Skip to content
Noroxi

CWE-307 · 628 records

Improper Restriction of Excessive Authentication Attempts

CVEs in this class

628 records

  • bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many different forged X-

    CriticalCVSS 9.8Proof of conceptEPSS 40%

    bludit · bluditOct 6, 2019

  • tiki-login.php in Tiki before 21.2 sets the admin password to a blank value after 50 invalid login attempts.

    CriticalCVSS 9.8Proof of conceptEPSS 27%

    tiki · tikiOct 22, 2020

  • Digits < 8.4.6.1 - Auth Bypass via OTP Bruteforcing

    CriticalCVSS 9.8Proof of conceptEPSS 16%

    unitedover · digitsMay 21, 2025

  • GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16,

    CriticalCVSS 9.8No exploitEPSS 14%

    gl-inet · mt6000 firmwareAug 6, 2024

  • Improper restriction of excessive authentication attempts in the SSHGuard component of Netgate pfSense Plus software v22.05.1 and pfSense CE

    CriticalCVSS 9.8Proof of conceptEPSS 10%

    netgate · pfsense plusMar 22, 2023

  • The telnet server for 3Com hardware such as PS40 SuperStack II does not delay or disconnect remote attackers who provide an incorrect userna

    CriticalCVSS 9.8Proof of conceptEPSS 9%

    3com · superstack ii ps hub 40 firmwareJul 12, 2001

  • Beck IPC GmbH IPC@CHIP telnet service does not delay or disconnect users from the service when bad passwords are entered, which makes it eas

    CriticalCVSS 9.8Proof of conceptEPSS 7%

    anybus · ipc\@chip firmwareMay 24, 2001

  • A brute-force protection bypass in CAPTCHA protection in ASUS ROG Rapture GT-AX11000, RT-AX3000, RT-AX55, RT-AX56U, RT-AX56U_V2, RT-AX58U, R

    CriticalCVSS 9.8No exploitEPSS 6%

    asus · gt-ax11000 firmwareNov 19, 2021

  • An Improper Restriction of Excessive Authentication Attempts issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1100 progr

    CriticalCVSS 9.8No exploitEPSS 5%

    rockwellautomation · 1763-l16awa series aJun 29, 2017

  • Adobe ColdFusion Improper Restriction of Excessive Authentication Attempts Security feature bypass

    HighCVSS 7.5No exploitEPSS 35%

    adobe · coldfusionJul 12, 2023

  • The htdocs/index.php?mainmenu=home login page in Dolibarr 10.0.6 allows an unlimited rate of failed authentication attempts.

    CriticalCVSS 9.8No exploitEPSS 5%

    dolibarr · dolibarr erp\/crmJan 26, 2020

  • LimitLoginAttempts.php in the limit-login-attempts-reloaded plugin before 2.17.4 for WordPress allows a bypass of (per IP address) rate limi

    CriticalCVSS 9.8Proof of conceptEPSS 4%

    limitloginattempts · limit login attempts reloadedDec 21, 2020

  • EyesOfNetwork 5.3-10 uses an integer of between 8 and 10 digits for the session ID, which might be leveraged for brute-force authentication

    CriticalCVSS 9.8No exploitEPSS 4%

    eyesofnetwork · eyesofnetworkFeb 21, 2021

  • VAXstations running Open VMS 5.3 through 5.5-2 with VMS DECwindows or MOTIF do not properly disable access to user accounts that exceed the

    CriticalCVSS 9.8No exploitEPSS 3%

    hp · openvms vaxDec 31, 1999

  • IBM Security Guardium Big Data Intelligence (SonarG) 3.1 uses an inadequate account lockout setting that could allow a remote attacker to br

    CriticalCVSS 9.8No exploitEPSS 3%

    ibm · security guardium big data intelligenceMar 2, 2018

  • An Improper Restriction of Excessive Authentication Attempts issue was discovered in Belden Hirschmann RS, RSR, RSB, MACH100, MACH1000, MACH

    CriticalCVSS 9.8No exploitEPSS 3%

    belden · hirschmann rs20-0900mmm2tdauMar 6, 2018

  • A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists in PLC Simulator on EcoStruxureª Control Expert (n

    CriticalCVSS 9.8No exploitEPSS 3%

    schneider-electric · ecostruxure control expertNov 19, 2020

  • Moxa IKS and EDS do not implement sufficient measures to prevent multiple failed authentication attempts, which may allow an attacker to dis

    CriticalCVSS 9.8No exploitEPSS 3%

    moxa · iks-g6824a firmwareMar 5, 2019

  • CACAGOO Cloud Storage Intelligent Camera TV-288ZD-2MP with firmware 3.4.2.0919 has weak authentication of TELNET access, leading to root pri

    CriticalCVSS 9.8No exploitEPSS 2%

    cacagoo · tv-288zd-2mp firmwareApr 2, 2020

  • Windows IIS Server Elevation of Privilege Vulnerability

    CriticalCVSS 9.8No exploitEPSS 2%

    microsoft · windows 10 1507Oct 10, 2023

  • AutoPi Wi-Fi/NB and 4G/LTE devices before 2019-10-15 allows an attacker to perform a brute-force attack or dictionary attack to gain access

    CriticalCVSS 9.8No exploitEPSS 2%

    autopi · wi-fi\/nb firmwareOct 14, 2019

  • IBM Tivoli Key Lifecycle Manager 3.0.1 and 4.0 uses an inadequate account lockout setting that could allow a remote attacker to brute force

    CriticalCVSS 9.8No exploitEPSS 2%

    ibm · security key lifecycle managerJul 29, 2020

  • Revive Adserver before 3.2.3 suffers from Improper Restriction of Excessive Authentication Attempts.

    CriticalCVSS 9.8No exploitEPSS 2%

    revive-adserver · revive adserverMar 27, 2017

  • IBM BigFix Platform 9.2 and 9.5 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credent

    CriticalCVSS 9.8No exploitEPSS 2%

    ibm · bigfix platformApr 27, 2018

  • Yamcs: No Rate Limiting on Authentication Endpoint

    CriticalCVSS 9.8Proof of conceptEPSS 2%

    spaceapplications · yamcsJul 16, 2026

All vulnerability classes