Skip to main content

CWE archive

CWE-307 CVEs

Programmatic archive

602 CVEs tagged with CWE-307155 Critical, 197 High, 209 Medium, 40 Low, 1 Unrated.

CVE-2025-25595

Published Mar 18, 2025

A lack of rate limiting in the login page of Safe App version a3.0.9 allows attackers to bypass authentication via a brute force attack.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-1714

Published Mar 5, 2025

Lack of Rate Limiting in Sign-up workflow in Perforce Gliffy prior to version 4.14.0-7 on Gliffy online allows attacker to enumerate valid user emails and potentially DOS the serv…

CVSS 6.9 · Medium

CVE-2025-1629

Published Feb 24, 2025

A vulnerability was found in Excitel Broadband Private my Excitel App 3.13.0 on Android. It has been classified as problematic. Affected is an unknown function of the component On…

CVSS 5.1 · Medium

CVE-2025-24806

Published Feb 19, 2025

Authelia is an open-source authentication and authorization server providing two-factor authentication and single sign-on (SSO) for applications via a web portal. If users are all…

CVSS 2.3 · Low

CVE-2025-22645

Published Feb 18, 2025

Improper Restriction of Excessive Authentication Attempts vulnerability in Rameez Iqbal Real Estate Manager real-estate-manager allows Password Brute Forcing.This issue affects Re…

CVSS 5.3 · Medium

CVE-2024-57610

Published Feb 6, 2025

A rate limiting issue in Sylius v2.0.2 allows a remote attacker to perform unrestricted brute-force attacks on user accounts, significantly increasing the risk of account compromi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-23106

Published Jan 14, 2025

An improper restriction of excessive authentication attempts [CWE-307] in FortiClientEMS version 7.2.0 through 7.2.4 and before 7.0.10 allows an unauthenticated attacker to try a…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-55008

Published Jan 7, 2025

JATOS 3.9.4 contains a denial-of-service (DoS) vulnerability in the authentication system, where an attacker can prevent legitimate users from accessing their accounts by repeated…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-8429

Published Dec 17, 2024

Improper Restriction of Excessive Authentication Attempts vulnerability in Digital Operation Services WiFiBurada allows Use of Known Domain Credentials. This issue affects WiFiBu…

CVSS 4.3 · Medium

CVE-2024-38488

Published Dec 13, 2024

Dell RecoverPoint for Virtual Machines 6.0.x contains a vulnerability. An improper Restriction of Excessive Authentication vulnerability where a Network attacker could potentially…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-45404

Published Dec 12, 2024

OpenCTI is an open-source cyber threat intelligence platform. In versions below 6.2.18, because the function to limit the rate of OTP does not exist, an attacker with valid creden…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-46442

Published Dec 10, 2024

An issue in the BYD Dilink Headunit System v3.0 to v4.0 allows attackers to bypass authentication via a bruteforce attack.

CVSS 9.8 · Critical

CVE-2024-9928

Published Nov 26, 2024

A vulnerability exists in NSD570 login panel that does not restrict excessive authentication attempts. If exploited, this could cause account takeover and unauthorized access to t…

CVSS 5.3 · Medium

CVE-2024-49597

Published Nov 26, 2024

Dell Wyse Management Suite, versions WMS 4.4 and prior, contain an Improper Restriction of Excessive Authentication Attempts vulnerability. A high privileged attacker with remote…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2024-5716

Published Nov 22, 2024

Logsign Unified SecOps Platform Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Logsign Unifi…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-0787

Published Nov 15, 2024

phpIPAM version 1.5.1 contains a vulnerability where an attacker can bypass the IP block mechanism to brute force passwords for users by using the 'X-Forwarded-For' header. The is…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-9832

Published Nov 14, 2024

There is no limit on the number of failed login attempts permitted with the Clinician Password or the Serial Number Clinician Password. An attacker could execute a brute-force att…

CVSS 9.3 · Critical

CVE-2024-51720

Published Nov 12, 2024

An insufficient entropy vulnerability in the SecuSUITE Secure Client Authentication (SCA) Server of SecuSUITE versions 5.0.420 and earlier could allow an attacker to potentially e…

CVSS 4.8 · Medium

CVE-2024-11126

Published Nov 12, 2024

A vulnerability was found in Digistar AG-30 Plus 2.6b. It has been classified as problematic. Affected is an unknown function of the component Login Page. The manipulation leads t…

CVSS 2.3 · Low

CVE-2024-47592

Published Nov 12, 2024

SAP NetWeaver AS Java allows an unauthenticated attacker to brute force the login functionality in order to identify the legitimate user IDs. This has an impact on confidentiality…

CVSS 5.3 · Medium

CVE-2024-51558

Published Nov 4, 2024

This vulnerability exists in the Wave 2.0 due to missing restrictions for excessive failed authentication attempts on its API based login. A remote attacker could exploit this vul…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-48143

Published Oct 24, 2024

A lack of rate limiting in the OTP validation component of Digitory Multi Channel Integrated POS v1.0 allows attackers to gain access to the ordering system and place an excessive…

CVSS 9.1 · Critical
Showing 201-225 of 602 CVEsPage 9 of 25