CWE-307— Improper Restriction of Excessive Authentication Attempts
The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.— MITRE CWE catalog
689 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-307page 7 of 14
- CVE-2026-32292HIGHCVSS 7.5EG 7.52026-03-17
The GL-iNet Comet (GL-RM1) KVM web interface does not limit login requests, enabling brute-force attempts to guess credentials.
- CVE-2026-24696HIGHCVSS 7.5EG 7.52026-03-06
The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks by suppressing or mis-routing legitimate …
- CVE-2026-20882HIGHCVSS 7.5EG 7.52026-03-06
The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks by suppressing or mis-routing legitimate …
- CVE-2026-27778HIGHCVSS 7.5EG 7.52026-03-06
The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks by suppressing or mis-routing legitimate …
- CVE-2025-36363HIGHCVSS 7.5EG 7.52026-03-03
IBM DevOps Plan 3.0.0 through 3.0.5 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials.
- CVE-2026-27521HIGHCVSS 7.5EG 7.52026-02-24
Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior do not implement rate limiting or account lockout on failed login attempts, enabling brute-force attacks against user credentials.
- CVE-2026-25577HIGHCVSS 7.5EG 7.52026-02-10
Emmett is a framework designed to simplify your development process. Prior to 1.3.11, the cookies property in mmett_core.http.wrappers.Request does not handle CookieError exceptions when parsing malformed Cookie headers. This allows unauth…
- CVE-2025-67853HIGHCVSS 7.5EG 7.52026-02-03
A flaw was found in Moodle. A remote attacker could exploit a lack of proper rate limiting in the confirmation email service. This vulnerability allows attackers to more easily enumerate or guess user credentials, facilitating brute-force …
- CVE-2025-53968HIGHCVSS 7.5EG 7.52026-01-22
This vulnerability arises because there are no limitations on the number of authentication attempts a user can make. An attacker can exploit this weakness by continuously sending authentication requests, leading to a denial-of-service (…
- CVE-2025-59113HIGHCVSS 7.5EG 7.52025-11-18
Windu CMS implements weak client-side brute-force protection by using parameter loginError. Information about attempt count or timeout is not stored on the server, which allows a malicious attacker to bypass this brute-force protection by…
- CVE-2025-62399HIGHCVSS 7.5EG 7.52025-10-23
Moodle’s mobile and web service authentication endpoints did not sufficiently restrict repeated password attempts, making them susceptible to brute-force attacks.
- CVE-2025-35041HIGHCVSS 7.5EG 7.52025-09-22
Airship AI Acropolis allows unlimited MFA attempts for 15 minutes after a user has logged in with valid credentials. A remote attacker with valid credentials could brute-force the 6-digit MFA code. Fixed in 10.2.35, 11.0.21, and 11.1.9.
- CVE-2025-53544HIGHCVSS 7.5EG 7.52025-08-05
Trilium Notes is an open-source, cross-platform hierarchical note taking application with focus on building large personal knowledge bases. In versions below 0.97.0, a brute-force protection bypass in the initial sync seed retrieval endpoi…
- CVE-2024-49342HIGHCVSS 7.5EG 7.52025-07-28
IBM Informix Dynamic Server 12.10 and 14.10 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials.
- CVE-2025-27456HIGHCVSS 7.5EG 7.52025-07-03
The SMB server's login mechanism does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it susceptible to brute-force attacks.
- CVE-2025-27449HIGHCVSS 7.5EG 7.52025-07-03
The MEAC300-FNADE4 does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it susceptible to brute-force attacks.
- CVE-2025-1710HIGHCVSS 7.5EG 7.52025-07-03
The maxView Storage Manager does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it susceptible to brute-force attacks.
- CVE-2025-48014HIGHCVSS 7.5EG 7.52025-05-20
Password guessing limits could be bypassed when using LDAP authentication.
- CVE-2024-51476HIGHCVSS 7.5EG 7.52025-03-06
IBM Concert Software 1.0.5 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials.
- CVE-2024-57610HIGHCVSS 7.5EG 7.52025-02-06
A rate limiting issue in Sylius v2.0.2 allows a remote attacker to perform unrestricted brute-force attacks on user accounts, significantly increasing the risk of account compromise and denial of service for legitimate users. The Supplier'…
- CVE-2024-55008HIGHCVSS 7.5EG 7.52025-01-07
JATOS 3.9.4 contains a denial-of-service (DoS) vulnerability in the authentication system, where an attacker can prevent legitimate users from accessing their accounts by repeatedly sending multiple failed login attempts. Specifically, by …
- CVE-2024-7292HIGHCVSS 7.5EG 7.52024-10-09
In Progress® Telerik® Report Server versions prior to 2024 Q3 (10.2.24.806), a credential stuffing attack is possible through improper restriction of excessive login attempts.
- CVE-2024-45327HIGHCVSS 7.5EG 7.52024-09-11
An improper authorization vulnerability [CWE-285] in FortiSOAR version 7.4.0 through 7.4.3, 7.3.0 through 7.3.2, 7.2.0 through 7.2.2, 7.0.0 through 7.0.3 change password endpoint may allow an authenticated attacker to perform a brute force…
- CVE-2024-41904HIGHCVSS 7.5EG 7.52024-08-13
A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V2.0). The affected application do not properly enforce restriction of excessive authentication attempts. This could allow an unauthenticat…
- CVE-2024-39874HIGHCVSS 7.5EG 7.52024-07-09
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The affected application does not properly implement brute force protection against user credentials in its Client Communication component. This…
- CVE-2024-39873HIGHCVSS 7.5EG 7.52024-07-09
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The affected application does not properly implement brute force protection against user credentials in its web API. This could allow an attacke…
- CVE-2024-5862HIGHCVSS 7.5EG 7.52024-06-24
Improper Restriction of Excessive Authentication Attempts vulnerability in Mia Technology Inc. Mia-Med Health Aplication allows Interface Manipulation. This issue affects Mia-Med Health Aplication: before 1.0.14.
- CVE-2024-21662HIGHCVSS 7.5EG 7.52024-03-18
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior to versions 2.8.13, 2.9.9, and 2.10.4, an attacker can effectively bypass the rate limit and brute force protections by exploiting the application's weak cache…
- CVE-2024-1104HIGHCVSS 7.5EG 7.52024-02-22
An unauthenticated remote attacker can bypass the brute force prevention mechanism and disturb the webservice for all users.
- CVE-2023-45191HIGHCVSS 7.5EG 7.52024-02-09
IBM Engineering Lifecycle Optimization 7.0.2 and 7.0.3 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 268755.
- CVE-2023-38273HIGHCVSS 7.5EG 7.52024-02-02
IBM Cloud Pak System 2.3.1.1, 2.3.2.0, and 2.3.3.7 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 260733.
- CVE-2023-50326HIGHCVSS 7.5EG 7.52024-02-02
IBM PowerSC 1.3, 2.0, and 2.1 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 275107.
- CVE-2023-50444HIGHCVSS 7.5EG 7.52023-12-13
By default, .ZED containers produced by PRIMX ZED! for Windows before Q.2020.3 (ANSSI qualification submission); ZED! for Windows before Q.2021.2 (ANSSI qualification submission); ZONECENTRAL for Windows before Q.2021.2 (ANSSI qualificatio…
- CVE-2023-46745HIGHCVSS 7.5EG 7.52023-11-17
LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring which includes support for a wide range of network hardware and operating systems. In affected versions the login method has no rate limit. An attacker may be able to …
- CVE-2023-37832HIGHCVSS 7.5EG 7.52023-10-31
A lack of rate limiting in Elenos ETG150 FM transmitter v3.12 allows attackers to obtain user credentials via brute force and cause other unspecified impacts.
- CVE-2015-20110HIGHCVSS 7.5EG 7.52023-10-31
JHipster generator-jhipster before 2.23.0 allows a timing attack against validateToken due to a string comparison that stops at the first character that is different. Attackers can guess tokens by brute forcing one character at a time and …
- CVE-2023-44111HIGHCVSS 7.5EG 7.52023-10-11
Vulnerability of brute-force attacks on the device authentication module.Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2023-44096HIGHCVSS 7.5EG 7.52023-10-11
Vulnerability of brute-force attacks on the device authentication module.Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2023-43699HIGHCVSS 7.5EG 7.52023-10-09
Improper Restriction of Excessive Authentication Attempts in RDT400 in SICK APU allows an unprivileged remote attacker to guess the password via trial-and-error as the login attempts are not limited.
- CVE-2022-43904HIGHCVSS 7.5EG 7.52023-08-28
IBM Security Guardium 11.3 and 11.4 could disclose sensitive information to an attacker due to improper restriction of excessive authentication attempts. IBM X-Force ID: 240895.
- CVE-2022-32757HIGHCVSS 7.5EG 7.52023-06-15
IBM Security Directory Suite VA 8.0.1 through 8.0.1.19 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 228510.
- CVE-2023-23755HIGHCVSS 7.5EG 7.52023-05-30
An issue was discovered in Joomla! 4.2.0 through 4.3.1. The lack of rate limiting allowed brute force attacks against MFA methods.
- CVE-2022-43377HIGHCVSS 7.5EG 7.52023-04-18
A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could cause account takeover when a brute force attack is performed on the account. Affected Products: NetBotz 4 - 355/450/455/550/570�…
- CVE-2023-26756HIGHCVSS 7.5EG 7.52023-04-14
The login page of Revive Adserver v5.4.1 is vulnerable to brute force attacks. NOTE: The vendor's position is that this is effectively mitigated by rate limits and password-quality features.
- CVE-2023-29005HIGHCVSS 7.5EG 7.52023-04-10
Flask-AppBuilder versions before 4.3.0 lack rate limiting which can allow an attacker to brute-force user credentials. Version 4.3.0 includes the ability to enable rate limiting using `AUTH_RATE_LIMITED = True`, `RATELIMIT_ENABLED = True`,…
- CVE-2023-26476HIGHCVSS 7.5EG 7.52023-03-02
XWiki Platform is a generic wiki platform. Starting in version 3.2-m3, users can deduce the content of the password fields by repeated call to `LiveTableResults` and `WikisLiveTableResultsMacros`. The issue can be fixed by upgrading to ver…
- CVE-2023-0860HIGHCVSS 7.5EG 7.52023-02-16
Improper Restriction of Excessive Authentication Attempts in GitHub repository modoboa/modoboa-installer prior to 2.0.4.
- CVE-2023-25156HIGHCVSS 7.5EG 7.52023-02-15
Kiwi TCMS, an open source test management system, does not impose rate limits in versions prior to 12.0. This makes it easier to attempt brute-force attacks against the login page. Users should upgrade to v12.0 or later to receive a patch.…
- CVE-2023-22960HIGHCVSS 7.5EG 7.52023-01-23
Lexmark products through 2023-01-10 have Improper Control of Interaction Frequency.
- CVE-2022-23746HIGHCVSS 7.5EG 7.52022-11-30
The IPsec VPN blade has a dedicated portal for downloading and connecting through SSL Network Extender (SNX). If the portal is configured for username/password authentication, it is vulnerable to a brute-force attack on usernames and passw…
Map vulnerabilities like CWE-307 to your infrastructure
EchelonGraph correlates every CVE — across CWE-307 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →