CWE-307— Improper Restriction of Excessive Authentication Attempts
539 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-307page 10 of 11
- CVE-2025-46414HIGHCVSS 8.1EG 8.12025-08-08
The affected product does not limit the number of attempts for inputting the correct PIN for a registered product, which may allow an attacker to gain unauthorized access using brute-force methods if they possess a valid device serial n…
- CVE-2025-46603HIGHCVSS 7.0EG 7.02025-12-05
Dell CloudBoost Virtual Appliance, versions 19.13.0.0 and prior, contains an Improper Restriction of Excessive Authentication Attempts vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerabili…
- CVE-2025-46606MEDIUMCVSS 6.2EG 6.22026-04-17
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 contain an improper restriction of excessive authentication attempts vulnerability. A high privileged attacker with remote …
- CVE-2025-46739HIGHCVSS 8.1EG 8.12025-05-12
An unauthenticated user could discover account credentials via a brute-force attack without rate limiting
- CVE-2025-47951MEDIUMCVSS 4.9EG 4.92025-06-16
Weblate is a web based localization tool. Prior to version 5.12, the verification of the second factor was not subject to rate limiting. The absence of rate limiting on the second factor endpoint allows an attacker with valid credentials t…
- CVE-2025-48014HIGHCVSS 7.5EG 7.52025-05-20
Password guessing limits could be bypassed when using LDAP authentication.
- CVE-2025-48187CRITICALCVSS 9.1EG 9.12025-05-17
RAGFlow through 0.18.1 allows account takeover because it is possible to conduct successful brute-force attacks against email verification codes to perform arbitrary account registration, login, and password reset. Codes are six digits and…
- CVE-2025-49186MEDIUMCVSS 5.3EG 5.32025-06-12
The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it susceptible to brute-force attacks.
- CVE-2025-49195MEDIUMCVSS 5.3EG 5.32025-06-12
The FTP server’s login mechanism does not restrict authentication attempts, allowing an attacker to brute-force user passwords and potentially compromising the FTP server.
- CVE-2025-52392MEDIUMCVSS 5.4EG 5.42025-08-13
Soosyze CMS 2.0 allows brute-force login attacks via the /user/login endpoint due to missing rate-limiting and lockout mechanisms. An attacker can repeatedly submit login attempts without restrictions, potentially gaining unauthorized admi…
- CVE-2025-52916LOWCVSS 2.2EG 2.22025-06-21
Yealink RPS before 2025-06-04 lacks SN verification attempt limits, enabling brute-force enumeration (last five digits).
- CVE-2025-52997MEDIUMCVSS 5.9EG 5.92025-06-30
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Prior to version 2.34.1, a missing password policy and brute-force protection makes the auth…
- CVE-2025-53544HIGHCVSS 7.5EG 7.52025-08-05
Trilium Notes is an open-source, cross-platform hierarchical note taking application with focus on building large personal knowledge bases. In versions below 0.97.0, a brute-force protection bypass in the initial sync seed retrieval endpoi…
- CVE-2025-53968HIGHCVSS 7.5EG 7.52026-01-22
This vulnerability arises because there are no limitations on the number of authentication attempts a user can make. An attacker can exploit this weakness by continuously sending authentication requests, leading to a denial-of-service (…
- CVE-2025-54833MEDIUMCVSS 5.3EG 5.32025-07-31
OPEXUS FOIAXpress Public Access Link (PAL) version v11.1.0 allows attackers to bypass account-lockout and CAPTCHA protections. Unauthenticated remote attackers can more easily brute force passwords.
- CVE-2025-54860HIGHCVSS 7.7EG 7.72025-09-18
Cognex In-Sight Explorer and In-Sight Camera Firmware expose a telnet-based service on port 23 in order to allow management operations on the device such as firmware upgrades and device reboot requiring an authentication. A wrong managem…
- CVE-2025-54998MEDIUMCVSS 5.3EG 5.32025-08-09
OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. In versions 0.1.0 through 2.3.1, attackers could bypass the automatic user lockout mechanisms in the O…
- CVE-2025-55003MEDIUMCVSS 5.7EG 5.72025-08-09
OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. In versions 2.3.1 and below, OpenBao's Login Multi-Factor Authentication (MFA) system allows enforcing…
- CVE-2025-56221CRITICALCVSS 9.8EG 9.82025-10-17
A lack of rate limiting in the login mechanism of SigningHub v8.6.8 allows attackers to bypass authentication via a brute force attack.
