CWE-307 · 628 kayıt
Improper Restriction of Excessive Authentication Attempts
Bu sınıftaki CVE’ler
628 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
51Planlayın | CVE-2019-17240Kavram kanıtı | bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many different forged X-bludit · bludit · CWE-307 | Kritik9,8 | — | %39,6 | 6 Eki 2019 |
47Planlayın | CVE-2020-15906Kavram kanıtı | tiki-login.php in Tiki before 21.2 sets the admin password to a blank value after 50 invalid login attempts.tiki · tiki · CWE-307 | Kritik9,8 | — | %27,2 | 22 Eki 2020 |
44Planlayın | CVE-2025-4094Kavram kanıtı | Digits < 8.4.6.1 - Auth Bypass via OTP Bruteforcingunitedover · digits · CWE-307 | Kritik9,8 | — | %15,8 | 21 May 2025 |
43Planlayın | CVE-2024-39225İstismar yok | GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16,gl-inet · mt6000 firmware · CWE-307 | Kritik9,8 | — | %14,4 | 6 Ağu 2024 |
42Planlayın | CVE-2023-27100Kavram kanıtı | Improper restriction of excessive authentication attempts in the SSHGuard component of Netgate pfSense Plus software v22.05.1 and pfSense CEnetgate · pfsense plus · CWE-307 | Kritik9,8 | — | %9,8 | 22 Mar 2023 |
42Planlayın | CVE-2001-1291Kavram kanıtı | The telnet server for 3Com hardware such as PS40 SuperStack II does not delay or disconnect remote attackers who provide an incorrect userna3com · superstack ii ps hub 40 firmware · CWE-307 | Kritik9,8 | — | %8,9 | 12 Tem 2001 |
41Planlayın | CVE-2001-1339Kavram kanıtı | Beck IPC GmbH IPC@CHIP telnet service does not delay or disconnect users from the service when bad passwords are entered, which makes it easanybus · ipc\@chip firmware · CWE-307 | Kritik9,8 | — | %7,5 | 24 May 2001 |
41Planlayın | CVE-2021-41435İstismar yok | A brute-force protection bypass in CAPTCHA protection in ASUS ROG Rapture GT-AX11000, RT-AX3000, RT-AX55, RT-AX56U, RT-AX56U_V2, RT-AX58U, Rasus · gt-ax11000 firmware · CWE-307 | Kritik9,8 | — | %6,5 | 19 Kas 2021 |
41Planlayın | CVE-2017-7898İstismar yok | An Improper Restriction of Excessive Authentication Attempts issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1100 progrrockwellautomation · 1763-l16awa series a · CWE-307 | Kritik9,8 | — | %5,2 | 29 Haz 2017 |
40Planlayın | CVE-2023-29301İstismar yok | Adobe ColdFusion Improper Restriction of Excessive Authentication Attempts Security feature bypassadobe · coldfusion · CWE-307 | Yüksek7,5 | — | %34,7 | 12 Tem 2023 |
40Planlayın | CVE-2020-7995İstismar yok | The htdocs/index.php?mainmenu=home login page in Dolibarr 10.0.6 allows an unlimited rate of failed authentication attempts.dolibarr · dolibarr erp\/crm · CWE-307 | Kritik9,8 | — | %4,5 | 26 Oca 2020 |
40Planlayın | CVE-2020-35590Kavram kanıtı | LimitLoginAttempts.php in the limit-login-attempts-reloaded plugin before 2.17.4 for WordPress allows a bypass of (per IP address) rate limilimitloginattempts · limit login attempts reloaded · CWE-307 | Kritik9,8 | — | %4,3 | 21 Ara 2020 |
40Planlayın | CVE-2021-27514İstismar yok | EyesOfNetwork 5.3-10 uses an integer of between 8 and 10 digits for the session ID, which might be leveraged for brute-force authentication eyesofnetwork · eyesofnetwork · CWE-307 | Kritik9,8 | — | %3,5 | 21 Şub 2021 |
40Planlayın | CVE-1999-1324İstismar yok | VAXstations running Open VMS 5.3 through 5.5-2 with VMS DECwindows or MOTIF do not properly disable access to user accounts that exceed the hp · openvms vax · CWE-307 | Kritik9,8 | — | %3,1 | 31 Ara 1999 |
40Planlayın | CVE-2018-1373İstismar yok | IBM Security Guardium Big Data Intelligence (SonarG) 3.1 uses an inadequate account lockout setting that could allow a remote attacker to bribm · security guardium big data intelligence · CWE-307 | Kritik9,8 | — | %3,0 | 2 Mar 2018 |
40Planlayın | CVE-2018-5469İstismar yok | An Improper Restriction of Excessive Authentication Attempts issue was discovered in Belden Hirschmann RS, RSR, RSB, MACH100, MACH1000, MACHbelden · hirschmann rs20-0900mmm2tdau · CWE-307 | Kritik9,8 | — | %2,8 | 6 Mar 2018 |
40Planlayın | CVE-2020-28212İstismar yok | A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists in PLC Simulator on EcoStruxureª Control Expert (nschneider-electric · ecostruxure control expert · CWE-307 | Kritik9,8 | — | %2,8 | 19 Kas 2020 |
40Planlayın | CVE-2019-6524İstismar yok | Moxa IKS and EDS do not implement sufficient measures to prevent multiple failed authentication attempts, which may allow an attacker to dismoxa · iks-g6824a firmware · CWE-307 | Kritik9,8 | — | %2,7 | 5 Mar 2019 |
40Planlayın | CVE-2020-6852İstismar yok | CACAGOO Cloud Storage Intelligent Camera TV-288ZD-2MP with firmware 3.4.2.0919 has weak authentication of TELNET access, leading to root pricacagoo · tv-288zd-2mp firmware · CWE-307 | Kritik9,8 | — | %2,4 | 2 Nis 2020 |
40Planlayın | CVE-2023-36434İstismar yok | Windows IIS Server Elevation of Privilege Vulnerabilitymicrosoft · windows 10 1507 · CWE-307 | Kritik9,8 | — | %2,4 | 10 Eki 2023 |
40Planlayın | CVE-2019-12941İstismar yok | AutoPi Wi-Fi/NB and 4G/LTE devices before 2019-10-15 allows an attacker to perform a brute-force attack or dictionary attack to gain access autopi · wi-fi\/nb firmware · CWE-307 | Kritik9,8 | — | %2,4 | 14 Eki 2019 |
40Planlayın | CVE-2020-4567İstismar yok | IBM Tivoli Key Lifecycle Manager 3.0.1 and 4.0 uses an inadequate account lockout setting that could allow a remote attacker to brute force ibm · security key lifecycle manager · CWE-307 | Kritik9,8 | — | %2,3 | 29 Tem 2020 |
40Planlayın | CVE-2016-9124İstismar yok | Revive Adserver before 3.2.3 suffers from Improper Restriction of Excessive Authentication Attempts.revive-adserver · revive adserver · CWE-307 | Kritik9,8 | — | %2,2 | 27 Mar 2017 |
40Planlayın | CVE-2018-1475İstismar yok | IBM BigFix Platform 9.2 and 9.5 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentibm · bigfix platform · CWE-307 | Kritik9,8 | — | %2,2 | 27 Nis 2018 |
40Planlayın | CVE-2026-44596Kavram kanıtı | Yamcs: No Rate Limiting on Authentication Endpointspaceapplications · yamcs · CWE-307 | Kritik9,8 | — | %2,1 | 16 Tem 2026 |
- CVE-2019-1724051Planlayın
bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many different forged X-
KritikCVSS 9,8Kavram kanıtıEPSS %40bludit · bludit6 Eki 2019
- CVE-2020-1590647Planlayın
tiki-login.php in Tiki before 21.2 sets the admin password to a blank value after 50 invalid login attempts.
KritikCVSS 9,8Kavram kanıtıEPSS %27tiki · tiki22 Eki 2020
- CVE-2025-409444Planlayın
Digits < 8.4.6.1 - Auth Bypass via OTP Bruteforcing
KritikCVSS 9,8Kavram kanıtıEPSS %16unitedover · digits21 May 2025
- CVE-2024-3922543Planlayın
GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16,
KritikCVSS 9,8İstismar yokEPSS %14gl-inet · mt6000 firmware6 Ağu 2024
- CVE-2023-2710042Planlayın
Improper restriction of excessive authentication attempts in the SSHGuard component of Netgate pfSense Plus software v22.05.1 and pfSense CE
KritikCVSS 9,8Kavram kanıtıEPSS %10netgate · pfsense plus22 Mar 2023
- CVE-2001-129142Planlayın
The telnet server for 3Com hardware such as PS40 SuperStack II does not delay or disconnect remote attackers who provide an incorrect userna
KritikCVSS 9,8Kavram kanıtıEPSS %93com · superstack ii ps hub 40 firmware12 Tem 2001
- CVE-2001-133941Planlayın
Beck IPC GmbH IPC@CHIP telnet service does not delay or disconnect users from the service when bad passwords are entered, which makes it eas
KritikCVSS 9,8Kavram kanıtıEPSS %7anybus · ipc\@chip firmware24 May 2001
- CVE-2021-4143541Planlayın
A brute-force protection bypass in CAPTCHA protection in ASUS ROG Rapture GT-AX11000, RT-AX3000, RT-AX55, RT-AX56U, RT-AX56U_V2, RT-AX58U, R
KritikCVSS 9,8İstismar yokEPSS %6asus · gt-ax11000 firmware19 Kas 2021
- CVE-2017-789841Planlayın
An Improper Restriction of Excessive Authentication Attempts issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1100 progr
KritikCVSS 9,8İstismar yokEPSS %5rockwellautomation · 1763-l16awa series a29 Haz 2017
- CVE-2023-2930140Planlayın
Adobe ColdFusion Improper Restriction of Excessive Authentication Attempts Security feature bypass
YüksekCVSS 7,5İstismar yokEPSS %35adobe · coldfusion12 Tem 2023
- CVE-2020-799540Planlayın
The htdocs/index.php?mainmenu=home login page in Dolibarr 10.0.6 allows an unlimited rate of failed authentication attempts.
KritikCVSS 9,8İstismar yokEPSS %5dolibarr · dolibarr erp\/crm26 Oca 2020
- CVE-2020-3559040Planlayın
LimitLoginAttempts.php in the limit-login-attempts-reloaded plugin before 2.17.4 for WordPress allows a bypass of (per IP address) rate limi
KritikCVSS 9,8Kavram kanıtıEPSS %4limitloginattempts · limit login attempts reloaded21 Ara 2020
- CVE-2021-2751440Planlayın
EyesOfNetwork 5.3-10 uses an integer of between 8 and 10 digits for the session ID, which might be leveraged for brute-force authentication
KritikCVSS 9,8İstismar yokEPSS %4eyesofnetwork · eyesofnetwork21 Şub 2021
- CVE-1999-132440Planlayın
VAXstations running Open VMS 5.3 through 5.5-2 with VMS DECwindows or MOTIF do not properly disable access to user accounts that exceed the
KritikCVSS 9,8İstismar yokEPSS %3hp · openvms vax31 Ara 1999
- CVE-2018-137340Planlayın
IBM Security Guardium Big Data Intelligence (SonarG) 3.1 uses an inadequate account lockout setting that could allow a remote attacker to br
KritikCVSS 9,8İstismar yokEPSS %3ibm · security guardium big data intelligence2 Mar 2018
- CVE-2018-546940Planlayın
An Improper Restriction of Excessive Authentication Attempts issue was discovered in Belden Hirschmann RS, RSR, RSB, MACH100, MACH1000, MACH
KritikCVSS 9,8İstismar yokEPSS %3belden · hirschmann rs20-0900mmm2tdau6 Mar 2018
- CVE-2020-2821240Planlayın
A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists in PLC Simulator on EcoStruxureª Control Expert (n
KritikCVSS 9,8İstismar yokEPSS %3schneider-electric · ecostruxure control expert19 Kas 2020
- CVE-2019-652440Planlayın
Moxa IKS and EDS do not implement sufficient measures to prevent multiple failed authentication attempts, which may allow an attacker to dis
KritikCVSS 9,8İstismar yokEPSS %3moxa · iks-g6824a firmware5 Mar 2019
- CVE-2020-685240Planlayın
CACAGOO Cloud Storage Intelligent Camera TV-288ZD-2MP with firmware 3.4.2.0919 has weak authentication of TELNET access, leading to root pri
KritikCVSS 9,8İstismar yokEPSS %2cacagoo · tv-288zd-2mp firmware2 Nis 2020
- CVE-2023-3643440Planlayın
Windows IIS Server Elevation of Privilege Vulnerability
KritikCVSS 9,8İstismar yokEPSS %2microsoft · windows 10 150710 Eki 2023
- CVE-2019-1294140Planlayın
AutoPi Wi-Fi/NB and 4G/LTE devices before 2019-10-15 allows an attacker to perform a brute-force attack or dictionary attack to gain access
KritikCVSS 9,8İstismar yokEPSS %2autopi · wi-fi\/nb firmware14 Eki 2019
- CVE-2020-456740Planlayın
IBM Tivoli Key Lifecycle Manager 3.0.1 and 4.0 uses an inadequate account lockout setting that could allow a remote attacker to brute force
KritikCVSS 9,8İstismar yokEPSS %2ibm · security key lifecycle manager29 Tem 2020
- CVE-2016-912440Planlayın
Revive Adserver before 3.2.3 suffers from Improper Restriction of Excessive Authentication Attempts.
KritikCVSS 9,8İstismar yokEPSS %2revive-adserver · revive adserver27 Mar 2017
- CVE-2018-147540Planlayın
IBM BigFix Platform 9.2 and 9.5 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credent
KritikCVSS 9,8İstismar yokEPSS %2ibm · bigfix platform27 Nis 2018
- CVE-2026-4459640Planlayın
Yamcs: No Rate Limiting on Authentication Endpoint
KritikCVSS 9,8Kavram kanıtıEPSS %2spaceapplications · yamcs16 Tem 2026