CWE-307 Improper Restriction of Excessive Authentication Attempts vulnerability exists that would allow an attacker to g
ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the public API login endpoint (/api/pu
Improper restriction of excessive authentication attempts vulnerability in Hitachi Virtual Storage Platform G130, G150,
OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.7, a logic flaw in the OPNsense lockout_handler
Strapi is an open source headless content management system. In Strapi versions prior to 5.45.0, the rate-limit middlewa
Capgo before 12.128.2 contains a credential validation vulnerability in the POST /functions/v1/private/validate_password
OpenClaw 2026.2.25 before 2026.5.26 allow a lower-trust caller or configured input path to bypass non-browser rate limit
The Mira cloud authentication endpoints do not enforce per-account rate limiting, per-IP throttling, or account lockout
Plainpad through 1.1.1, fixed in commit d3823fc, contains a missing rate limiting vulnerability that allows unauthentica
HCL Hive is affected by a missing rate limit which could allow an attacker unauthorized access via brute-force or creden
Rocket.Chat exposes the sendForgotPasswordEmail Meteor method without a DDP rate limit, so an unauthenticated caller may
The LuCI web interface on Gl Inet GL.Inet AX1800 Version 4.6.4 & 4.6.8 are vulnerable. Fix available in version 4.8.2 GL
OneUptime is a solution for monitoring and managing online services. The resend-verification-code endpoint allows any au
OpenClaw before 2026.3.25 contains a missing rate limiting vulnerability in webhook authentication that allows attackers
OpenClaw before 2026.3.25 contains a missing rate limiting vulnerability in Telegram webhook authentication that allows
OpenClaw before 2026.3.25 contains a pre-authentication rate-limit bypass vulnerability in webhook token validation that
Uncontrolled resource consumption in the Wireless Control Module (WCM) of the Indian Motorcycle Scout Bobber + Tech 2025
Improper restriction of excessive authentication attempts vulnerability in Universal Software Inc. FlexCity allows Exces
A vulnerability was identified in D-Link DIR-823X 250416. This vulnerability affects the function sub_40AC74 of the comp
A security flaw has been discovered in Tasin1025 SwiftBuy up to 0f5011372e8d1d7edfd642d57d721c9fadc54ec7. Affected by th
VideoLAN VLC for Android prior to version 3.7.0 contains an authentication bypass in the Remote Access Server feature du
An improper restriction of excessive authentication attempts vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4
A vulnerability has been found in CodeWise Tornet Scooter Mobile App 4.75 on iOS/Android. The impacted element is an unk
A vulnerability was detected in unitedbyai droidclaw up to 0.5.3. The affected element is an unknown function of the fil
A vulnerability was detected in opensourcepos Open Source Point of Sale up to 3.4.2. This affects the function Login::in
A vulnerability has been found in mangroup dtale up to 3.22.0. This issue affects the function Login of the file dtale/a
A vulnerability was found in VictoriaMetrics up to 1.146.0. Impacted is the function requestHandler of the file app/vmau
A vulnerability was found in karakeep-app karakeep up to 0.32.0. The affected element is the function authorize of the f
Anytype Heart is the middleware library for Anytype. The challenge-based authentication for the local gRPC client API ca
Successful exploitation of this vulnerability could allow an attacker with local network access to bypass the applicatio
A security vulnerability has been detected in Beetel 777VR1 up to 01.00.09/01.00.09_55. This issue affects some unknown
FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, the password reset conf
Authelia is an open-source authentication and authorization server providing two-factor authentication and single sign-o
AIL did not restrict repeated failed attempts to verify a two-factor authentication (OTP) code. An attacker who had reac
NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, sign-in response timing differed between
An Improper Authorization vulnerability exists in PayloadCMS version 3.84.1 due to insufficient access control on the ac
KTM System e-BOK does not implement any limit or timeout on consecutive login attempts, allowing an attacker to perform
A race condition in the account lockout mechanism in Delphix Continous Data allowed the lockout threshold to be bypassed
This vulnerability exists in CP PLUS EZ-P21 IP Camera due to improper authentication of HTTP endpoints. A remote attacke
PaperCut NG/MF does not properly restrict excessive authentication attempts within its login component. An unauthenticat
RansomLook contains multiple weaknesses in its authentication endpoint that allow an unauthenticated remote attacker to
Typebot is an open-source chatbot builder. In self-hosted versions up to and including 3.17.1, the default passwordless
WatchGuard Dimension's web login endpoint does not enforce effective rate-limiting or account lockout by default allowin
Moxa IKS and EDS do not implement sufficient measures to prevent multiple failed authentication attempts, which may allo
Plataformatec Devise version 4.5.0 and earlier, using the lockable module contains a CWE-367 vulnerability in The `Devis
IBM Robotic Process Automation with Automation Anywhere 11 uses an inadequate account lockout setting that could allow a
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0 SP1). The web interface has no
Dell EMC ECS versions prior to 3.4.0.0 contain an improper restriction of excessive authentication attempts vulnerabilit
An issue was discovered on V-Zug Combi-Steam MSLQ devices before Ethernet R07 and before WLAN R05. There is no bruteforc
bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many
Frequently Asked Questions
What is CWE-307?
CWE-307 (CWE-307) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-307?
There are 215 CVE records associated with CWE-307 in our database. Of these, 44 are critical severity, 69 are high severity, and 56 are medium severity.
How can I protect against CWE-307 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-307 using AI-powered security agents.
Detect CWE-307 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-307 vulnerabilities across your infrastructure.
Get Started