CWE-307— Improper Restriction of Excessive Authentication Attempts
539 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-307page 6 of 11
- CVE-2023-25820MEDIUMCVSS 4.2EG 4.22023-03-22
Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform, and Nextcloud Enterprise Server is the enterprise version of the file server software. In Nextcloud Server versions 25.0.x prior to 25.0.5 and…
- CVE-2023-26208LOWCVSS 3.7EG 5.32023-03-09
A improper restriction of excessive authentication attempts vulnerability [CWE-307] in Fortinet FortiAuthenticator 6.4.x and before allows a remote unauthenticated attacker to partially exhaust CPU and memory via sending numerous HTTP re…
- CVE-2023-26209LOWCVSS 3.7EG 5.32023-03-09
A improper restriction of excessive authentication attempts vulnerability [CWE-307] in Fortinet FortiDeceptor 3.1.x and before allows a remote unauthenticated attacker to partially exhaust CPU and memory via sending numerous HTTP request…
- CVE-2023-26271MEDIUMCVSS 5.3EG 5.32023-08-28
IBM Security Guardium Data Encryption (IBM Guardium Cloud Key Manager (GCKM) 1.10.3)) uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 248126.
- CVE-2023-26476HIGHCVSS 7.5EG 7.52023-03-02
XWiki Platform is a generic wiki platform. Starting in version 3.2-m3, users can deduce the content of the password fields by repeated call to `LiveTableResults` and `WikisLiveTableResultsMacros`. The issue can be fixed by upgrading to ver…
- CVE-2023-2675CRITICALCVSS 9.8EG 9.82023-11-07
Improper Restriction of Excessive Authentication Attempts in GitHub repository linagora/twake prior to 2023.Q1.1223.
- CVE-2023-26756HIGHCVSS 7.5EG 7.52023-04-14
The login page of Revive Adserver v5.4.1 is vulnerable to brute force attacks. NOTE: The vendor's position is that this is effectively mitigated by rate limits and password-quality features.
- CVE-2023-27100CRITICALCVSS 9.8EG 9.82023-03-22
Improper restriction of excessive authentication attempts in the SSHGuard component of Netgate pfSense Plus software v22.05.1 and pfSense CE software v2.6.0 allows attackers to bypass brute force protection mechanisms via crafted web reque…
- CVE-2023-27152CRITICALCVSS 9.8EG 9.82023-10-23
DECISO OPNsense 23.1 does not impose rate limits for authentication, allowing attackers to perform a brute-force attack to bypass authentication.
- CVE-2023-27172CRITICALCVSS 9.1EG 9.12023-12-20
Xpand IT Write-back Manager v2.3.1 uses weak secret keys to sign JWT tokens. This allows attackers to easily obtain the secret key used to sign JWT tokens via a bruteforce attack.
- CVE-2023-27746CRITICALCVSS 9.8EG 9.82023-04-13
BlackVue DR750-2CH LTE v.1.012_2022.10.26 was discovered to contain a weak default passphrase which can be easily cracked via a brute force attack if the WPA2 handshake is intercepted.
- CVE-2023-28847LOWCVSS 3.1EG 3.12023-04-25
Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. In Nextcloud Server 24.0.0 prior to 24.0.11 and 25.0.0 prior to 25.0.5; as well as Nextcloud Server Enterprise 23.0.0 prior to 23.0.12.6, 24.0…
- CVE-2023-29005HIGHCVSS 7.5EG 7.52023-04-10
Flask-AppBuilder versions before 4.3.0 lack rate limiting which can allow an attacker to brute-force user credentials. Version 4.3.0 includes the ability to enable rate limiting using `AUTH_RATE_LIMITED = True`, `RATELIMIT_ENABLED = True`,…
- CVE-2023-29301HIGHCVSS 7.5EG 7.52023-07-12
Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0.0.330468 (and earlier) are affected by an Improper Restriction of Excessive Authentication Attempts vulnerability that could result in a Security feature bypa…
- CVE-2023-3173CRITICALCVSS 9.8EG 9.82023-06-09
Improper Restriction of Excessive Authentication Attempts in GitHub repository froxlor/froxlor prior to 2.0.20.
