Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) do not enforce rate limiting or account l
Raytha CMS does not have any brute force protection mechanism implemented. It allows an attacker to send multiple automa
Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 does not implement rate limiting or account lockout mec
Outline is a service that allows for collaborative documentation. Outline implements an Email OTP login flow for users n
Federated Learning and Interoperability Platform (FLIP) is an open-source platform for federated training and evaluation
iDS6 DSSPro Digital Signage System 6.2 contains a CAPTCHA security bypass vulnerability that allows attackers to bypass
The Login with OTP plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.6
Improper restriction of excessive authentication attempts vulnerability in Başbelen Group Food Cafe Businesses Industry
SiYuan before v3.7.4 improperly restricts excessive authentication attempts in the CheckAuth() middleware. The HTTP Basi
SiYuan kernel versions before 3.7.4 contain an improper restriction of excessive authentication attempts vulnerability i
Improper Restriction of Excessive Authentication Attempts, Weak Password Recovery Mechanism for Forgotten Password vulne
Incorrect Access Control via missing 2FA rate-limiting allowing unlimited brute-force retries and full MFA bypass with n
Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. In versions prior t
phpMyFAQ before 4.1.2 contains an improper restriction of excessive authentication attempts vulnerability in the /admin/
Typemill's login endpoint (POST /tm/login, ControllerWebAuth::login) performs no rate-limiting, failed-attempt counting,
IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain unauthorized access to user accounts due to
Punk::Plugin::TOTP versions before 0.05 for Perl allow the second-factor attempt limit to be reset by replaying an earli
This vulnerability exists in Quantum Networks router due to missing rate limiting and CAPTCHA protection for failed logi
Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 allows unauthenticated brute-force attacks via the TDDP
MikroTik RouterOS contains a weakness in its API authentication handling that lacks effective safeguards against excessi
phpMyFAQ before 4.1.3 contains an authentication bypass vulnerability in the password reset endpoint that allows unauthe
Dell PowerScale OneFS versions prior to 9.13.0.0 contains an improper restriction of excessive authentication attempts v
Runtipi is a personal homeserver orchestrator. Prior to 4.8.1, The Runtipi /api/auth/verify-totp endpoint does not enfor
This vulnerability arises because there are no limitations on the number of authentication attempts a user can make. An
A flaw was found in Moodle. A remote attacker could exploit a lack of proper rate limiting in the confirmation email ser
Emmett is a framework designed to simplify your development process. Prior to 1.3.11, the cookies property in mmett_core
Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior do not implement rate limiting or accoun
The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absen
The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absen
The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absen
The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absen
The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absen
The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absen
The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absenc
The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absenc
The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absenc
The GL-iNet Comet (GL-RM1) KVM web interface does not limit login requests, enabling brute-force attempts to guess crede
JetKVM before 0.5.4 does not rate limit login requests, enabling brute-force attempts to guess credentials.
OpenClaw versions prior to 2026.2.25 contain an authentication hardening gap in browser-origin WebSocket clients that al
The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absenc
The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absenc
MinIO is a high-performance object storage system. Prior to RELEASE.2026-03-17T21-25-16Z, MinIO AIStor's STS (Security T
MyTube is a self-hosted downloader and player for several video websites Prior to version 1.8.72, an unauthenticated att
blueprintUE is a tool to help Unreal Engine developers. Prior to 4.2.0, the login form handler performs no throttling of
DWM-222W USB Wi-Fi Adapter developed by D-Link has a Brute-Force Protection Bypass vulnerability, allowing unauthenticat
U-SPEED N300 router V1.0.0 does not implement rate limiting or account lockout protections on the /api/login endpoint. T
OpenEMR 7.0.1 contains an authentication brute force vulnerability that allows attackers to bypass rate limiting protect
Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.25.0, the HTTP login en
A remote unauthenticated attacker may be able to conduct credential-guessing attacks against user accounts in Sonatype N
The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absenc
Frequently Asked Questions
What is CWE-307?
CWE-307 (CWE-307) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-307?
There are 147 CVE records associated with CWE-307 in our database. Of these, 17 are critical severity, 54 are high severity, and 47 are medium severity.
How can I protect against CWE-307 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-307 using AI-powered security agents.
Detect CWE-307 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-307 vulnerabilities across your infrastructure.
Get Started