Skip to main content

CWE archive

CWE-307 CVEs

Programmatic archive

616 CVEs tagged with CWE-307157 Critical, 203 High, 214 Medium, 41 Low, 1 Unrated.

CVE-2024-8429

Published Dec 17, 2024

Improper Restriction of Excessive Authentication Attempts vulnerability in Digital Operation Services WiFiBurada allows Use of Known Domain Credentials. This issue affects WiFiBu…

CVSS 4.3 · Medium

CVE-2024-38488

Published Dec 13, 2024

Dell RecoverPoint for Virtual Machines 6.0.x contains a vulnerability. An improper Restriction of Excessive Authentication vulnerability where a Network attacker could potentially…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-45404

Published Dec 12, 2024

OpenCTI is an open-source cyber threat intelligence platform. In versions below 6.2.18, because the function to limit the rate of OTP does not exist, an attacker with valid creden…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-46442

Published Dec 10, 2024

An issue in the BYD Dilink Headunit System v3.0 to v4.0 allows attackers to bypass authentication via a bruteforce attack.

CVSS 9.8 · Critical

CVE-2024-9928

Published Nov 26, 2024

A vulnerability exists in NSD570 login panel that does not restrict excessive authentication attempts. If exploited, this could cause account takeover and unauthorized access to t…

CVSS 5.3 · Medium

CVE-2024-49597

Published Nov 26, 2024

Dell Wyse Management Suite, versions WMS 4.4 and prior, contain an Improper Restriction of Excessive Authentication Attempts vulnerability. A high privileged attacker with remote…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2024-5716

Published Nov 22, 2024

Logsign Unified SecOps Platform Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Logsign Unifi…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-0787

Published Nov 15, 2024

phpIPAM version 1.5.1 contains a vulnerability where an attacker can bypass the IP block mechanism to brute force passwords for users by using the 'X-Forwarded-For' header. The is…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-9832

Published Nov 14, 2024

There is no limit on the number of failed login attempts permitted with the Clinician Password or the Serial Number Clinician Password. An attacker could execute a brute-force att…

CVSS 9.3 · Critical

CVE-2024-51720

Published Nov 12, 2024

An insufficient entropy vulnerability in the SecuSUITE Secure Client Authentication (SCA) Server of SecuSUITE versions 5.0.420 and earlier could allow an attacker to potentially e…

CVSS 4.8 · Medium

CVE-2024-11126

Published Nov 12, 2024

A vulnerability was found in Digistar AG-30 Plus 2.6b. It has been classified as problematic. Affected is an unknown function of the component Login Page. The manipulation leads t…

CVSS 2.3 · Low

CVE-2024-47592

Published Nov 12, 2024

SAP NetWeaver AS Java allows an unauthenticated attacker to brute force the login functionality in order to identify the legitimate user IDs. This has an impact on confidentiality…

CVSS 5.3 · Medium

CVE-2024-51558

Published Nov 4, 2024

This vulnerability exists in the Wave 2.0 due to missing restrictions for excessive failed authentication attempts on its API based login. A remote attacker could exploit this vul…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-48143

Published Oct 24, 2024

A lack of rate limiting in the OTP validation component of Digitory Multi Channel Integrated POS v1.0 allows attackers to gain access to the ordering system and place an excessive…

CVSS 9.1 · Critical

CVE-2024-7292

Published Oct 9, 2024

In Progress® Telerik® Report Server versions prior to 2024 Q3 (10.2.24.806), a credential stuffing attack is possible through improper restriction of excessive login attempts.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-47656

Published Oct 4, 2024

This vulnerability exists in Shilpi Client Dashboard due to missing restrictions for incorrect login attempts on its API based login. A remote attacker could exploit this vulnerab…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-41276

Published Oct 1, 2024

A vulnerability in Kaiten version 57.131.12 and earlier allows attackers to bypass the PIN code authentication mechanism. The application requires users to input a 6-digit PIN cod…

CVSS 9.8 · Critical

CVE-2024-45523

Published Sep 18, 2024

An issue was discovered in Bravura Security Fabric versions 12.3.x before 12.3.5.32784, 12.4.x before 12.4.3.35110, 12.5.x before 12.5.2.35950, 12.6.x before 12.6.2.37183, and 12.…

CVSS 9.1 · Critical

CVE-2024-5682

Published Sep 18, 2024

Improper Restriction of Excessive Authentication Attempts vulnerability in Yordam Information Technology Yordam Library Automation System allows Interface Manipulation. This issu…

CVSS 6.9 · Medium

CVE-2024-45790

Published Sep 11, 2024

This vulnerability exists in Reedos aiM-Star version 2.0.1 due to missing restrictions for excessive failed authentication attempts on its API based login. A remote attacker could…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-45327

Published Sep 11, 2024

An improper authorization vulnerability [CWE-285] in FortiSOAR version 7.4.0 through 7.4.3, 7.3.0 through 7.3.2, 7.2.0 through 7.2.2, 7.0.0 through 7.0.3 change password endpoint…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-32771

Published Sep 6, 2024

An improper restriction of excessive authentication attempts vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability coul…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-45589

Published Sep 5, 2024

RapidIdentity LTS through 2023.0.2 and Cloud through 2024.08.0 improperly restricts excessive authentication attempts and allows a remote attacker to cause a denial of service via…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-8462

Published Sep 5, 2024

A vulnerability was found in Windmill 1.380.0. It has been classified as problematic. Affected is an unknown function of the file backend/windmill-api/src/users.rs of the componen…

CVSS 6.3 · Medium
Showing 226-250 of 616 CVEsPage 10 of 25