CWE-307 · 628 records
Improper Restriction of Excessive Authentication Attempts
CVEs in this class
628 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
51Plan | CVE-2019-17240Proof of concept | bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many different forged X-bludit · bludit · CWE-307 | Critical9.8 | — | 39.6% | Oct 6, 2019 |
47Plan | CVE-2020-15906Proof of concept | tiki-login.php in Tiki before 21.2 sets the admin password to a blank value after 50 invalid login attempts.tiki · tiki · CWE-307 | Critical9.8 | — | 27.2% | Oct 22, 2020 |
44Plan | CVE-2025-4094Proof of concept | Digits < 8.4.6.1 - Auth Bypass via OTP Bruteforcingunitedover · digits · CWE-307 | Critical9.8 | — | 15.8% | May 21, 2025 |
43Plan | CVE-2024-39225No exploit | GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16,gl-inet · mt6000 firmware · CWE-307 | Critical9.8 | — | 14.4% | Aug 6, 2024 |
42Plan | CVE-2023-27100Proof of concept | Improper restriction of excessive authentication attempts in the SSHGuard component of Netgate pfSense Plus software v22.05.1 and pfSense CEnetgate · pfsense plus · CWE-307 | Critical9.8 | — | 9.8% | Mar 22, 2023 |
42Plan | CVE-2001-1291Proof of concept | The telnet server for 3Com hardware such as PS40 SuperStack II does not delay or disconnect remote attackers who provide an incorrect userna3com · superstack ii ps hub 40 firmware · CWE-307 | Critical9.8 | — | 8.9% | Jul 12, 2001 |
41Plan | CVE-2001-1339Proof of concept | Beck IPC GmbH IPC@CHIP telnet service does not delay or disconnect users from the service when bad passwords are entered, which makes it easanybus · ipc\@chip firmware · CWE-307 | Critical9.8 | — | 7.5% | May 24, 2001 |
41Plan | CVE-2021-41435No exploit | A brute-force protection bypass in CAPTCHA protection in ASUS ROG Rapture GT-AX11000, RT-AX3000, RT-AX55, RT-AX56U, RT-AX56U_V2, RT-AX58U, Rasus · gt-ax11000 firmware · CWE-307 | Critical9.8 | — | 6.5% | Nov 19, 2021 |
41Plan | CVE-2017-7898No exploit | An Improper Restriction of Excessive Authentication Attempts issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1100 progrrockwellautomation · 1763-l16awa series a · CWE-307 | Critical9.8 | — | 5.2% | Jun 29, 2017 |
40Plan | CVE-2023-29301No exploit | Adobe ColdFusion Improper Restriction of Excessive Authentication Attempts Security feature bypassadobe · coldfusion · CWE-307 | High7.5 | — | 34.7% | Jul 12, 2023 |
40Plan | CVE-2020-7995No exploit | The htdocs/index.php?mainmenu=home login page in Dolibarr 10.0.6 allows an unlimited rate of failed authentication attempts.dolibarr · dolibarr erp\/crm · CWE-307 | Critical9.8 | — | 4.5% | Jan 26, 2020 |
40Plan | CVE-2020-35590Proof of concept | LimitLoginAttempts.php in the limit-login-attempts-reloaded plugin before 2.17.4 for WordPress allows a bypass of (per IP address) rate limilimitloginattempts · limit login attempts reloaded · CWE-307 | Critical9.8 | — | 4.3% | Dec 21, 2020 |
40Plan | CVE-2021-27514No exploit | EyesOfNetwork 5.3-10 uses an integer of between 8 and 10 digits for the session ID, which might be leveraged for brute-force authentication eyesofnetwork · eyesofnetwork · CWE-307 | Critical9.8 | — | 3.5% | Feb 21, 2021 |
40Plan | CVE-1999-1324No exploit | VAXstations running Open VMS 5.3 through 5.5-2 with VMS DECwindows or MOTIF do not properly disable access to user accounts that exceed the hp · openvms vax · CWE-307 | Critical9.8 | — | 3.1% | Dec 31, 1999 |
40Plan | CVE-2018-1373No exploit | IBM Security Guardium Big Data Intelligence (SonarG) 3.1 uses an inadequate account lockout setting that could allow a remote attacker to bribm · security guardium big data intelligence · CWE-307 | Critical9.8 | — | 3.0% | Mar 2, 2018 |
40Plan | CVE-2018-5469No exploit | An Improper Restriction of Excessive Authentication Attempts issue was discovered in Belden Hirschmann RS, RSR, RSB, MACH100, MACH1000, MACHbelden · hirschmann rs20-0900mmm2tdau · CWE-307 | Critical9.8 | — | 2.8% | Mar 6, 2018 |
40Plan | CVE-2020-28212No exploit | A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists in PLC Simulator on EcoStruxureª Control Expert (nschneider-electric · ecostruxure control expert · CWE-307 | Critical9.8 | — | 2.8% | Nov 19, 2020 |
40Plan | CVE-2019-6524No exploit | Moxa IKS and EDS do not implement sufficient measures to prevent multiple failed authentication attempts, which may allow an attacker to dismoxa · iks-g6824a firmware · CWE-307 | Critical9.8 | — | 2.7% | Mar 5, 2019 |
40Plan | CVE-2020-6852No exploit | CACAGOO Cloud Storage Intelligent Camera TV-288ZD-2MP with firmware 3.4.2.0919 has weak authentication of TELNET access, leading to root pricacagoo · tv-288zd-2mp firmware · CWE-307 | Critical9.8 | — | 2.4% | Apr 2, 2020 |
40Plan | CVE-2023-36434No exploit | Windows IIS Server Elevation of Privilege Vulnerabilitymicrosoft · windows 10 1507 · CWE-307 | Critical9.8 | — | 2.4% | Oct 10, 2023 |
40Plan | CVE-2019-12941No exploit | AutoPi Wi-Fi/NB and 4G/LTE devices before 2019-10-15 allows an attacker to perform a brute-force attack or dictionary attack to gain access autopi · wi-fi\/nb firmware · CWE-307 | Critical9.8 | — | 2.4% | Oct 14, 2019 |
40Plan | CVE-2020-4567No exploit | IBM Tivoli Key Lifecycle Manager 3.0.1 and 4.0 uses an inadequate account lockout setting that could allow a remote attacker to brute force ibm · security key lifecycle manager · CWE-307 | Critical9.8 | — | 2.3% | Jul 29, 2020 |
40Plan | CVE-2016-9124No exploit | Revive Adserver before 3.2.3 suffers from Improper Restriction of Excessive Authentication Attempts.revive-adserver · revive adserver · CWE-307 | Critical9.8 | — | 2.2% | Mar 27, 2017 |
40Plan | CVE-2018-1475No exploit | IBM BigFix Platform 9.2 and 9.5 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentibm · bigfix platform · CWE-307 | Critical9.8 | — | 2.2% | Apr 27, 2018 |
40Plan | CVE-2026-44596Proof of concept | Yamcs: No Rate Limiting on Authentication Endpointspaceapplications · yamcs · CWE-307 | Critical9.8 | — | 2.1% | Jul 16, 2026 |
- CVE-2019-1724051Plan
bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many different forged X-
CriticalCVSS 9.8Proof of conceptEPSS 40%bludit · bluditOct 6, 2019
- CVE-2020-1590647Plan
tiki-login.php in Tiki before 21.2 sets the admin password to a blank value after 50 invalid login attempts.
CriticalCVSS 9.8Proof of conceptEPSS 27%tiki · tikiOct 22, 2020
- CVE-2025-409444Plan
Digits < 8.4.6.1 - Auth Bypass via OTP Bruteforcing
CriticalCVSS 9.8Proof of conceptEPSS 16%unitedover · digitsMay 21, 2025
- CVE-2024-3922543Plan
GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16,
CriticalCVSS 9.8No exploitEPSS 14%gl-inet · mt6000 firmwareAug 6, 2024
- CVE-2023-2710042Plan
Improper restriction of excessive authentication attempts in the SSHGuard component of Netgate pfSense Plus software v22.05.1 and pfSense CE
CriticalCVSS 9.8Proof of conceptEPSS 10%netgate · pfsense plusMar 22, 2023
- CVE-2001-129142Plan
The telnet server for 3Com hardware such as PS40 SuperStack II does not delay or disconnect remote attackers who provide an incorrect userna
CriticalCVSS 9.8Proof of conceptEPSS 9%3com · superstack ii ps hub 40 firmwareJul 12, 2001
- CVE-2001-133941Plan
Beck IPC GmbH IPC@CHIP telnet service does not delay or disconnect users from the service when bad passwords are entered, which makes it eas
CriticalCVSS 9.8Proof of conceptEPSS 7%anybus · ipc\@chip firmwareMay 24, 2001
- CVE-2021-4143541Plan
A brute-force protection bypass in CAPTCHA protection in ASUS ROG Rapture GT-AX11000, RT-AX3000, RT-AX55, RT-AX56U, RT-AX56U_V2, RT-AX58U, R
CriticalCVSS 9.8No exploitEPSS 6%asus · gt-ax11000 firmwareNov 19, 2021
- CVE-2017-789841Plan
An Improper Restriction of Excessive Authentication Attempts issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1100 progr
CriticalCVSS 9.8No exploitEPSS 5%rockwellautomation · 1763-l16awa series aJun 29, 2017
- CVE-2023-2930140Plan
Adobe ColdFusion Improper Restriction of Excessive Authentication Attempts Security feature bypass
HighCVSS 7.5No exploitEPSS 35%adobe · coldfusionJul 12, 2023
- CVE-2020-799540Plan
The htdocs/index.php?mainmenu=home login page in Dolibarr 10.0.6 allows an unlimited rate of failed authentication attempts.
CriticalCVSS 9.8No exploitEPSS 5%dolibarr · dolibarr erp\/crmJan 26, 2020
- CVE-2020-3559040Plan
LimitLoginAttempts.php in the limit-login-attempts-reloaded plugin before 2.17.4 for WordPress allows a bypass of (per IP address) rate limi
CriticalCVSS 9.8Proof of conceptEPSS 4%limitloginattempts · limit login attempts reloadedDec 21, 2020
- CVE-2021-2751440Plan
EyesOfNetwork 5.3-10 uses an integer of between 8 and 10 digits for the session ID, which might be leveraged for brute-force authentication
CriticalCVSS 9.8No exploitEPSS 4%eyesofnetwork · eyesofnetworkFeb 21, 2021
- CVE-1999-132440Plan
VAXstations running Open VMS 5.3 through 5.5-2 with VMS DECwindows or MOTIF do not properly disable access to user accounts that exceed the
CriticalCVSS 9.8No exploitEPSS 3%hp · openvms vaxDec 31, 1999
- CVE-2018-137340Plan
IBM Security Guardium Big Data Intelligence (SonarG) 3.1 uses an inadequate account lockout setting that could allow a remote attacker to br
CriticalCVSS 9.8No exploitEPSS 3%ibm · security guardium big data intelligenceMar 2, 2018
- CVE-2018-546940Plan
An Improper Restriction of Excessive Authentication Attempts issue was discovered in Belden Hirschmann RS, RSR, RSB, MACH100, MACH1000, MACH
CriticalCVSS 9.8No exploitEPSS 3%belden · hirschmann rs20-0900mmm2tdauMar 6, 2018
- CVE-2020-2821240Plan
A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists in PLC Simulator on EcoStruxureª Control Expert (n
CriticalCVSS 9.8No exploitEPSS 3%schneider-electric · ecostruxure control expertNov 19, 2020
- CVE-2019-652440Plan
Moxa IKS and EDS do not implement sufficient measures to prevent multiple failed authentication attempts, which may allow an attacker to dis
CriticalCVSS 9.8No exploitEPSS 3%moxa · iks-g6824a firmwareMar 5, 2019
- CVE-2020-685240Plan
CACAGOO Cloud Storage Intelligent Camera TV-288ZD-2MP with firmware 3.4.2.0919 has weak authentication of TELNET access, leading to root pri
CriticalCVSS 9.8No exploitEPSS 2%cacagoo · tv-288zd-2mp firmwareApr 2, 2020
- CVE-2023-3643440Plan
Windows IIS Server Elevation of Privilege Vulnerability
CriticalCVSS 9.8No exploitEPSS 2%microsoft · windows 10 1507Oct 10, 2023
- CVE-2019-1294140Plan
AutoPi Wi-Fi/NB and 4G/LTE devices before 2019-10-15 allows an attacker to perform a brute-force attack or dictionary attack to gain access
CriticalCVSS 9.8No exploitEPSS 2%autopi · wi-fi\/nb firmwareOct 14, 2019
- CVE-2020-456740Plan
IBM Tivoli Key Lifecycle Manager 3.0.1 and 4.0 uses an inadequate account lockout setting that could allow a remote attacker to brute force
CriticalCVSS 9.8No exploitEPSS 2%ibm · security key lifecycle managerJul 29, 2020
- CVE-2016-912440Plan
Revive Adserver before 3.2.3 suffers from Improper Restriction of Excessive Authentication Attempts.
CriticalCVSS 9.8No exploitEPSS 2%revive-adserver · revive adserverMar 27, 2017
- CVE-2018-147540Plan
IBM BigFix Platform 9.2 and 9.5 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credent
CriticalCVSS 9.8No exploitEPSS 2%ibm · bigfix platformApr 27, 2018
- CVE-2026-4459640Plan
Yamcs: No Rate Limiting on Authentication Endpoint
CriticalCVSS 9.8Proof of conceptEPSS 2%spaceapplications · yamcsJul 16, 2026