- CVE-2023-32074HIGHCVSS 8.0EG 8.02023-05-25
user_oidc app is an OpenID Connect user backend for Nextcloud. Authentication can be broken/bypassed in user_oidc app. It is recommended that the Nextcloud user_oidc app is upgraded to 1.3.2
- CVE-2023-32224CRITICALCVSS 9.8EG 9.82023-06-28
D-Link DSL-224 firmware version 3.0.10 CWE-307: Improper Restriction of Excessive Authentication Attempts
- CVE-2023-32251LOWCVSS 3.7EG 3.72025-07-31
A vulnerability has been identified in the Linux kernel's ksmbd component (kernel SMB/CIFS server). A security control designed to prevent dictionary attacks, which introduces a 5-second delay during session setup, can be bypassed through …
- CVE-2023-32319HIGHCVSS 8.1EG 8.12023-05-26
Nextcloud server is an open source personal cloud implementation. Missing brute-force protection on the WebDAV endpoints via the basic auth header allowed to brute-force user credentials when the provided user name was not an email address…
- CVE-2023-32320HIGHCVSS 8.7EG 8.72023-06-22
Nextcloud Server is a data storage system for Nextcloud, a self-hosted productivity platform. When multiple requests are sent in parallel, all of them were executed even if the amount of faulty requests succeeded the limit by the time the …
- CVE-2023-32657MEDIUMCVSS 5.3EG 5.32023-07-19
Weintek Weincloud v0.13.6 could allow an attacker to efficiently develop a brute force attack on credentials with authentication hints from error message responses.
- CVE-2023-33754MEDIUMCVSS 6.5EG 6.52023-06-01
The captive portal in Inpiazza Cloud WiFi versions prior to v4.2.17 does not enforce limits on the number of attempts for password recovery, allowing attackers to brute force valid user accounts to gain access to login credentials.
- CVE-2023-33759CRITICALCVSS 9.8EG 9.82024-01-25
SpliceCom Maximiser Soft PBX v1.5 and before does not restrict excessive authentication attempts, allowing attackers to bypass authentication via a brute force attack.
- CVE-2023-33868MEDIUMCVSS 5.9EG 5.92023-07-06
The number of login attempts is not limited. This could allow an attacker to perform a brute force on HTTP basic authentication.
- CVE-2023-34001MEDIUMCVSS 5.3EG 5.32024-06-04
Improper Restriction of Excessive Authentication Attempts vulnerability in WPPlugins – WordPress Security Plugins Hide My WP Ghost allows Functionality Bypass.This issue affects Hide My WP Ghost: from n/a through 5.0.25.
- CVE-2023-34243MEDIUMCVSS 5.8EG 5.82023-06-08
TGstation is a toolset to manage production BYOND servers. In affected versions if a Windows user was registered in tgstation-server (TGS), an attacker could discover their username by brute-forcing the login endpoint with an invalid passw…
- CVE-2023-34732MEDIUMCVSS 5.4EG 5.42025-05-12
An issue in the userId parameter in the change password function of Flytxt NEON-dX v0.0.1-SNAPSHOT-6.9-qa-2-9-g5502a0c allows attackers to execute brute force attacks to discover user passwords.
- CVE-2023-35039CRITICALCVSS 9.8EG 9.82023-12-07
Improper Restriction of Excessive Authentication Attempts vulnerability in Be Devious Web Development Password Reset with Code for WordPress REST API allows Authentication Abuse.This issue affects Password Reset with Code for WordPress RES…
- CVE-2023-35172HIGHCVSS 8.7EG 8.72023-06-23
NextCloud Server and NextCloud Enterprise Server provide file storage for Nextcloud, a self-hosted productivity platform. In NextCloud Server versions 25.0.0 until 25.0.7 and 26.0.0 until 26.0.2 and Nextcloud Enterprise Server versions 21.…
- CVE-2023-3548HIGHCVSS 8.3EG 8.32023-07-25
An unauthorized user could gain account access to IQ Wifi 6 versions prior to 2.0.2 by conducting a brute force authentication attack.
- CVE-2023-35697MEDIUMCVSS 5.3EG 5.32023-07-10
Improper Restriction of Excessive Authentication Attempts in the SICK ICR890-4 could allow a remote attacker to brute-force user credentials.
- CVE-2023-3605MEDIUMCVSS 6.5EG 6.52023-07-10
A vulnerability was found in PHPGurukul Online Shopping Portal 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Registration Page. The manipulation leads to improper restric…
- CVE-2023-36434CRITICALCVSS 9.8EG 9.82023-10-10
Windows IIS Server Elevation of Privilege Vulnerability
- CVE-2023-3669LOWCVSS 3.3EG 3.32023-08-03
A missing Brute-Force protection in CODESYS Development System prior to 3.5.19.20 allows a local attacker to have unlimited attempts of guessing the password within an import dialog.
- CVE-2023-36917MEDIUMCVSS 5.9EG 5.92023-07-11
SAP BusinessObjects Business Intelligence Platform - version 420, 430, allows an unauthorized attacker who had hijacked a user session, to be able to bypass the victim’s old password via brute force, due to unrestricted rate limit for pa…
- CVE-2023-37635CRITICALCVSS 9.8EG 9.82023-10-23
UVDesk Community Skeleton v1.1.1 allows unauthenticated attackers to perform brute force attacks on the login page to gain access to the application.
- CVE-2023-37832HIGHCVSS 7.5EG 7.52023-10-31
A lack of rate limiting in Elenos ETG150 FM transmitter v3.12 allows attackers to obtain user credentials via brute force and cause other unspecified impacts.
- CVE-2023-38273HIGHCVSS 7.5EG 7.52024-02-02
IBM Cloud Pak System 2.3.1.1, 2.3.2.0, and 2.3.3.7 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 260733.
- CVE-2023-39958MEDIUMCVSS 5.8EG 5.82023-08-10
Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 22.0.0 and prior to versions 22.2.10.13, 23.0.12.8, 24.0.12.5, 25.0.9, 26.0.4, and 27.0.1, missing protection allows an attacker to br…
- CVE-2023-39960MEDIUMCVSS 5.0EG 5.02023-10-13
Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. In Nextcloud Server starting with 25.0.0 and prior to 25.09 and 26.04; as well as Nextcloud Enterprise Server starting with 22.0.0 and prior to 22.2.10.14…
- CVE-2023-40706HIGHCVSS 8.6EG 8.62023-08-24
There is no limit on the number of login attempts in the web server for the SNAP PAC S1 Firmware version R10.3b. This could allow for a brute-force attack on the built-in web server login.
- CVE-2023-40834CRITICALCVSS 9.8EG 9.82023-09-12
OpenCart CMS v4.0.2.2 was discovered to lack a protective mechanism on its login page against excessive login attempts, allowing unauthenticated attackers to gain access to the application via a brute force attack to the password parameter.
- CVE-2023-41270LOWCVSS 3.5EG 3.52023-11-08
Improper Restriction of Excessive Authentication Attempts vulnerability in Samsung Smart TV UE40D7000 version T-GAPDEUC-1033.2 and before allows attackers to cause a denial of service via WPS attack tools.
- CVE-2023-41350HIGHCVSS 7.5EG 7.52023-11-03
Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of insufficient measures to prevent multiple failed authentication attempts. An unauthenticated remote attacker can execute a crafted Javascript to expose captcha in page, making it very …
- CVE-2023-42480MEDIUMCVSS 5.3EG 5.32023-11-14
The unauthenticated attacker in NetWeaver AS Java Logon application - version 7.50, can brute force the login functionality to identify the legitimate user ids. This will have an impact on confidentiality but there is no other impact on i…
- CVE-2023-42769CRITICALCVSS 9.8EG 9.82023-10-26
The cookie session ID is of insufficient length and can be exploited by brute force, which may allow a remote attacker to obtain a valid session, bypass authentication, and manipulate the transmitter.
- CVE-2023-42818MEDIUMCVSS 5.4EG 5.42023-09-27
JumpServer is an open source bastion host. When users enable MFA and use a public key for authentication, the Koko SSH server does not verify the corresponding SSH private key. An attacker could exploit a vulnerability by utilizing a discl…
- CVE-2023-43699HIGHCVSS 7.5EG 7.52023-10-09
Improper Restriction of Excessive Authentication Attempts in RDT400 in SICK APU allows an unprivileged remote attacker to guess the password via trial-and-error as the login attempts are not limited.
- CVE-2023-44096HIGHCVSS 7.5EG 7.52023-10-11
Vulnerability of brute-force attacks on the device authentication module.Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2023-44111HIGHCVSS 7.5EG 7.52023-10-11
Vulnerability of brute-force attacks on the device authentication module.Successful exploitation of this vulnerability may affect service confidentiality.
Map vulnerabilities like CWE-307 to your infrastructure
EchelonGraph correlates every CVE — across CWE-307 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →