CWE-307: CWE-307
Yearly Trend
Top Affected Vendors
All CWE-307 CVEs (177)
CVE-2025-53544 is a brute-force protection bypass vulnerability in Trilium Notes that allows unauthenticated attackers to guess the login password wit...
Aug 5, 2025This vulnerability allows attackers to perform brute-force attacks against SMB server login mechanisms due to insufficient rate limiting. It affects s...
Jul 3, 2025CVE-2025-1710 is an authentication brute-force vulnerability in maxView Storage Manager that allows attackers to guess credentials through repeated lo...
Jul 3, 2025The MEAC300-FNADE4 device lacks rate limiting for authentication attempts, allowing attackers to systematically guess passwords via brute-force attack...
Jul 3, 2025This vulnerability allows attackers to bypass password guessing limits when LDAP authentication is used, enabling brute-force attacks against user acc...
May 20, 2025IBM Concert Software 1.0.5 has an inadequate account lockout mechanism that allows attackers to perform brute force attacks against user credentials. ...
Mar 6, 2025CVE-2024-57610 is a rate limiting vulnerability in Sylius v2.0.2 that allows attackers to perform unlimited brute-force attacks on user accounts. This...
Feb 6, 2025JATOS 3.9.4 contains an authentication DoS vulnerability where attackers can lock any user account indefinitely by submitting 3 failed login attempts ...
Jan 7, 2025This vulnerability allows attackers to perform credential stuffing attacks against Progress Telerik Report Server by bypassing login attempt restricti...
Oct 9, 2024An improper authorization vulnerability in FortiSOAR's change password endpoint allows authenticated attackers to perform brute force attacks against ...
Sep 11, 2024SINEC Traffic Analyzer versions before V2.0 lack proper rate limiting on authentication attempts, allowing unauthenticated attackers to perform brute ...
Aug 13, 2024SINEMA Remote Connect Server versions before V3.2 SP1 lack proper brute force protection in the Client Communication component, allowing attackers to ...
Jul 9, 2024This vulnerability allows attackers to bypass authentication rate limiting in Mia-Med Health Application, enabling brute-force attacks on login interf...
Jun 24, 2024This vulnerability in IBM Engineering Lifecycle Optimization allows remote attackers to brute force account credentials due to inadequate account lock...
Feb 9, 2024IBM PowerSC versions 1.3, 2.0, and 2.1 have an inadequate account lockout mechanism that allows remote attackers to perform brute-force attacks agains...
Feb 2, 2024M-Files Server versions before 23.12.13205.0 lack brute force protection, allowing attackers unlimited authentication attempts to guess user passwords...
Dec 20, 2023This vulnerability allows unauthenticated attackers to brute-force encrypted sensitive user information stored in .ZED containers created by affected ...
Dec 13, 2023This vulnerability allows unauthenticated remote attackers to bypass CAPTCHA protection on Chunghwa Telecom NOKIA G-040W-Q routers, enabling automated...
Nov 3, 2023CVE-2023-37832 is a vulnerability in Elenos ETG150 FM transmitter firmware that lacks rate limiting on authentication endpoints, allowing attackers to...
Oct 31, 2023CVE-2015-20110 is a timing attack vulnerability in JHipster's token validation that allows attackers to brute-force authentication tokens character by...
Oct 31, 2023This CVE describes a vulnerability in Huawei device authentication modules that allows brute-force attacks. Attackers can repeatedly attempt authentic...
Oct 11, 2023IBM Security Guardium versions 11.3 and 11.4 have an authentication flaw that allows attackers to bypass rate limiting on login attempts. This enables...
Aug 28, 2023IBM Security Directory Suite VA 8.0.1 through 8.0.1.19 has an inadequate account lockout setting that allows remote attackers to perform brute force a...
Jun 15, 2023This vulnerability in Joomla! allows attackers to perform brute force attacks against multi-factor authentication (MFA) methods due to insufficient ra...
May 30, 2023The login page of Revive Adserver v5.4.1 is vulnerable to brute force attacks, allowing attackers to guess user credentials through repeated login att...
Apr 14, 2023Flask-AppBuilder versions before 4.3.0 lack built-in rate limiting for authentication endpoints, allowing attackers to perform unlimited brute-force a...
Apr 10, 2023IBM Security Verify Identity Manager 10.0 has an inadequate account lockout setting that allows attackers to perform brute force attacks against user ...
Jul 14, 2022This vulnerability allows attackers to perform unlimited login attempts against certain M-Files user accounts, enabling brute-force attacks to guess p...
Jan 18, 2022IBM Sterling Connect:Direct Web Services has an inadequate account lockout mechanism that allows remote attackers to perform brute-force attacks again...
Nov 23, 2021This vulnerability in OpenStack Keystone allows unauthenticated attackers to confirm account existence and obtain account UUIDs through failed authent...
Aug 6, 2021This vulnerability allows an attacker to brute-force the pairing code between Vizio Smart TVs and the mobile app, enabling remote control of TV settin...
Aug 2, 2021CVE-2021-3663 is an authentication rate limiting vulnerability in Firefly III personal finance software that allows attackers to perform unlimited log...
Jul 25, 2021This vulnerability in MV's mConnect application allows attackers to determine valid user accounts through brute force attacks on the login page. It af...
Jul 21, 2021This vulnerability in Stormshield Network Security (SNS) firewalls allows brute-force attacks against authentication mechanisms. Attackers can attempt...
Jul 1, 2021This vulnerability in Bluetooth Mesh provisioning allows a nearby attacker to brute-force the AuthValue during device pairing before the provisioning ...
May 24, 2021CVE-2021-28248 allows attackers to perform unlimited authentication attempts against CA eHealth Performance Manager web interface, enabling brute-forc...
Mar 26, 2021This vulnerability in Siemens industrial networking devices allows attackers to cause a denial-of-service by repeatedly attempting SSH authentication....
Mar 15, 2021This vulnerability allows attackers to bypass authentication rate limiting in HomeBox by forging IP headers, enabling brute-force attacks on login cre...
Mar 3, 2026This vulnerability in Turkguven Software Technologies Inc. Perfektive allows attackers to bypass authentication and functionality through brute force ...
Nov 11, 2025CVE-2021-3412 is a brute force vulnerability in all versions of 3Scale developer portal that lacks login attempt protections. Attackers can exploit th...
Jun 1, 2021Dell CloudBoost Virtual Appliance versions 19.13.0.0 and earlier have a vulnerability that allows attackers to bypass authentication rate limiting. Un...
Dec 5, 2025This vulnerability in Caterease software allows local attackers to perform password brute-forcing attacks due to insufficient restrictions on authenti...
Aug 2, 2024A race condition vulnerability in GL.iNet AX1800 router firmware allows authenticated attackers to bypass file locking mechanisms and potentially exec...
Jan 8, 2026This vulnerability allows attackers to perform unlimited password guessing attempts against the Dbit N300 T1 Pro router's login API endpoint. Attacker...
Dec 16, 2025This vulnerability allows attackers to bypass IP-based rate limiting in Misskey by forging X-Forwarded-For headers. It affects Misskey instances runni...
Dec 16, 2025This vulnerability in Drupal Protected Pages module allows attackers to perform brute force attacks by bypassing rate limiting on authentication attem...
Oct 10, 2025This vulnerability allows attackers to perform brute-force attacks against authentication systems by attempting multiple login attempts without rate l...
Oct 6, 2025The SupportCandy WordPress plugin has an authentication bypass vulnerability that allows unauthenticated attackers to brute-force 6-digit OTP codes an...
Sep 20, 2025Fides Admin UI login endpoint lacks specific anti-automation controls, allowing attackers to conduct credential testing attacks like brute-force, cred...
Sep 8, 2025Grandstream UCM6510 PBX systems running firmware v1.0.20.52 and earlier lack rate limiting on authentication attempts, allowing attackers to brute for...
Jul 29, 2025About CWE-307 (CWE-307)
Our database tracks 177 CVEs classified as CWE-307, with 69 rated critical and 72 rated high severity. The average CVSS score for CWE-307 vulnerabilities is 8.1.
External reference: View CWE-307 on MITRE CWE →
Monitor CWE-307 Vulnerabilities
Get alerted when new CWE-307 CVEs affect your infrastructure.
Start Monitoring Free