Previously, there was no throttling on repeated authentication attempts to the charging station backend, which could al
PasswordPusher before 2.9.2 contains a brute-force vulnerability in the POST /p/:token/access endpoint that lacks route-
The miniOrange 2FA WordPress plugin before 6.2.8 does not correctly limit the number of second-factor verification attem
SiYuan before 3.7.4 contains an improper restriction of excessive authentication attempts vulnerability in the authFileP
SiYuan versions before 3.7.4 contain an unthrottled brute-force vulnerability in the Publish Service Basic Auth implemen
Monkeytype is a minimalistic and customizable typing test. In 26.26.0 and earlier, the backend rate-limit key generator
The affected Ebyte device does not restrict repeated authentication attempts through rate limiting or account lockout m
WWBN AVideo (current e01e41ecc and earlier) contains a brute-force rate limiting bypass in enforceRateLimit(), which pro
HomeBox is a home inventory and organization system. Prior to 0.24.0, the authentication rate limiter (authRateLimiter)
Git for Windows is the Windows port of Git. Prior to 2.53.0(2), it is possible to obtain a user's NTLM hash by tricking
OpenProject is an open-source project management application. In versions prior to 17.3.0, 2FA OTP verification in the c
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Versions pri
phpMyFAQ before 4.1.7 contains a brute-force vulnerability in the two-factor authentication step where the failure count
The login limit is not enforced on the SFTP service of Fortra's GoAnywhere MFT prior to 7.10.0 if the Web User attemptin
Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.4, there is a security vulnerability in Vaul
Better Auth is an authentication and authorization library for TypeScript. Prior to 1.4.17 and 1.5.0-beta.9, Better Auth
9Router is an AI router & token saver. Prior to 0.4.80, the dashboard login rate limiter in src/lib/auth/loginLimiter.js
dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat
@fastify/rate-limit before 11.2.0 keys rate-limit buckets by the verbatim client IP string returned from request.ip. Bec
UnixAuth lacks brute-force protection in Apache Ranger versions <= 2.8.0. Note: UnixAuth is NOT a recommended option f
MCO is vulnerable to Account Denial of Service due to improper implementation of password reset functionality. Each pass
Rate Limiting for attempting a user login is not being properly enforced, making HCL DevOps Velocity susceptible to brut
An issue in GL Inet GL.Inet AX1800 Version 4.6.4 & 4.6.8 are vulnerable. GL.Inet AX1800 Version 4.6.4 & 4.6.8 in the GL.
OpenProject is an open-source, web-based project management software. Prior to version 16.6.2, OpenProject’s unauthentic
SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain an authentication bypass vulnerability that allows re
OpenClaw before 2026.3.12 applies rate limiting only after successful webhook authentication, allowing attackers to bypa
OpenClaw before 2026.3.28 contains a missing rate limiting vulnerability in the Nextcloud Talk webhook authentication th
Eaton Intelligent Power Protector (IPP) software allows repeated authentication attempts against the web interface login
Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.0.0 to befo
Improper restriction of excessive authentication attempts (CWE-307) in pgAdmin 4. pgAdmin enforces MAX_LOGIN_ATTEMPTS o
** UNSUPPORTED WHEN ASSIGNED ** An improper restriction of excessive authentication attempts vulnerability in the web ma
Yamcs is a mission control framework. Prior to 5.12.7, the authentication endpoint POST /auth/token in yamcs-core, handl
changedetection.io's /login route checks the submitted password against a single PBKDF2-HMAC-SHA256 hash with no per-IP
WWBN AVideo contains an unauthenticated credential submission vulnerability in plugin/Live/api/preauthorize.json.php tha
Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 enables WPS 2.0 by default with a weak lockout policy (60-secon
Improper restriction of excessive authentication attempts vulnerability in Turkiye Electricity Transmission Corporation
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 cont
The RTSP service of MERCURY IP camera MIPC252W 1.0.5 Build 230306 has an issue handling failed Digest authentication att
IBM DevOps Plan 3.0.0 through 3.0.5 uses an inadequate account lockout setting that could allow a remote attacker to bru
Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Vaultwarden ve
Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the TOTP failed-attempt lockout mechanis
@node-oauth/oauth2-server is a module for implementing an OAuth2 server in Node.js. The token exchange path accepts RFC7
vulnerability in Drupal Brute force attack protection allows . This issue affects Brute force attack protection versions
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver
HCL AION is affected by a vulnerability where certain endpoints lack sufficient anti-automation controls. Automated or s
HCL AION is affected by a vulnerability where adequate protections against brute-force attempts are not enforced. This m
Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Login Disable allows Brute Force. This
Improper Restriction of Excessive Authentication Attempts, Improper Authentication vulnerability in Doruk Communication
calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to version 9.
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `get_api_video_password_is_corre
Frequently Asked Questions
What is CWE-307?
CWE-307 (CWE-307) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-307?
There are 147 CVE records associated with CWE-307 in our database. Of these, 17 are critical severity, 54 are high severity, and 47 are medium severity.
How can I protect against CWE-307 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-307 using AI-powered security agents.
Detect CWE-307 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-307 vulnerabilities across your infrastructure.
Get Started