up to 3.22.0. This issue affects the function Login of the file dtale/auth.py of the component Login Endpoint. Such manipulation leads to improper restriction of excessive authentication att…
- CVE-2026-19898LOWCVSS 3.7EG 3.72026-08-15
A vulnerability was found in VictoriaMetrics up to 1.146.0. Impacted is the function requestHandler of the file app/vmauth/main.go of the component VMAuth Authentication Endpoint. Performing a manipulation results in improper restriction o…
- CVE-2026-20792CRITICALCVSS 9.8EG 9.82026-02-27
The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks by suppressing or misrouting legitimat…
- CVE-2026-20882HIGHCVSS 7.5EG 7.52026-03-06
The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks by suppressing or mis-routing legitimate …
- CVE-2026-2110HIGHCVSS 8.1EG 8.12026-02-07
A security flaw has been discovered in Tasin1025 SwiftBuy up to 0f5011372e8d1d7edfd642d57d721c9fadc54ec7. Affected by this vulnerability is an unknown functionality of the file /login.php. Performing a manipulation results in improper rest…
- CVE-2026-21755MEDIUMCVSS 5.3EG 5.32026-08-24
HCL Hive is affected by a missing rate limit which could allow an attacker unauthorized access via brute-force or credential stuffing attacks, or cause a denial of service.
- CVE-2026-22278CRITICALCVSS 9.8EG 9.82026-01-22
Dell PowerScale OneFS versions prior to 9.13.0.0 contains an improper restriction of excessive authentication attempts vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to U…
- CVE-2026-22603MEDIUMCVSS 6.5EG 6.52026-01-10
OpenProject is an open-source, web-based project management software. Prior to version 16.6.2, OpenProject’s unauthenticated password-change endpoint (/account/change_password) was not protected by the same brute-force safeguards that ap…
- CVE-2026-22616MEDIUMCVSS 6.5EG 6.52026-04-16
Eaton Intelligent Power Protector (IPP) software allows repeated authentication attempts against the web interface login page due to insufficient rate‑limiting controls. This security issue has been fixed in the latest version of Eat…
- CVE-2026-22629LOWCVSS 3.7EG 3.72026-03-10
An improper restriction of excessive authentication attempts vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4 all versions, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer 6.4 all…
- CVE-2026-2402MEDIUMCVSS 5.3EG 5.32026-04-14
CWE-307 Improper Restriction of Excessive Authentication Attempts vulnerability exists that would allow an attacker to gain access to the user account by performing an arbitrary number of authentication attempts with different credentials …
- CVE-2026-24436CRITICALCVSS 9.8EG 9.82026-01-26
Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) do not enforce rate limiting or account lockout mechanisms on authentication endpoints. This allows attackers to perform unrestricted brute-force attempts again…
- CVE-2026-24445CRITICALCVSS 9.8EG 9.82026-02-27
The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks by suppressing or mis-routing legitima…
- CVE-2026-24696HIGHCVSS 7.5EG 7.52026-03-06
The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks by suppressing or mis-routing legitimate …
- CVE-2026-25113CRITICALCVSS 9.8EG 9.82026-02-27
The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks by suppressing or mis-routing legitima…
Map vulnerabilities like CWE-307 to your infrastructure
EchelonGraph correlates every CVE — across CWE-307 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →