Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-307

MITRE ↗

CWE-307

17
CRITICAL
54
HIGH
47
MEDIUM
13
LOW
143 CVEs · Page 1/3
9.8
CVE-2026-24436

Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) do not enforce rate limiting or account l

9.8
CVE-2025-69246

Raytha CMS does not have any brute force protection mechanism implemented. It allows an attacker to send multiple automa

9.8
CVE-2026-31851

Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 does not implement rate limiting or account lockout mec

9.8
CVE-2026-33640

Outline is a service that allows for collaborative documentation. Outline implements an Email OTP login flow for users n

9.8
CVE-2026-33879

Federated Learning and Interoperability Platform (FLIP) is an open-source platform for federated training and evaluation

9.8
CVE-2020-37228

iDS6 DSSPro Digital Signage System 6.2 contains a CAPTCHA security bypass vulnerability that allows attackers to bypass

9.8
CVE-2026-8760

The Login with OTP plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.6

9.8
CVE-2026-6853

Improper restriction of excessive authentication attempts vulnerability in Başbelen Group Food Cafe Businesses Industry

9.8
CVE-2026-73046

SiYuan before v3.7.4 improperly restricts excessive authentication attempts in the CheckAuth() middleware. The HTTP Basi

9.8
CVE-2026-73056

SiYuan kernel versions before 3.7.4 contain an improper restriction of excessive authentication attempts vulnerability i

9.4
CVE-2025-4319

Improper Restriction of Excessive Authentication Attempts, Weak Password Recovery Mechanism for Forgotten Password vulne

9.1
CVE-2025-69615

Incorrect Access Control via missing 2FA rate-limiting allowing unlimited brute-force retries and full MFA bypass with n

9.1
CVE-2026-33152

Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. In versions prior t

9.1
CVE-2026-45010

phpMyFAQ before 4.1.2 contains an improper restriction of excessive authentication attempts vulnerability in the /admin/

9.1
CVE-2026-71213

Typemill's login endpoint (POST /tm/login, ControllerWebAuth::login) performs no rate-limiting, failed-attempt counting,

9.1
CVE-2026-19297

IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain unauthorized access to user accounts due to

9.1
CVE-2026-78655

Punk::Plugin::TOTP versions before 0.05 for Perl allow the second-factor attempt limit to be reset by replaying an earli

8.8
CVE-2026-41037

This vulnerability exists in Quantum Networks router due to missing rate limiting and CAPTCHA protection for failed logi

8.8
CVE-2026-36607

Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 allows unauthenticated brute-force attacks via the TDDP

8.8
CVE-2026-16347

MikroTik RouterOS contains a weakness in its API authentication handling that lacks effective safeguards against excessi

8.2
CVE-2026-35675

phpMyFAQ before 4.1.3 contains an authentication bypass vulnerability in the password reset endpoint that allows unauthe

8.1
CVE-2026-22278

Dell PowerScale OneFS versions prior to 9.13.0.0 contains an improper restriction of excessive authentication attempts v

8.1
CVE-2026-32729

Runtipi is a personal homeserver orchestrator. Prior to 4.8.1, The Runtipi /api/auth/verify-totp endpoint does not enfor

7.5
CVE-2025-53968

This vulnerability arises because there are no limitations on the number of authentication attempts a user can make. An

7.5
CVE-2025-67853

A flaw was found in Moodle. A remote attacker could exploit a lack of proper rate limiting in the confirmation email ser

7.5
CVE-2026-25577

Emmett is a framework designed to simplify your development process. Prior to 1.3.11, the cookies property in mmett_core

7.5
CVE-2026-27521

Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior do not implement rate limiting or accoun

7.5
CVE-2026-20792

The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absen

7.5
CVE-2026-25113

The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absen

7.5
CVE-2026-25114

The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absen

7.5
CVE-2026-25945

The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absen

7.5
CVE-2026-24445

The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absen

7.5
CVE-2026-26305

The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absen

7.5
CVE-2026-27778

The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absenc

7.5
CVE-2026-20882

The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absenc

7.5
CVE-2026-24696

The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absenc

7.5
CVE-2026-32292

The GL-iNet Comet (GL-RM1) KVM web interface does not limit login requests, enabling brute-force attempts to guess crede

7.5
CVE-2026-32295

JetKVM before 0.5.4 does not rate limit login requests, enabling brute-force attempts to guess credentials.

7.5
CVE-2026-32025

OpenClaw versions prior to 2026.2.25 contain an authentication hardening gap in browser-origin WebSocket clients that al

7.5
CVE-2026-31903

The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absenc

7.5
CVE-2026-31904

The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absenc

7.5
CVE-2026-33419

MinIO is a high-performance object storage system. Prior to RELEASE.2026-03-17T21-25-16Z, MinIO AIStor's STS (Security T

7.5
CVE-2026-33935

MyTube is a self-hosted downloader and player for several video websites Prior to version 1.8.72, an unauthenticated att

7.5
CVE-2026-40586

blueprintUE is a tool to help Unreal Engine developers. Prior to 4.2.0, the login form handler performs no throttling of

7.5
CVE-2026-6947

DWM-222W USB Wi-Fi Adapter developed by D-Link has a Brute-Force Protection Bypass vulnerability, allowing unauthenticat

7.5
CVE-2026-36959

U-SPEED N300 router V1.0.0 does not implement rate limiting or account lockout protections on the /api/login endpoint. T

7.5
CVE-2023-54347

OpenEMR 7.0.1 contains an authentication brute force vulnerability that allows attackers to bypass rate limiting protect

7.5
CVE-2026-41893

Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.25.0, the HTTP login en

7.5
CVE-2026-3329

A remote unauthenticated attacker may be able to conduct credential-guessing attacks against user accounts in Sonatype N

7.5
CVE-2026-50176

The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absenc

Frequently Asked Questions

What is CWE-307?

CWE-307 (CWE-307) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-307?

There are 147 CVE records associated with CWE-307 in our database. Of these, 17 are critical severity, 54 are high severity, and 47 are medium severity.

How can I protect against CWE-307 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-307 using AI-powered security agents.

Detect CWE-307 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-307 vulnerabilities across your infrastructure.

Get Started