Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-307

MITRE ↗

CWE-307

17
CRITICAL
54
HIGH
47
MEDIUM
13
LOW
143 CVEs · Page 2/3
7.5
CVE-2026-42952

Previously, there was no throttling on repeated authentication attempts to the charging station backend, which could al

7.5
CVE-2026-61458

PasswordPusher before 2.9.2 contains a brute-force vulnerability in the POST /p/:token/access endpoint that lacks route-

7.5
CVE-2026-16619

The miniOrange 2FA WordPress plugin before 6.2.8 does not correctly limit the number of second-factor verification attem

7.5
CVE-2026-73045

SiYuan before 3.7.4 contains an improper restriction of excessive authentication attempts vulnerability in the authFileP

7.5
CVE-2026-74868

SiYuan versions before 3.7.4 contain an unthrottled brute-force vulnerability in the Publish Service Basic Auth implemen

7.5
CVE-2026-69183

Monkeytype is a minimalistic and customizable typing test. In 26.26.0 and earlier, the backend rate-limit key generator

7.5
CVE-2026-76940

The affected Ebyte device does not restrict repeated authentication attempts through rate limiting or account lockout m

7.5
CVE-2026-82644

WWBN AVideo (current e01e41ecc and earlier) contains a brute-force rate limiting bypass in enforceRateLimit(), which pro

7.4
CVE-2026-27981

HomeBox is a home inventory and organization system. Prior to 0.24.0, the authentication rate limiter (authRateLimiter)

7.4
CVE-2025-66413

Git for Windows is the Windows port of Git. Prior to 2.53.0(2), it is possible to obtain a user's NTLM hash by tricking

7.4
CVE-2026-33667

OpenProject is an open-source project management application. In versions prior to 17.3.0, 2FA OTP verification in the c

7.4
CVE-2026-48084

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Versions pri

7.4
CVE-2026-76213

phpMyFAQ before 4.1.7 contains a brute-force vulnerability in the two-factor authentication step where the failure count

7.3
CVE-2025-14362

The login limit is not enforced on the SFTP service of Fortra's GoAnywhere MFT prior to 7.10.0 if the Web User attemptin

7.3
CVE-2026-43914

Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.4, there is a security vulnerability in Vaul

7.3
CVE-2026-45364

Better Auth is an authentication and authorization library for TypeScript. Prior to 1.4.17 and 1.5.0-beta.9, Better Auth

7.3
CVE-2026-55501

9Router is an AI router & token saver. Prior to 0.4.80, the dashboard login rate limiter in src/lib/auth/loginLimiter.js

7.3
CVE-2026-32825

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat

7.3
CVE-2026-15144

@fastify/rate-limit before 11.2.0 keys rate-limit buckets by the verbatim client IP string returned from request.ip. Bec

7.3
CVE-2026-65948

UnixAuth lacks brute-force protection in Apache Ranger versions <= 2.8.0.  Note:  UnixAuth is NOT a recommended option f

7.1
CVE-2026-53904

MCO is vulnerable to Account Denial of Service due to improper implementation of password reset functionality. Each pass

6.8
CVE-2025-31991

Rate Limiting for attempting a user login is not being properly enforced, making HCL DevOps Velocity susceptible to brut

6.5
CVE-2025-67091

An issue in GL Inet GL.Inet AX1800 Version 4.6.4 & 4.6.8 are vulnerable. GL.Inet AX1800 Version 4.6.4 & 4.6.8 in the GL.

6.5
CVE-2026-22603

OpenProject is an open-source, web-based project management software. Prior to version 16.6.2, OpenProject’s unauthentic

6.5
CVE-2026-27753

SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain an authentication bypass vulnerability that allows re

6.5
CVE-2026-34505

OpenClaw before 2026.3.12 applies rate limiting only after successful webhook authentication, allowing attackers to bypa

6.5
CVE-2026-33580

OpenClaw before 2026.3.28 contains a missing rate limiting vulnerability in the Nextcloud Talk webhook authentication th

6.5
CVE-2026-22616

Eaton Intelligent Power Protector (IPP) software allows repeated authentication attempts against the web interface login

6.5
CVE-2026-26206

Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.0.0 to befo

6.5
CVE-2026-7820

Improper restriction of excessive authentication attempts (CWE-307) in pgAdmin 4. pgAdmin enforces MAX_LOGIN_ATTEMPTS o

6.5
CVE-2026-7255

** UNSUPPORTED WHEN ASSIGNED ** An improper restriction of excessive authentication attempts vulnerability in the web ma

6.5
CVE-2026-44596

Yamcs is a mission control framework. Prior to 5.12.7, the authentication endpoint POST /auth/token in yamcs-core, handl

6.5
CVE-2026-71205

changedetection.io's /login route checks the submitted password against a single PBKDF2-HMAC-SHA256 hash with no per-IP

6.5
CVE-2026-82643

WWBN AVideo contains an unauthenticated credential submission vulnerability in plugin/Live/api/preauthorize.json.php tha

6.4
CVE-2026-36612

Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 enables WPS 2.0 by default with a weak lockout policy (60-secon

6.3
CVE-2026-1816

Improper restriction of excessive authentication attempts vulnerability in Turkiye Electricity Transmission Corporation

6.2
CVE-2025-46606

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 cont

6.2
CVE-2026-35902

The RTSP service of MERCURY IP camera MIPC252W 1.0.5 Build 230306 has an issue handling failed Digest authentication att

5.9
CVE-2025-36363

IBM DevOps Plan 3.0.0 through 3.0.5 uses an inadequate account lockout setting that could allow a remote attacker to bru

5.9
CVE-2026-27801

Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Vaultwarden ve

5.9
CVE-2026-35597

Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the TOTP failed-attempt lockout mechanis

5.9
CVE-2026-41213

@node-oauth/oauth2-server is a module for implementing an OAuth2 server in Node.js. The token exchange path accepts RFC7

5.9
CVE-2026-11915

vulnerability in Drupal Brute force attack protection allows . This issue affects Brute force attack protection versions

5.8
CVE-2026-48071

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver

5.6
CVE-2025-62314

HCL AION is affected by a vulnerability where certain endpoints lack sufficient anti-automation controls. Automated or s

5.4
CVE-2025-62313

HCL AION is affected by a vulnerability where adequate protections against brute-force attempts are not enforced. This m

5.4
CVE-2026-15079

Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Login Disable allows Brute Force. This

5.3
CVE-2025-7630

Improper Restriction of Excessive Authentication Attempts, Improper Authentication vulnerability in Doruk Communication

5.3
CVE-2026-27824

calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to version 9.

5.3
CVE-2026-33763

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `get_api_video_password_is_corre

Frequently Asked Questions

What is CWE-307?

CWE-307 (CWE-307) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-307?

There are 147 CVE records associated with CWE-307 in our database. Of these, 17 are critical severity, 54 are high severity, and 47 are medium severity.

How can I protect against CWE-307 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-307 using AI-powered security agents.

Detect CWE-307 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-307 vulnerabilities across your infrastructure.

Get Started