CWE-307— Improper Restriction of Excessive Authentication Attempts
The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.— MITRE CWE catalog
613 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-307page 6 of 13
- CVE-2023-0860HIGHCVSS 7.5EG 7.52023-02-16
Improper Restriction of Excessive Authentication Attempts in GitHub repository modoboa/modoboa-installer prior to 2.0.4.
- CVE-2023-1101HIGHCVSS 8.8EG 8.82023-03-02
SonicOS SSLVPN improper restriction of excessive MFA attempts vulnerability allows an authenticated attacker to use excessive MFA codes.
- CVE-2023-1539MEDIUMCVSS 5.3EG 5.32023-03-21
Improper Restriction of Excessive Authentication Attempts in GitHub repository answerdev/answer prior to 1.0.6.
- CVE-2023-1665CRITICALCVSS 9.8EG 9.82023-03-27
Improper Restriction of Excessive Authentication Attempts in GitHub repository linagora/twake prior to 0.0.0.
- CVE-2023-21709CRITICALCVSS 9.8EG 9.82023-08-08
Microsoft Exchange Server Elevation of Privilege Vulnerability
- CVE-2023-22960HIGHCVSS 7.5EG 7.52023-01-23
Lexmark products through 2023-01-10 have Improper Control of Interaction Frequency.
- CVE-2023-23730MEDIUMCVSS 5.3EG 5.32024-06-03
Improper Restriction of Excessive Authentication Attempts vulnerability in Brainstorm Force Spectra allows Functionality Bypass.This issue affects Spectra: from n/a through 2.3.0.
- CVE-2023-23755HIGHCVSS 7.5EG 7.52023-05-30
An issue was discovered in Joomla! 4.2.0 through 4.3.1. The lack of rate limiting allowed brute force attacks against MFA methods.
- CVE-2023-24020CRITICALCVSS 7.5EG 9.82023-01-30
Snap One Wattbox WB-300-IP-3 versions WB10.9a17 and prior could bypass the brute force protection, allowing multiple attempts to force a login.
- CVE-2023-24051CRITICALCVSS 9.8EG 9.82023-12-04
A client side rate limit issue discovered in Connectize AC21000 G6 641.139.1.1256 allows attackers to gain escalated privileges via brute force style attacks.
- CVE-2023-24080CRITICALCVSS 9.8EG 9.82023-02-21
A lack of rate limiting on the password reset endpoint of Chamberlain myQ v5.222.0.32277 (on iOS) allows attackers to compromise user accounts via a bruteforce attack.
- CVE-2023-25156HIGHCVSS 7.5EG 7.52023-02-15
Kiwi TCMS, an open source test management system, does not impose rate limits in versions prior to 12.0. This makes it easier to attempt brute-force attacks against the login page. Users should upgrade to v12.0 or later to receive a patch.…
- CVE-2023-2531CRITICALCVSS 9.8EG 9.82023-05-05
Improper Restriction of Excessive Authentication Attempts in GitHub repository azuracast/azuracast prior to 0.18.3.
- CVE-2023-25818MEDIUMCVSS 5.3EG 5.32023-03-27
Nextcloud server is an open source, personal cloud implementation. In affected versions a malicious user could try to reset the password of another user and then brute force the 62^21 combinations for the password reset token. As of commit…
- CVE-2023-25820MEDIUMCVSS 4.2EG 4.22023-03-22
Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform, and Nextcloud Enterprise Server is the enterprise version of the file server software. In Nextcloud Server versions 25.0.x prior to 25.0.5 and…
- CVE-2023-26208MEDIUMCVSS 3.7EG 5.32023-03-09
A improper restriction of excessive authentication attempts vulnerability [CWE-307] in Fortinet FortiAuthenticator 6.4.x and before allows a remote unauthenticated attacker to partially exhaust CPU and memory via sending numerous HTTP re…
- CVE-2023-26209MEDIUMCVSS 3.7EG 5.32023-03-09
A improper restriction of excessive authentication attempts vulnerability [CWE-307] in Fortinet FortiDeceptor 3.1.x and before allows a remote unauthenticated attacker to partially exhaust CPU and memory via sending numerous HTTP request…
- CVE-2023-26271MEDIUMCVSS 5.3EG 5.32023-08-28
IBM Security Guardium Data Encryption (IBM Guardium Cloud Key Manager (GCKM) 1.10.3)) uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 248126.
- CVE-2023-26476HIGHCVSS 7.5EG 7.52023-03-02
XWiki Platform is a generic wiki platform. Starting in version 3.2-m3, users can deduce the content of the password fields by repeated call to `LiveTableResults` and `WikisLiveTableResultsMacros`. The issue can be fixed by upgrading to ver…
- CVE-2023-2675CRITICALCVSS 9.8EG 9.82023-11-07
Improper Restriction of Excessive Authentication Attempts in GitHub repository linagora/twake prior to 2023.Q1.1223.
- CVE-2023-26756HIGHCVSS 7.5EG 7.52023-04-14
The login page of Revive Adserver v5.4.1 is vulnerable to brute force attacks. NOTE: The vendor's position is that this is effectively mitigated by rate limits and password-quality features.
- CVE-2023-27100CRITICALCVSS 9.8EG 9.82023-03-22
Improper restriction of excessive authentication attempts in the SSHGuard component of Netgate pfSense Plus software v22.05.1 and pfSense CE software v2.6.0 allows attackers to bypass brute force protection mechanisms via crafted web reque…
- CVE-2023-27152CRITICALCVSS 9.8EG 9.82023-10-23
DECISO OPNsense 23.1 does not impose rate limits for authentication, allowing attackers to perform a brute-force attack to bypass authentication.
- CVE-2023-27172CRITICALCVSS 9.1EG 9.12023-12-20
Xpand IT Write-back Manager v2.3.1 uses weak secret keys to sign JWT tokens. This allows attackers to easily obtain the secret key used to sign JWT tokens via a bruteforce attack.
- CVE-2023-27746CRITICALCVSS 9.8EG 9.82023-04-13
BlackVue DR750-2CH LTE v.1.012_2022.10.26 was discovered to contain a weak default passphrase which can be easily cracked via a brute force attack if the WPA2 handshake is intercepted.
- CVE-2023-28847LOWCVSS 3.1EG 3.12023-04-25
Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. In Nextcloud Server 24.0.0 prior to 24.0.11 and 25.0.0 prior to 25.0.5; as well as Nextcloud Server Enterprise 23.0.0 prior to 23.0.12.6, 24.0…
- CVE-2023-29005HIGHCVSS 7.5EG 7.52023-04-10
Flask-AppBuilder versions before 4.3.0 lack rate limiting which can allow an attacker to brute-force user credentials. Version 4.3.0 includes the ability to enable rate limiting using `AUTH_RATE_LIMITED = True`, `RATELIMIT_ENABLED = True`,…
- CVE-2023-29301HIGHCVSS 7.5EG 7.52023-07-12
Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0.0.330468 (and earlier) are affected by an Improper Restriction of Excessive Authentication Attempts vulnerability that could result in a Security feature bypa…
- CVE-2023-3173CRITICALCVSS 9.8EG 9.82023-06-09
Improper Restriction of Excessive Authentication Attempts in GitHub repository froxlor/froxlor prior to 2.0.20.
- CVE-2023-32074HIGHCVSS 8.0EG 8.02023-05-25
user_oidc app is an OpenID Connect user backend for Nextcloud. Authentication can be broken/bypassed in user_oidc app. It is recommended that the Nextcloud user_oidc app is upgraded to 1.3.2
- CVE-2023-32224CRITICALCVSS 9.8EG 9.82023-06-28
D-Link DSL-224 firmware version 3.0.10 CWE-307: Improper Restriction of Excessive Authentication Attempts
- CVE-2023-32251LOWCVSS 3.7EG 3.72025-07-31
A vulnerability has been identified in the Linux kernel's ksmbd component (kernel SMB/CIFS server). A security control designed to prevent dictionary attacks, which introduces a 5-second delay during session setup, can be bypassed through …
- CVE-2023-32319HIGHCVSS 8.1EG 8.12023-05-26
Nextcloud server is an open source personal cloud implementation. Missing brute-force protection on the WebDAV endpoints via the basic auth header allowed to brute-force user credentials when the provided user name was not an email address…
- CVE-2023-32320HIGHCVSS 8.7EG 8.72023-06-22
Nextcloud Server is a data storage system for Nextcloud, a self-hosted productivity platform. When multiple requests are sent in parallel, all of them were executed even if the amount of faulty requests succeeded the limit by the time the …
- CVE-2023-32657MEDIUMCVSS 5.3EG 5.32023-07-19
Weintek Weincloud v0.13.6 could allow an attacker to efficiently develop a brute force attack on credentials with authentication hints from error message responses.
- CVE-2023-33754MEDIUMCVSS 6.5EG 6.52023-06-01
The captive portal in Inpiazza Cloud WiFi versions prior to v4.2.17 does not enforce limits on the number of attempts for password recovery, allowing attackers to brute force valid user accounts to gain access to login credentials.
- CVE-2023-33759CRITICALCVSS 9.8EG 9.82024-01-25
SpliceCom Maximiser Soft PBX v1.5 and before does not restrict excessive authentication attempts, allowing attackers to bypass authentication via a brute force attack.
- CVE-2023-33868MEDIUMCVSS 5.9EG 5.92023-07-06
The number of login attempts is not limited. This could allow an attacker to perform a brute force on HTTP basic authentication.
- CVE-2023-34001MEDIUMCVSS 5.3EG 5.32024-06-04
Improper Restriction of Excessive Authentication Attempts vulnerability in WPPlugins – WordPress Security Plugins Hide My WP Ghost allows Functionality Bypass.This issue affects Hide My WP Ghost: from n/a through 5.0.25.
- CVE-2023-34243MEDIUMCVSS 5.8EG 5.82023-06-08
TGstation is a toolset to manage production BYOND servers. In affected versions if a Windows user was registered in tgstation-server (TGS), an attacker could discover their username by brute-forcing the login endpoint with an invalid passw…
- CVE-2023-34732MEDIUMCVSS 5.4EG 5.42025-05-12
An issue in the userId parameter in the change password function of Flytxt NEON-dX v0.0.1-SNAPSHOT-6.9-qa-2-9-g5502a0c allows attackers to execute brute force attacks to discover user passwords.
- CVE-2023-35039CRITICALCVSS 9.8EG 9.82023-12-07
Improper Restriction of Excessive Authentication Attempts vulnerability in Be Devious Web Development Password Reset with Code for WordPress REST API allows Authentication Abuse.This issue affects Password Reset with Code for WordPress RES…
- CVE-2023-35172HIGHCVSS 8.7EG 8.72023-06-23
NextCloud Server and NextCloud Enterprise Server provide file storage for Nextcloud, a self-hosted productivity platform. In NextCloud Server versions 25.0.0 until 25.0.7 and 26.0.0 until 26.0.2 and Nextcloud Enterprise Server versions 21.…
- CVE-2023-3548HIGHCVSS 8.3EG 8.32023-07-25
An unauthorized user could gain account access to IQ Wifi 6 versions prior to 2.0.2 by conducting a brute force authentication attack.
- CVE-2023-35697MEDIUMCVSS 5.3EG 5.32023-07-10
Improper Restriction of Excessive Authentication Attempts in the SICK ICR890-4 could allow a remote attacker to brute-force user credentials.
- CVE-2023-3605MEDIUMCVSS 6.5EG 6.52023-07-10
A vulnerability was found in PHPGurukul Online Shopping Portal 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Registration Page. The manipulation leads to improper restric…
- CVE-2023-36434CRITICALCVSS 9.8EG 9.82023-10-10
Windows IIS Server Elevation of Privilege Vulnerability
- CVE-2023-3669LOWCVSS 3.3EG 3.32023-08-03
A missing Brute-Force protection in CODESYS Development System prior to 3.5.19.20 allows a local attacker to have unlimited attempts of guessing the password within an import dialog.
- CVE-2023-36917MEDIUMCVSS 5.9EG 5.92023-07-11
SAP BusinessObjects Business Intelligence Platform - version 420, 430, allows an unauthorized attacker who had hijacked a user session, to be able to bypass the victim’s old password via brute force, due to unrestricted rate limit for pa…
- CVE-2023-37635CRITICALCVSS 9.8EG 9.82023-10-23
UVDesk Community Skeleton v1.1.1 allows unauthenticated attackers to perform brute force attacks on the login page to gain access to the application.
Map vulnerabilities like CWE-307 to your infrastructure
EchelonGraph correlates every CVE — across CWE-307 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →