CWE-307— Improper Restriction of Excessive Authentication Attempts
The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.— MITRE CWE catalog
613 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-307page 7 of 13
- CVE-2023-37832HIGHCVSS 7.5EG 7.52023-10-31
A lack of rate limiting in Elenos ETG150 FM transmitter v3.12 allows attackers to obtain user credentials via brute force and cause other unspecified impacts.
- CVE-2023-38273HIGHCVSS 7.5EG 7.52024-02-02
IBM Cloud Pak System 2.3.1.1, 2.3.2.0, and 2.3.3.7 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 260733.
- CVE-2023-39958MEDIUMCVSS 5.8EG 5.82023-08-10
Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 22.0.0 and prior to versions 22.2.10.13, 23.0.12.8, 24.0.12.5, 25.0.9, 26.0.4, and 27.0.1, missing protection allows an attacker to br…
- CVE-2023-39960MEDIUMCVSS 5.0EG 5.02023-10-13
Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. In Nextcloud Server starting with 25.0.0 and prior to 25.09 and 26.04; as well as Nextcloud Enterprise Server starting with 22.0.0 and prior to 22.2.10.14…
- CVE-2023-40706HIGHCVSS 8.6EG 8.62023-08-24
There is no limit on the number of login attempts in the web server for the SNAP PAC S1 Firmware version R10.3b. This could allow for a brute-force attack on the built-in web server login.
- CVE-2023-40834CRITICALCVSS 9.8EG 9.82023-09-12
OpenCart CMS v4.0.2.2 was discovered to lack a protective mechanism on its login page against excessive login attempts, allowing unauthenticated attackers to gain access to the application via a brute force attack to the password parameter.
- CVE-2023-41270MEDIUMCVSS 4.3EG 4.32023-11-08
Improper Restriction of Excessive Authentication Attempts vulnerability in Samsung Smart TV UE40D7000 version T-GAPDEUC-1033.2 and before allows attackers to cause a denial of service via WPS attack tools.
- CVE-2023-41350CRITICALCVSS 9.8EG 9.82023-11-03
Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of insufficient measures to prevent multiple failed authentication attempts. An unauthenticated remote attacker can execute a crafted Javascript to expose captcha in page, making it very …
- CVE-2023-42480MEDIUMCVSS 5.3EG 5.32023-11-14
The unauthenticated attacker in NetWeaver AS Java Logon application - version 7.50, can brute force the login functionality to identify the legitimate user ids. This will have an impact on confidentiality but there is no other impact on i…
- CVE-2023-42769CRITICALCVSS 9.8EG 9.82023-10-26
The cookie session ID is of insufficient length and can be exploited by brute force, which may allow a remote attacker to obtain a valid session, bypass authentication, and manipulate the transmitter.
- CVE-2023-42818CRITICALCVSS 9.8EG 9.82023-09-27
JumpServer is an open source bastion host. When users enable MFA and use a public key for authentication, the Koko SSH server does not verify the corresponding SSH private key. An attacker could exploit a vulnerability by utilizing a discl…
- CVE-2023-43699HIGHCVSS 7.5EG 7.52023-10-09
Improper Restriction of Excessive Authentication Attempts in RDT400 in SICK APU allows an unprivileged remote attacker to guess the password via trial-and-error as the login attempts are not limited.
- CVE-2023-44096HIGHCVSS 7.5EG 7.52023-10-11
Vulnerability of brute-force attacks on the device authentication module.Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2023-44111HIGHCVSS 7.5EG 7.52023-10-11
Vulnerability of brute-force attacks on the device authentication module.Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2023-44235MEDIUMCVSS 5.3EG 5.32024-06-04
Improper Restriction of Excessive Authentication Attempts vulnerability in Devnath verma WP Captcha allows Functionality Bypass.This issue affects WP Captcha: from n/a through 2.0.0.
- CVE-2023-45009MEDIUMCVSS 5.3EG 5.32024-06-04
Improper Restriction of Excessive Authentication Attempts vulnerability in Forge12 Interactive GmbH Captcha/Honeypot for Contact Form 7 allows Functionality Bypass.This issue affects Captcha/Honeypot for Contact Form 7: from n/a through 1.…
- CVE-2023-45148MEDIUMCVSS 4.3EG 4.32023-10-16
Nextcloud is an open source home cloud server. When Memcached is used as `memcache.distributed` the rate limiting in Nextcloud Server could be reset unexpectedly resetting the rate count earlier than intended. Users are advised to upgrade …
- CVE-2023-45149MEDIUMCVSS 4.3EG 4.32023-10-16
Nextcloud talk is a chat module for the Nextcloud server platform. In affected versions brute force protection of public talk conversation passwords can be bypassed, as there was an endpoint validating the conversation password without reg…
- CVE-2023-45190MEDIUMCVSS 5.1EG 5.12024-02-09
IBM Engineering Lifecycle Optimization 7.0.2 and 7.0.3 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable syst…
- CVE-2023-45191HIGHCVSS 7.5EG 7.52024-02-09
IBM Engineering Lifecycle Optimization 7.0.2 and 7.0.3 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 268755.
- CVE-2023-45582HIGHCVSS 7.3EG 7.32023-11-14
An improper restriction of excessive authentication attempts vulnerability [CWE-307] in FortiMail webmail version 7.2.0 through 7.2.4, 7.0.0 through 7.0.6 and before 6.4.8 may allow an unauthenticated attacker to perform a brute force at…
- CVE-2023-46123MEDIUMCVSS 5.3EG 5.32023-10-25
jumpserver is an open source bastion machine, professional operation and maintenance security audit system that complies with 4A specifications. A flaw in the Core API allows attackers to bypass password brute-force protections by spoofing…
- CVE-2023-4625MEDIUMCVSS 5.3EG 5.32023-11-06
Improper Restriction of Excessive Authentication Attempts vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F/iQ-R Series CPU modules Web server function allows a remote unauthenticated attacker to prevent legitimate users from lo…
- CVE-2023-46745HIGHCVSS 7.5EG 7.52023-11-17
LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring which includes support for a wide range of network hardware and operating systems. In affected versions the login method has no rate limit. An attacker may be able to …
- CVE-2023-48028CRITICALCVSS 9.8EG 9.82023-11-18
kodbox 1.46.01 has a security flaw that enables user enumeration. This problem is present on the login page, where an attacker can identify valid users based on varying response messages, potentially paving the way for a brute force attack.
- CVE-2023-48276MEDIUMCVSS 5.3EG 5.32024-06-04
Improper Restriction of Excessive Authentication Attempts vulnerability in Nitin Rathod WP Forms Puzzle Captcha allows Functionality Bypass.This issue affects WP Forms Puzzle Captcha: from n/a through 4.1.
- CVE-2023-48290MEDIUMCVSS 5.3EG 5.32024-06-04
Improper Restriction of Excessive Authentication Attempts vulnerability in 10Web Form Builder Team Form Maker by 10Web allows Functionality Bypass.This issue affects Form Maker by 10Web: from n/a through 1.15.20.
- CVE-2023-48318MEDIUMCVSS 5.3EG 5.32024-06-04
Improper Restriction of Excessive Authentication Attempts vulnerability in CodePeople Contact Form Email allows Functionality Bypass.This issue affects Contact Form Email: from n/a through 1.3.41.
- CVE-2023-48745MEDIUMCVSS 5.3EG 5.32024-06-04
Improper Restriction of Excessive Authentication Attempts vulnerability in WebFactory Ltd Captcha Code allows Functionality Bypass.This issue affects Captcha Code: from n/a through 2.9.
- CVE-2023-49278MEDIUMCVSS 5.3EG 5.32023-12-12
Umbraco is an ASP.NET content management system (CMS). Starting in version 8.0.0 and prior to versions 8.18.10, 10.8.1, and 12.3.4, a brute force exploit can be used to collect valid usernames. Versions 8.18.10, 10.8.1, and 12.3.4 contain …
- CVE-2023-49443CRITICALCVSS 9.8EG 9.82023-12-08
DoraCMS v2.1.8 was discovered to re-use the same code for verification of valid usernames and passwords. This vulnerability allows attackers to gain access to the application via a bruteforce attack.
- CVE-2023-49792CRITICALCVSS 9.8EG 9.82023-12-22
Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. In Nextcloud Server prior to versions 26.0.9 and 27.1.4; as well as Nextcloud Enterprise Server prior to versions 23.0.12.13, 24.0.12.9, 25.0.13.4, 26.0.9…
- CVE-2023-49810HIGHCVSS 7.3EG 7.32024-01-10
A login attempt restriction bypass vulnerability exists in the checkLoginAttempts functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to captcha bypass, which can be abused by an attacker to…
- CVE-2023-50123HIGHCVSS 8.1EG 8.12024-01-11
The number of attempts to bring the Hozard Alarm system (alarmsystemen) v1.0 to a disarmed state is not limited. This could allow an attacker to perform a brute force on the SMS authentication, to bring the alarm system to a disarmed state.
- CVE-2023-50326HIGHCVSS 7.5EG 7.52024-02-02
IBM PowerSC 1.3, 2.0, and 2.1 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 275107.
- CVE-2023-50444HIGHCVSS 7.5EG 7.52023-12-13
By default, .ZED containers produced by PRIMX ZED! for Windows before Q.2020.3 (ANSSI qualification submission); ZED! for Windows before Q.2021.2 (ANSSI qualification submission); ZONECENTRAL for Windows before Q.2021.2 (ANSSI qualificatio…
- CVE-2023-54347HIGHCVSS 7.5EG 7.52026-05-05
OpenEMR 7.0.1 contains an authentication brute force vulnerability that allows attackers to bypass rate limiting protections by sending repeated login attempts to the main login endpoint. Attackers can submit POST requests with authUser an…
- CVE-2023-5754CRITICALCVSS 9.8EG 9.82023-10-26
Sielco PolyEco1000 uses a weak set of default administrative credentials that can be easily guessed in remote password attacks and gain full control of the system.
- CVE-2023-6272CRITICALCVSS 9.8EG 9.82023-12-18
The Theme My Login 2FA WordPress plugin before 1.2 does not rate limit 2FA validation attempts, which may allow an attacker to brute-force all possibilities, which shouldn't be too long, as the 2FA codes are 6 digits.
- CVE-2023-6756CRITICALCVSS 9.8EG 9.82023-12-13
A vulnerability was found in Thecosy IceCMS 2.0.1. It has been classified as problematic. Affected is an unknown function of the file /login of the component Captcha Handler. The manipulation leads to improper restriction of excessive auth…
- CVE-2023-6912CRITICALCVSS 9.8EG 9.82023-12-20
Lack of protection against brute force attacks in M-Files Server before 23.12.13205.0 allows an attacker unlimited authentication attempts, potentially compromising targeted M-Files user accounts by guessing passwords.
- CVE-2023-6928CRITICALCVSS 9.8EG 9.82023-12-19
EuroTel ETL3100 versions v01c01 and v01x37 does not limit the number of attempts to guess administrative credentials in remote password attacks to gain full control of the system.
- CVE-2024-0787MEDIUMCVSS 5.9EG 5.92024-11-15
phpIPAM version 1.5.1 contains a vulnerability where an attacker can bypass the IP block mechanism to brute force passwords for users by using the 'X-Forwarded-For' header. The issue lies in the 'get_user_ip()' function in 'class.Common.ph…
- CVE-2024-1104HIGHCVSS 7.5EG 7.52024-02-22
An unauthenticated remote attacker can bypass the brute force prevention mechanism and disturb the webservice for all users.
- CVE-2024-11126LOWCVSS 3.1EG 3.12024-11-12
A vulnerability was found in Digistar AG-30 Plus 2.6b. It has been classified as problematic. Affected is an unknown function of the component Login Page. The manipulation leads to improper restriction of excessive authentication attempts.…
- CVE-2024-12039HIGHCVSS 8.1EG 8.12025-03-20
langgenius/dify version v0.10.1 contains a vulnerability where there are no limits applied to the number of code guess attempts for password reset. This allows an unauthenticated attacker to reset owner, admin, or other user passwords with…
- CVE-2024-1345MEDIUMCVSS 6.8EG 6.82024-02-19
Weak MySQL database root password in LaborOfficeFree affects version 19.10. This vulnerability allows an attacker to perform a brute force attack and easily discover the root password.
- CVE-2024-2051CRITICALCVSS 9.8EG 9.82024-03-18
CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could cause account takeover and unauthorized access to the system when an attacker conducts brute-force attacks against the login form.
- CVE-2024-21500MEDIUMCVSS 4.8EG 4.82024-02-17
All versions of the package github.com/greenpau/caddy-security are vulnerable to Improper Restriction of Excessive Authentication Attempts via the two-factor authentication (2FA). Although the application blocks the user after several fail…
- CVE-2024-21652CRITICALCVSS 9.8EG 9.82024-03-18
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior to versions 2.8.13, 2.9.9, and 2.10.4, an attacker can exploit a chain of vulnerabilities, including a Denial of Service (DoS) flaw and in-memory data storage …
Map vulnerabilities like CWE-307 to your infrastructure
EchelonGraph correlates every CVE — across CWE-307 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →