CWE-307— Improper Restriction of Excessive Authentication Attempts
The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.— MITRE CWE catalog
689 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-307page 11 of 14
- CVE-2026-1816MEDIUMCVSS 6.3EG 6.32026-05-21
Improper restriction of excessive authentication attempts vulnerability in Turkiye Electricity Transmission Corporation (TEİAŞ) Mobile Application allows Brute Force. This issue affects Mobile Application: from 1.6.2 before 1.13.
- CVE-2025-10928MEDIUMCVSS 6.3EG 6.32025-10-30
Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Access code allows Brute Force.This issue affects Access code: from 0.0.0 before 2.0.5.
- CVE-2025-36758MEDIUMCVSS 6.3EG 6.32025-09-10
It is possible to bypass the clipping level of authentication attempts in SolaX Cloud through the use of the 'Forgot Password' functionality as an oracle.
- CVE-2021-38474MEDIUMCVSS 6.3EG 6.32021-10-19
InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 have has no account lockout policy configured for the login page of the product. This may allow an attacker to execute a brute-force password attack with no time limitatio…
- CVE-2026-35902MEDIUMCVSS 6.2EG 6.22026-04-27
The RTSP service of MERCURY IP camera MIPC252W 1.0.5 Build 230306 has an issue handling failed Digest authentication attempts. By repeatedly sending RTSP requests with invalid authentication parameters, an unauthenticated attacker can caus…
- CVE-2024-3461MEDIUMCVSS 6.2EG 6.22024-05-14
KioWare for Windows (versions all through 8.35) allows to brute force the PIN number, which protects the application from being closed, as there are no mechanisms preventing a user from excessively guessing the number.
- CVE-2014-2875MEDIUMCVSS 6.1EG 6.12020-02-06
The session.lua library in CGILua 5.2 alpha 1 and 5.2 alpha 2 uses weak session IDs generated based on OS time, which allows remote attackers to hijack arbitrary sessions via a brute force attack. NOTE: CVE-2014-10399 and CVE-2014-10400 we…
- CVE-2026-11915MEDIUMCVSS 5.9EG 5.92026-07-10
vulnerability in Drupal Brute force attack protection allows . This issue affects Brute force attack protection versions: *.*.
- CVE-2026-41213MEDIUMCVSS 5.9EG 5.92026-04-23
@node-oauth/oauth2-server is a module for implementing an OAuth2 server in Node.js. The token exchange path accepts RFC7636-invalid code_verifier values (including one-character strings) for S256 PKCE flows. Because short/weak verifiers ar…
- CVE-2026-35597MEDIUMCVSS 5.9EG 5.92026-04-10
Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the TOTP failed-attempt lockout mechanism is non-functional due to a database transaction handling bug. When a TOTP validation fails, the login handler in pkg/…
- CVE-2026-27801MEDIUMCVSS 5.9EG 5.92026-03-04
Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Vaultwarden versions 1.34.3 and prior are susceptible to a 2FA bypass when performing protected actions. An attacker who gains authen…
- CVE-2026-1685MEDIUMCVSS 5.9EG 5.92026-01-30
A vulnerability was identified in D-Link DIR-823X 250416. This vulnerability affects the function sub_40AC74 of the component Login. Such manipulation leads to improper restriction of excessive authentication attempts. The attack may be pe…
- CVE-2025-36064MEDIUMCVSS 5.9EG 5.92025-09-22
IBM Sterling Connect:Express for Microsoft Windows 3.1.0.0 through 3.1.0.22 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials.
- CVE-2025-52997MEDIUMCVSS 5.9EG 5.92025-06-30
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Prior to version 2.34.1, a missing password policy and brute-force protection makes the auth…
- CVE-2025-6533MEDIUMCVSS 5.9EG 5.92025-06-24
A vulnerability, which was classified as critical, has been found in xxyopen/201206030 novel-plus up to 5.1.3. Affected by this issue is the function ajaxLogin of the file novel-admin/src/main/java/com/java2nb/system/controller/LoginContro…
- CVE-2024-0787MEDIUMCVSS 5.9EG 5.92024-11-15
phpIPAM version 1.5.1 contains a vulnerability where an attacker can bypass the IP block mechanism to brute force passwords for users by using the 'X-Forwarded-For' header. The issue lies in the 'get_user_ip()' function in 'class.Common.ph…
- CVE-2024-28833MEDIUMCVSS 5.9EG 5.92024-06-10
Improper restriction of excessive authentication attempts with two factor authentication methods in Checkmk 2.3 before 2.3.0p6 facilitates brute-forcing of second factor mechanisms.
- CVE-2024-28825MEDIUMCVSS 5.9EG 5.92024-04-24
Improper restriction of excessive authentication attempts on some authentication methods in Checkmk before 2.3.0b5 (beta), 2.2.0p26, 2.1.0p43, and in Checkmk 2.0.0 (EOL) facilitates password brute-forcing.
- CVE-2023-36917MEDIUMCVSS 5.9EG 5.92023-07-11
SAP BusinessObjects Business Intelligence Platform - version 420, 430, allows an unauthorized attacker who had hijacked a user session, to be able to bypass the victim’s old password via brute force, due to unrestricted rate limit for pa…
- CVE-2023-33868MEDIUMCVSS 5.9EG 5.92023-07-06
The number of login attempts is not limited. This could allow an attacker to perform a brute force on HTTP basic authentication.
- CVE-2021-41171MEDIUMCVSS 5.9EG 5.92021-10-22
eLabFTW is an open source electronic lab notebook manager for research teams. In versions of eLabFTW before 4.1.0, it allows attackers to bypass a brute-force protection mechanism by using many different forged PHPSESSID values in HTTP Coo…
- CVE-2026-48071MEDIUMCVSS 5.8EG 5.82026-08-06
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.4, the PIN-type challenge throttle uses `emailHash` as the only key. The throttle rows live in the central `ch…
- CVE-2023-39958MEDIUMCVSS 5.8EG 5.82023-08-10
Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 22.0.0 and prior to versions 22.2.10.13, 23.0.12.8, 24.0.12.5, 25.0.9, 26.0.4, and 27.0.1, missing protection allows an attacker to br…
- CVE-2023-34243MEDIUMCVSS 5.8EG 5.82023-06-08
TGstation is a toolset to manage production BYOND servers. In affected versions if a Windows user was registered in tgstation-server (TGS), an attacker could discover their username by brute-forcing the login endpoint with an invalid passw…
- CVE-2026-18260MEDIUMCVSS 5.7EG 5.72026-08-25
Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Disable Login Page allows Brute Force. This issue affects Disable Login Page versions: from 0.0.0 to 1.1.4.
- CVE-2025-55003MEDIUMCVSS 5.7EG 5.72025-08-09
OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. In versions 2.3.1 and below, OpenBao's Login Multi-Factor Authentication (MFA) system allows enforcing…
- CVE-2025-6015MEDIUMCVSS 5.7EG 5.72025-08-01
Vault and Vault Enterprise’s (“Vault”) login MFA rate limits could be bypassed and TOTP tokens could be reused. Fixed in Vault Community Edition 1.20.1 and Vault Enterprise 1.20.1, 1.19.7, 1.18.12, and 1.16.23.
- CVE-2021-36285MEDIUMCVSS 5.7EG 5.72021-09-28
Dell BIOS contains an Improper Restriction of Excessive Authentication Attempts vulnerability. A local authenticated malicious administrator could exploit this vulnerability to bypass excessive NVMe password attempt mitigations in order to…
- CVE-2021-36284MEDIUMCVSS 5.7EG 5.72021-09-28
Dell BIOS contains an Improper Restriction of Excessive Authentication Attempts vulnerability. A local authenticated malicious administrator could exploit this vulnerability to bypass excessive admin password attempt mitigations in order t…
- CVE-2025-62314MEDIUMCVSS 5.6EG 5.62026-08-13
HCL AION is affected by a vulnerability where certain endpoints lack sufficient anti-automation controls. Automated or scripted requests may be submitted without adequate rate limiting or challenge mechanisms, potentially resulting in unin…
- CVE-2022-28384MEDIUMCVSS 5.5EG 5.52022-06-08
An issue was discovered in certain Verbatim drives through 2022-03-31. Due to an insecure design, they allow an offline brute-force attack for determining the correct passcode, and thus gaining unauthorized access to the stored encrypted d…
- CVE-2022-26519MEDIUMCVSS 5.5EG 5.52022-04-20
There is no limit to the number of attempts to authenticate for the local configuration pages for the Hills ComNav Version 3002-19 interface, which allows local attackers to brute-force credentials.
- CVE-2021-29648MEDIUMCVSS 5.5EG 5.52021-03-30
An issue was discovered in the Linux kernel before 5.11.11. The BPF subsystem does not properly consider that resolved_ids and resolved_sizes are intentionally uninitialized in the vmlinux BPF Type Format (BTF), which can cause a system cr…
- CVE-2020-4891MEDIUMCVSS 5.5EG 5.52021-03-16
IBM Spectrum Scale 5.0.0 through 5.0.5.5 and 5.1.0 through 5.1.0.2 uses an inadequate account lockout setting that could allow a local user er to brute force Rest API account credentials. IBM X-Force ID: 190974.
- CVE-2020-15770MEDIUMCVSS 5.5EG 5.52020-09-18
An issue was discovered in Gradle Enterprise 2018.5. An attacker can potentially make repeated attempts to guess a local user's password, due to lack of lock-out after excessive failed logins.
- CVE-2017-16900MEDIUMCVSS 5.5EG 5.52020-02-27
Incorrect Access Control in Hunesion i-oneNet 3.0.6042.1200 allows the local user to access other user's information which is unauthorized via brute force.
- CVE-2019-5263MEDIUMCVSS 5.5EG 5.52019-11-29
HiSuite with 9.1.0.305 and earlier versions and 9.1.0.305(MAC) and earlier versions and HwBackup with earlier versions before 9.1.1.308 have a brute forcing encrypted backup data vulnerability. Huawei smartphone user backup information can…
- CVE-2026-15079MEDIUMCVSS 5.4EG 5.42026-07-10
Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Login Disable allows Brute Force. This issue affects Login Disable versions: from 0.0.0 to 2.1.4.
- CVE-2025-62313MEDIUMCVSS 5.4EG 5.42026-05-14
HCL AION is affected by a vulnerability where adequate protections against brute-force attempts are not enforced. This may allow repeated authentication attempts, potentially leading to unauthorized access or account compromise under certa…
- CVE-2025-52392MEDIUMCVSS 5.4EG 5.42025-08-13
Soosyze CMS 2.0 allows brute-force login attacks via the /user/login endpoint due to missing rate-limiting and lockout mechanisms. An attacker can repeatedly submit login attempts without restrictions, potentially gaining unauthorized admi…
- CVE-2023-34732MEDIUMCVSS 5.4EG 5.42025-05-12
An issue in the userId parameter in the change password function of Flytxt NEON-dX v0.0.1-SNAPSHOT-6.9-qa-2-9-g5502a0c allows attackers to execute brute force attacks to discover user passwords.
- CVE-2021-1311MEDIUMCVSS 5.4EG 5.42021-01-13
A vulnerability in the reclaim host role feature of Cisco Webex Meetings and Cisco Webex Meetings Server could allow an authenticated, remote attacker to take over the host role during a meeting. This vulnerability is due to a lack of prot…
- CVE-2026-56682MEDIUMCVSS 5.3EG 5.32026-09-22
9Router is an AI router & token saver. Prior to 0.5.6, 9Router deployments that allow requests to reach Next.js without the sanitizing custom-server.js wrapper use the client-supplied X-9r-Real-Ip value as the bucket key in getClientIp, ch…
- CVE-2026-77561MEDIUMCVSS 5.3EG 5.32026-09-21
Tinyauth is an authentication and authorization server. Prior to 5.1.0, an unauthenticated remote attacker can send POST /api/user/login requests with 257 distinct nonexistent usernames to fill MaxLoginAttemptRecords and activate a global …
- CVE-2026-75575MEDIUMCVSS 5.3EG 5.32026-08-25
Rocket.Chat exposes the sendForgotPasswordEmail Meteor method without a DDP rate limit, so an unauthenticated caller may invoke it as often as it likes. The method is reachable over DDP and over the HTTP route POST /api/v1/method.callAnon/…
- CVE-2026-21755MEDIUMCVSS 5.3EG 5.32026-08-24
HCL Hive is affected by a missing rate limit which could allow an attacker unauthorized access via brute-force or credential stuffing attacks, or cause a denial of service.
- CVE-2026-73529MEDIUMCVSS 5.3EG 5.32026-08-18
Plainpad through 1.1.1, fixed in commit d3823fc, contains a missing rate limiting vulnerability that allows unauthenticated attackers to send unbounded login requests to the POST /v1/sessions endpoint due to dead code in App\Http\Kernel.ph…
- CVE-2026-66340MEDIUMCVSS 5.3EG 5.32026-08-11
The Mira cloud authentication endpoints do not enforce per-account rate limiting, per-IP throttling, or account lockout after repeated failed login attempts. An attacker can use brute-force methods to obtain gain access to user accounts.
- CVE-2026-15144MEDIUMCVSS 5.3EG 5.32026-07-29
@fastify/rate-limit before 11.2.0 keys rate-limit buckets by the verbatim client IP string returned from request.ip. Because a single IPv6 client can control a large address range (a /64 holds 2^64 distinct addresses) and the same address …
- CVE-2026-62220MEDIUMCVSS 5.3EG 5.32026-07-17
OpenClaw 2026.2.25 before 2026.5.26 allow a lower-trust caller or configured input path to bypass non-browser rate limits on WebSocket authentication attempts. When the affected feature is enabled and reachable by lower-trust input, this c…
Map vulnerabilities like CWE-307 to your infrastructure
EchelonGraph correlates every CVE — across CWE-307 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →