Skip to main content

CWE archive

CWE-307 CVEs

Programmatic archive

602 CVEs tagged with CWE-307155 Critical, 197 High, 209 Medium, 40 Low, 1 Unrated.

CVE-2021-31646

Published Apr 26, 2021

Gestsup before 3.2.10 allows account takeover through the password recovery functionality (remote). The affected component is the file forgot_pwd.php - it uses a weak algorithm fo…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-29648

Published Mar 30, 2021

An issue was discovered in the Linux kernel before 5.11.11. The BPF subsystem does not properly consider that resolved_ids and resolved_sizes are intentionally uninitialized in th…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-28248

Published Mar 26, 2021

CA eHealth Performance Manager through 6.3.2.12 is affected by Improper Restriction of Excessive Authentication Attempts. An attacker is able to perform an arbitrary number of /we…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-4891

Published Mar 16, 2021

IBM Spectrum Scale 5.0.0 through 5.0.5.5 and 5.1.0 through 5.1.0.2 uses an inadequate account lockout setting that could allow a local user er to brute force Rest API account cred…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-25676

Published Mar 15, 2021

A vulnerability has been identified in RUGGEDCOM RM1224 (V6.3), SCALANCE M-800 (V6.3), SCALANCE S615 (V6.3), SCALANCE SC-600 (All Versions >= V2.1 and < V2.1.3). Multiple failed S…

CVSS 7.5 · High

CVE-2021-27514

Published Feb 22, 2021

EyesOfNetwork 5.3-10 uses an integer of between 8 and 10 digits for the session ID, which might be leveraged for brute-force authentication bypass (such as in CVE-2021-27513 explo…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-3138

Published Jan 14, 2021

In Discourse 2.7.0 through beta1, a rate-limit bypass leads to a bypass of the 2FA requirement for certain forms.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-35590

Published Dec 21, 2020

LimitLoginAttempts.php in the limit-login-attempts-reloaded plugin before 2.17.4 for WordPress allows a bypass of (per IP address) rate limits because the X-Forwarded-For header c…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-28206

Published Dec 2, 2020

An issue was discovered in Bitrix24 Bitrix Framework (1c site management) 20.0. An "User enumeration and Improper Restriction of Excessive Authentication Attempts" vulnerability e…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-29136

Published Nov 27, 2020

In cPanel before 90.0.17, 2FA can be bypassed via a brute-force approach (SEC-575).

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-29042

Published Nov 26, 2020

An issue was discovered in BigBlueButton through 2.2.29. A brute-force attack may occur because an unlimited number of codes can be entered for a meeting that is protected by an a…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2020-28212

Published Nov 19, 2020

A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists in PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) (all versions) that could…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-27423

Published Nov 16, 2020

Anuko Time Tracker v1.19.23.5311 lacks rate limit on the password reset module which allows attacker to perform Denial of Service attack on any legitimate user's mailbox

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-27747

Published Oct 29, 2020

An issue was discovered in Click Studios Passwordstate 8.9 (Build 8973).If the user of the system has assigned himself a PIN code for entering from a mobile device using the built…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-15906

Published Oct 22, 2020

tiki-login.php in Tiki before 21.2 sets the admin password to a blank value after 50 invalid login attempts.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 476-500 of 602 CVEsPage 20 of 25