Skip to main content

CWE archive

CWE-307 CVEs

Programmatic archive

602 CVEs tagged with CWE-307155 Critical, 197 High, 209 Medium, 40 Low, 1 Unrated.

CVE-2025-2414

Published Sep 2, 2025

Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft OctoCloud allows Authentication Bypass. This issue affects OctoCloud: from s1.09.03 before v1.…

CVSS 8.6 · High

CVE-2025-2412

Published Sep 1, 2025

Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft QR Menu allows Authentication Bypass. This issue affects QR Menu: from s1.05.07 before v1.05.1…

CVSS 8.6 · High

CVE-2025-9004

Published Aug 15, 2025

A vulnerability was found in mtons mblog up to 3.5.0. This issue affects some unknown processing of the file /settings/password. The manipulation leads to improper restriction of…

CVSS 2.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-8927

Published Aug 13, 2025

A vulnerability was determined in mtons mblog up to 3.5.0. Affected by this issue is some unknown functionality of the file /email/send_code of the component Verification Code Han…

CVSS 2.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-52392

Published Aug 13, 2025

Soosyze CMS 2.0 allows brute-force login attacks via the /user/login endpoint due to missing rate-limiting and lockout mechanisms. An attacker can repeatedly submit login attempts…

CVSS 5.4 · Medium

CVE-2025-55003

Published Aug 9, 2025

OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. In versions 2.3.1 and below, OpenBao's Log…

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-54998

Published Aug 9, 2025

OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. In versions 0.1.0 through 2.3.1, attackers…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-8742

Published Aug 8, 2025

A vulnerability was found in macrozheng mall 1.0.3. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Admin Login. The manipu…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-46414

Published Aug 8, 2025

The affected product does not limit the number of attempts for inputting the correct PIN for a registered product, which may allow an attacker to gain unauthorized access using…

CVSS 9.2 · Critical

CVE-2025-53544

Published Aug 5, 2025

Trilium Notes is an open-source, cross-platform hierarchical note taking application with focus on building large personal knowledge bases. In versions below 0.97.0, a brute-force…

CVSS 7.5 · High

CVE-2025-6015

Published Aug 1, 2025

Vault and Vault Enterprise’s (“Vault”) login MFA rate limits could be bypassed and TOTP tokens could be reused. Fixed in Vault Community Edition 1.20.1 and Vault Enterprise 1.20.1…

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-6004

Published Aug 1, 2025

Vault and Vault Enterprise’s (“Vault”) user lockout feature could be bypassed for Userpass and LDAP authentication methods. Fixed in Vault Community Edition 1.20.1 and Vault Enter…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-32251

Published Jul 31, 2025

A vulnerability has been identified in the Linux kernel's ksmbd component (kernel SMB/CIFS server). A security control designed to prevent dictionary attacks, which introduces a 5…

CVSS 3.7 · Low

CVE-2024-49342

Published Jul 28, 2025

IBM Informix Dynamic Server 12.10 and 14.10 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-7393

Published Jul 21, 2025

Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Mail Login allows Brute Force.This issue affects Mail Login: from 3.0.0 before 3.2.0, from 4.0.0…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-7882

Published Jul 20, 2025

A vulnerability was found in Mercusys MW301R 1.0.2 Build 190726 Rel.59423n. It has been rated as problematic. This issue affects some unknown processing of the component Login. Th…

CVSS 1.3 · Low

CVE-2024-9342

Published Jul 16, 2025

In Eclipse GlassFish versions before 8.0.3 it is possible to perform Login Brute Force attacks as there is no limitation in the number of failed login attempts. GlassFish 8.0.3 ad…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-52997

Published Jun 30, 2025

File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Prior to version 2.34.1, a missi…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-4383

Published Jun 24, 2025

Improper Restriction of Excessive Authentication Attempts vulnerability in Art-in Bilişim Teknolojileri ve Yazılım Hizm. Tic. Ltd. Şti. Wi-Fi Cloud Hotspot allows Authentication A…

CVSS 9.3 · Critical

CVE-2025-6533

Published Jun 24, 2025

A vulnerability, which was classified as critical, has been found in xxyopen/201206030 novel-plus up to 5.1.3. Affected by this issue is the function ajaxLogin of the file novel-a…

CVSS 2.9 · Low
Vendor/product tagsBeta · best-effort
Showing 151-175 of 602 CVEsPage 7 of 25