Skip to main content

CWE archive

CWE-307 CVEs

Programmatic archive

602 CVEs tagged with CWE-307155 Critical, 197 High, 209 Medium, 40 Low, 1 Unrated.

CVE-2025-2171

Published Jun 23, 2025

Aviatrix Controller versions prior to 7.1.4208, 7.2.5090, and 8.0.0 do not enforce rate limiting on password reset attempts, allowing adversaries to brute force guess the 6-digit…

CVSS 7.8 · High

CVE-2025-52916

Published Jun 21, 2025

Yealink RPS before 2025-06-04 lacks SN verification attempt limits, enabling brute-force enumeration (last five digits).

CVSS 2.2 · Low

CVE-2025-47951

Published Jun 16, 2025

Weblate is a web based localization tool. Prior to version 5.12, the verification of the second factor was not subject to rate limiting. The absence of rate limiting on the second…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-6030

Published Jun 13, 2025

Use of fixed learning codes, one code to lock the car and the other code to unlock it, in the Key Fob Transmitter in Cyclone Matrix TRF Smart Keyless Entry System, which allows a…

CVSS 9.4 · Critical

CVE-2025-6029

Published Jun 13, 2025

Use of fixed learning codes, one code to lock the car and the other code to unlock it, the Key Fob Transmitter in KIA-branded Aftermarket Generic Smart Keyless Entry System, prim…

CVSS 9.4 · Critical

CVE-2025-43863

Published Jun 12, 2025

vantage6 is an open source framework built to enable, manage and deploy privacy enhancing technologies like Federated Learning and Multi-Party Computation. If attacker gets access…

CVSS 1.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-49195

Published Jun 12, 2025

The FTP server’s login mechanism does not restrict authentication attempts, allowing an attacker to brute-force user passwords and potentially compromising the FTP server.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-5864

Published Jun 9, 2025

A vulnerability was found in Tenda TDSEE App up to 1.7.12. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /app/Confirm…

CVSS 2.9 · Low

CVE-2025-48014

Published May 20, 2025

Password guessing limits could be bypassed when using LDAP authentication.

CVSS 7.5 · High

CVE-2025-48187

Published May 17, 2025

RAGFlow through 0.18.1 allows account takeover because it is possible to conduct successful brute-force attacks against email verification codes to perform arbitrary account regis…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-34732

Published May 12, 2025

An issue in the userId parameter in the change password function of Flytxt NEON-dX v0.0.1-SNAPSHOT-6.9-qa-2-9-g5502a0c allows attackers to execute brute force attacks to discover…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-46739

Published May 12, 2025

An unauthenticated user could discover account credentials via a brute-force attack without rate limiting

CVSS 8.1 · High

CVE-2025-3709

Published May 2, 2025

Agentflow from Flowring Technology has an Account Lockout Bypass vulnerability, allowing unauthenticated remote attackers to exploit this vulnerability to perform password brute f…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-42600

Published Apr 23, 2025

This vulnerability exists in Meon KYC solutions due to missing restrictions on the number of incorrect One-Time Password (OTP) attempts through certain API endpoints of login proc…

CVSS 8.2 · High

CVE-2025-3129

Published Apr 2, 2025

Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Access code allows Brute Force.This issue affects Access code: from 0.0.0 before 2.0.4.

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-0417

Published Apr 1, 2025

Lack of protection against brute force attacks in Valmet DNA visualization in DNA Operate. The possibility to make an arbitrary number of login attempts without any rate limit giv…

CVSS 7.0 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-2911

Published Mar 28, 2025

Unauthorised access to the call forwarding service system in MeetMe products in versions prior to 2024-09 allows an attacker to identify multiple users and perform brute force att…

CVSS 5.3 · Medium

CVE-2025-1496

Published Mar 20, 2025

Improper Restriction of Excessive Authentication Attempts vulnerability in BG-TEK Coslat Hotspot allows Password Brute Forcing, Authentication Abuse. This issue affects Coslat Ho…

CVSS 6.5 · Medium

CVE-2024-12039

Published Mar 20, 2025

langgenius/dify version v0.10.1 contains a vulnerability where there are no limits applied to the number of code guess attempts for password reset. This allows an unauthenticated…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-42176

Published Mar 19, 2025

HCL MyXalytics is affected by concurrent login vulnerability. A concurrent login vulnerability occurs when simultaneous active sessions are allowed for a single credential allowin…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort
Showing 176-200 of 602 CVEsPage 8 of 25