- CVE-2025-56224HIGHCVSS 8.1EG 6.52025-10-20
A lack of rate limiting in the One-Time Password (OTP) verification endpoint of SigningHub v8.6.8 allows attackers to bypass verification via a bruteforce attack.
- CVE-2025-57815MEDIUMCVSS 6.5EG 6.52025-09-08
Fides is an open-source privacy engineering platform. Prior to version 2.69.1, the Fides Admin UI login endpoint relies on a general IP-based rate limit for all API traffic and lacks specific anti-automation controls designed to protect ag…
- CVE-2025-58587MEDIUMCVSS 6.5EG 6.52025-10-06
The application does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it possible for an attacker to guess user credentials.
- CVE-2025-5864LOWCVSS 3.7EG 3.72025-06-09
A vulnerability was found in Tenda TDSEE App up to 1.7.12. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /app/ConfirmSmsCode of the component Password Reset Confirmation Code Ha…
- CVE-2025-59113HIGHCVSS 7.5EG 7.52025-11-18
Windu CMS implements weak client-side brute-force protection by using parameter loginError. Information about attempt count or timeout is not stored on the server, which allows a malicious attacker to bypass this brute-force protection by…
- CVE-2025-6004MEDIUMCVSS 5.3EG 5.32025-08-01
Vault and Vault Enterprise’s (“Vault”) user lockout feature could be bypassed for Userpass and LDAP authentication methods. Fixed in Vault Community Edition 1.20.1 and Vault Enterprise 1.20.1, 1.19.7, 1.18.12, and 1.16.23.
- CVE-2025-6015MEDIUMCVSS 5.7EG 5.72025-08-01
Vault and Vault Enterprise’s (“Vault”) login MFA rate limits could be bypassed and TOTP tokens could be reused. Fixed in Vault Community Edition 1.20.1 and Vault Enterprise 1.20.1, 1.19.7, 1.18.12, and 1.16.23.
- CVE-2025-6029CRITICALCVSS 9.4EG 0.02025-06-13
Use of fixed learning codes, one code to lock the car and the other code to unlock it, the Key Fob Transmitter in KIA-branded Aftermarket Generic Smart Keyless Entry System, primarily distributed in Ecuador, which allows a replay attack.…
- CVE-2025-6030CRITICALCVSS 9.4EG 0.02025-06-13
Use of fixed learning codes, one code to lock the car and the other code to unlock it, in the Key Fob Transmitter in Cyclone Matrix TRF Smart Keyless Entry System, which allows a replay attack. Research was completed on the 2024 KIA So…
- CVE-2025-60424HIGHCVSS 7.6EG 7.62025-10-27
A lack of rate limiting in the OTP verification component of Nagios Fusion v2024R1.2 and v2024R2 allows attackers to bypass authentication via a bruteforce attack.
- CVE-2025-62257MEDIUMCVSS 5.3EG 5.32025-10-30
Password enumeration vulnerability in Liferay Portal 7.4.0 through 7.4.3.119, and older unsupported versions, and Liferay DXP 2024.Q1.1 through 2024.Q1.5, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92…
- CVE-2025-62313MEDIUMCVSS 5.4EG 5.42026-05-14
HCL AION is affected by a vulnerability where adequate protections against brute-force attempts are not enforced. This may allow repeated authentication attempts, potentially leading to unauthorized access or account compromise under certa…
- CVE-2025-62399HIGHCVSS 7.5EG 7.52025-10-23
Moodle’s mobile and web service authentication endpoints did not sufficiently restrict repeated password attempts, making them susceptible to brute-force attacks.
- CVE-2025-63807CRITICALCVSS 9.8EG 7.52025-11-20
An issue was discovered in weijiang1994 university-bbs (aka Blogin) in commit 9e06bab430bfc729f27b4284ba7570db3b11ce84 (2025-01-13). A weak verification code generation mechanism combined with missing rate limiting allows attackers to perf…
- CVE-2025-64102CRITICALCVSS 9.8EG 9.82025-10-29
Zitadel is open-source identity infrastructure software. Prior to 4.6.0, 3.4.3, and 2.71.18, an attacker can perform an online brute-force attack on OTP, TOTP, and passwords. While Zitadel allows preventing online brute force attacks in sc…
- CVE-2025-64310CRITICALCVSS 9.8EG 9.82025-11-21
EPSON WebConfig and Epson Web Control for SEIKO EPSON Projector Products do not restrict excessive authentication attempts. An administrative user's password may be identified through a brute force attack.
- CVE-2025-64526MEDIUMCVSS 5.3EG 5.32026-05-14
Strapi is an open source headless content management system. In Strapi versions prior to 5.45.0, the rate-limit middleware in the users-permissions plugin derived its rate-limit key in part from `ctx.request.body.email`, including on route…
- CVE-2025-6533MEDIUMCVSS 5.6EG 5.62025-06-24
A vulnerability, which was classified as critical, has been found in xxyopen/201206030 novel-plus up to 5.1.3. Affected by this issue is the function ajaxLogin of the file novel-admin/src/main/java/com/java2nb/system/controller/LoginContro…
- CVE-2025-65427MEDIUMCVSS 6.5EG 6.52025-12-16
An issue was discovered in Dbit N300 T1 Pro Easy Setup Wireless Wi-Fi Router on firmware version V1.0.0 does not implement rate limiting to /api/login allowing attackers to brute force password enumerations.
- CVE-2025-66204HIGHCVSS 8.1EG 8.12025-12-09
WBCE CMS is a content management system. Version 1.6.4 contains a brute-force protection bypass where an attacker can indefinitely reset the counter by modifying `X-Forwarded-For` on each request, gaining unlimited password guessing attemp…
- CVE-2025-66482MEDIUMCVSS 6.5EG 6.52025-12-16
Misskey is an open source, federated social media platform. Attackers who use an untrusted reverse proxy or not using a reverse proxy at all can bypass IP rate limiting by adding a forged X-Forwarded-For header. Starting with version 2025.…
- CVE-2025-67090MEDIUMCVSS 5.1EG 5.12026-01-08
The LuCI web interface on Gl Inet GL.Inet AX1800 Version 4.6.4 & 4.6.8 are vulnerable. Fix available in version 4.8.2 GL.Inet AX1800 Version 4.6.4 & 4.6.8 lacks rate limiting or account lockout mechanisms on the authentication endpoint (`/…
- CVE-2025-67091MEDIUMCVSS 6.5EG 6.52026-01-08
An issue in GL Inet GL.Inet AX1800 Version 4.6.4 & 4.6.8 are vulnerable. GL.Inet AX1800 Version 4.6.4 & 4.6.8 in the GL.iNet custom opkg wrapper script located at /usr/libexec/opkg-call. The script is executed with root privileges when tri…
- CVE-2025-67853HIGHCVSS 7.5EG 7.52026-02-03
A flaw was found in Moodle. A remote attacker could exploit a lack of proper rate limiting in the confirmation email service. This vulnerability allows attackers to more easily enumerate or guess user credentials, facilitating brute-force …
- CVE-2025-7393CRITICALCVSS 9.8EG 9.82025-07-21
Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Mail Login allows Brute Force.This issue affects Mail Login: from 3.0.0 before 3.2.0, from 4.0.0 before 4.2.0.
- CVE-2025-7882LOWCVSS 3.1EG 3.12025-07-20
A vulnerability was found in Mercusys MW301R 1.0.2 Build 190726 Rel.59423n. It has been rated as problematic. This issue affects some unknown processing of the component Login. The manipulation leads to improper restriction of excessive au…
- CVE-2025-8118MEDIUMCVSS 6.5EG 6.52025-09-30
PAD CMS implements weak client-side brute-force protection by utilizing two cookies: login_count and login_timeout. Information about attempt count or timeout is not stored on the server, which allows a malicious attacker to bypass th…
- CVE-2025-8679CRITICALCVSS 9.8EG 9.82025-10-01
In ExtremeGuest Essentials before 25.5.0, captive-portal may permit unauthorized access via manual brute-force procedure. Under certain ExtremeGuest Essentials captive-portal SSID configurations, repeated manual login attempts may allow an…
- CVE-2025-8742LOWCVSS 3.7EG 3.72025-08-08
A vulnerability was found in macrozheng mall 1.0.3. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Admin Login. The manipulation leads to improper restriction of excessive authentica…
- CVE-2025-8927LOWCVSS 3.7EG 3.72025-08-13
A vulnerability was determined in mtons mblog up to 3.5.0. Affected by this issue is some unknown functionality of the file /email/send_code of the component Verification Code Handler. The manipulation of the argument email leads to improp…
- CVE-2025-9004LOWCVSS 3.7EG 3.72025-08-15
A vulnerability was found in mtons mblog up to 3.5.0. This issue affects some unknown processing of the file /settings/password. The manipulation leads to improper restriction of excessive authentication attempts. The attack may be initiat…
Map vulnerabilities like CWE-307 to your infrastructure
EchelonGraph correlates every CVE — across CWE-307 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →