CWE-307: CWE-307

177
Total CVEs
69
Critical
72
High
8.1
Avg CVSS

Yearly Trend

2026
14
2025
57
2024
36
2023
33
2022
9

Top Affected Vendors

1 Ibm 9
2 Dell 7
3 Siemens 4
4 Nextcloud 4
5 Fortinet 3
6 Schneider Electric 3
7 Endress 3
8 Gl Inet 3
9 Moodle 2
10 Dlink 2

All CWE-307 CVEs (177)

CVE-2025-53544
7.5

CVE-2025-53544 is a brute-force protection bypass vulnerability in Trilium Notes that allows unauthenticated attackers to guess the login password wit...

Aug 5, 2025
CVE-2025-27456
7.5

This vulnerability allows attackers to perform brute-force attacks against SMB server login mechanisms due to insufficient rate limiting. It affects s...

Jul 3, 2025
CVE-2025-1710
7.5

CVE-2025-1710 is an authentication brute-force vulnerability in maxView Storage Manager that allows attackers to guess credentials through repeated lo...

Jul 3, 2025
CVE-2025-27449
7.5

The MEAC300-FNADE4 device lacks rate limiting for authentication attempts, allowing attackers to systematically guess passwords via brute-force attack...

Jul 3, 2025
CVE-2025-48014
7.5

This vulnerability allows attackers to bypass password guessing limits when LDAP authentication is used, enabling brute-force attacks against user acc...

May 20, 2025
CVE-2024-51476
7.5

IBM Concert Software 1.0.5 has an inadequate account lockout mechanism that allows attackers to perform brute force attacks against user credentials. ...

Mar 6, 2025
CVE-2024-57610
7.5

CVE-2024-57610 is a rate limiting vulnerability in Sylius v2.0.2 that allows attackers to perform unlimited brute-force attacks on user accounts. This...

Feb 6, 2025
CVE-2024-55008
7.5

JATOS 3.9.4 contains an authentication DoS vulnerability where attackers can lock any user account indefinitely by submitting 3 failed login attempts ...

Jan 7, 2025
CVE-2024-7292
7.5

This vulnerability allows attackers to perform credential stuffing attacks against Progress Telerik Report Server by bypassing login attempt restricti...

Oct 9, 2024
CVE-2024-45327
7.5

An improper authorization vulnerability in FortiSOAR's change password endpoint allows authenticated attackers to perform brute force attacks against ...

Sep 11, 2024
CVE-2024-41904
7.5

SINEC Traffic Analyzer versions before V2.0 lack proper rate limiting on authentication attempts, allowing unauthenticated attackers to perform brute ...

Aug 13, 2024
CVE-2024-39874
7.5

SINEMA Remote Connect Server versions before V3.2 SP1 lack proper brute force protection in the Client Communication component, allowing attackers to ...

Jul 9, 2024
CVE-2024-5862
7.5

This vulnerability allows attackers to bypass authentication rate limiting in Mia-Med Health Application, enabling brute-force attacks on login interf...

Jun 24, 2024
CVE-2023-45191
7.5

This vulnerability in IBM Engineering Lifecycle Optimization allows remote attackers to brute force account credentials due to inadequate account lock...

Feb 9, 2024
CVE-2023-50326
7.5

IBM PowerSC versions 1.3, 2.0, and 2.1 have an inadequate account lockout mechanism that allows remote attackers to perform brute-force attacks agains...

Feb 2, 2024
CVE-2023-6912
7.5

M-Files Server versions before 23.12.13205.0 lack brute force protection, allowing attackers unlimited authentication attempts to guess user passwords...

Dec 20, 2023
CVE-2023-50444
7.5

This vulnerability allows unauthenticated attackers to brute-force encrypted sensitive user information stored in .ZED containers created by affected ...

Dec 13, 2023
CVE-2023-41350
7.5

This vulnerability allows unauthenticated remote attackers to bypass CAPTCHA protection on Chunghwa Telecom NOKIA G-040W-Q routers, enabling automated...

Nov 3, 2023
CVE-2023-37832
7.5

CVE-2023-37832 is a vulnerability in Elenos ETG150 FM transmitter firmware that lacks rate limiting on authentication endpoints, allowing attackers to...

Oct 31, 2023
CVE-2015-20110
7.5

CVE-2015-20110 is a timing attack vulnerability in JHipster's token validation that allows attackers to brute-force authentication tokens character by...

Oct 31, 2023
CVE-2023-44111
7.5

This CVE describes a vulnerability in Huawei device authentication modules that allows brute-force attacks. Attackers can repeatedly attempt authentic...

Oct 11, 2023
CVE-2022-43904
7.5

IBM Security Guardium versions 11.3 and 11.4 have an authentication flaw that allows attackers to bypass rate limiting on login attempts. This enables...

Aug 28, 2023
CVE-2022-32757
7.5

IBM Security Directory Suite VA 8.0.1 through 8.0.1.19 has an inadequate account lockout setting that allows remote attackers to perform brute force a...

Jun 15, 2023
CVE-2023-23755
7.5

This vulnerability in Joomla! allows attackers to perform brute force attacks against multi-factor authentication (MFA) methods due to insufficient ra...

May 30, 2023
CVE-2023-26756
7.5

The login page of Revive Adserver v5.4.1 is vulnerable to brute force attacks, allowing attackers to guess user credentials through repeated login att...

Apr 14, 2023
CVE-2023-29005
7.5

Flask-AppBuilder versions before 4.3.0 lack built-in rate limiting for authentication endpoints, allowing attackers to perform unlimited brute-force a...

Apr 10, 2023
CVE-2022-22452
7.5

IBM Security Verify Identity Manager 10.0 has an inadequate account lockout setting that allows attackers to perform brute force attacks against user ...

Jul 14, 2022
CVE-2021-41807
7.5

This vulnerability allows attackers to perform unlimited login attempts against certain M-Files user accounts, enabling brute-force attacks to guess p...

Jan 18, 2022
CVE-2021-38890
7.5

IBM Sterling Connect:Direct Web Services has an inadequate account lockout mechanism that allows remote attackers to perform brute-force attacks again...

Nov 23, 2021
CVE-2021-38155
7.5

This vulnerability in OpenStack Keystone allows unauthenticated attackers to confirm account existence and obtain account UUIDs through failed authent...

Aug 6, 2021
CVE-2021-27943
7.5

This vulnerability allows an attacker to brute-force the pairing code between Vizio Smart TVs and the mobile app, enabling remote control of TV settin...

Aug 2, 2021
CVE-2021-3663
7.5

CVE-2021-3663 is an authentication rate limiting vulnerability in Firefly III personal finance software that allows attackers to perform unlimited log...

Jul 25, 2021
CVE-2020-23283
7.5

This vulnerability in MV's mConnect application allows attackers to determine valid user accounts through brute force attacks on the login page. It af...

Jul 21, 2021
CVE-2021-28127
7.5

This vulnerability in Stormshield Network Security (SNS) firewalls allows brute-force attacks against authentication mechanisms. Attackers can attempt...

Jul 1, 2021
CVE-2020-26556
7.5

This vulnerability in Bluetooth Mesh provisioning allows a nearby attacker to brute-force the AuthValue during device pairing before the provisioning ...

May 24, 2021
CVE-2021-28248
7.5

CVE-2021-28248 allows attackers to perform unlimited authentication attempts against CA eHealth Performance Manager web interface, enabling brute-forc...

Mar 26, 2021
CVE-2021-25676
7.5

This vulnerability in Siemens industrial networking devices allows attackers to cause a denial-of-service by repeatedly attempting SSH authentication....

Mar 15, 2021
CVE-2026-27981
7.4

This vulnerability allows attackers to bypass authentication rate limiting in HomeBox by forging IP headers, enabling brute-force attacks on login cre...

Mar 3, 2026
CVE-2025-10161
7.3

This vulnerability in Turkguven Software Technologies Inc. Perfektive allows attackers to bypass authentication and functionality through brute force ...

Nov 11, 2025
CVE-2021-3412
7.3

CVE-2021-3412 is a brute force vulnerability in all versions of 3Scale developer portal that lacks login attempt protections. Attackers can exploit th...

Jun 1, 2021
CVE-2025-46603
7.0

Dell CloudBoost Virtual Appliance versions 19.13.0.0 and earlier have a vulnerability that allows attackers to bypass authentication rate limiting. Un...

Dec 5, 2025
CVE-2024-38888
6.8

This vulnerability in Caterease software allows local attackers to perform password brute-forcing attacks due to insufficient restrictions on authenti...

Aug 2, 2024
CVE-2025-67091
6.5

A race condition vulnerability in GL.iNet AX1800 router firmware allows authenticated attackers to bypass file locking mechanisms and potentially exec...

Jan 8, 2026
CVE-2025-65427
6.5

This vulnerability allows attackers to perform unlimited password guessing attempts against the Dbit N300 T1 Pro router's login API endpoint. Attacker...

Dec 16, 2025
CVE-2025-66482
6.5

This vulnerability allows attackers to bypass IP-based rate limiting in Misskey by forging X-Forwarded-For headers. It affects Misskey instances runni...

Dec 16, 2025
CVE-2025-9551
6.5

This vulnerability in Drupal Protected Pages module allows attackers to perform brute force attacks by bypassing rate limiting on authentication attem...

Oct 10, 2025
CVE-2025-58587
6.5

This vulnerability allows attackers to perform brute-force attacks against authentication systems by attempting multiple login attempts without rate l...

Oct 6, 2025
CVE-2025-10658
6.5

The SupportCandy WordPress plugin has an authentication bypass vulnerability that allows unauthenticated attackers to brute-force 6-digit OTP codes an...

Sep 20, 2025
CVE-2025-57815
6.5

Fides Admin UI login endpoint lacks specific anti-automation controls, allowing attackers to conduct credential testing attacks like brute-force, cred...

Sep 8, 2025
CVE-2025-28172
6.5

Grandstream UCM6510 PBX systems running firmware v1.0.20.52 and earlier lack rate limiting on authentication attempts, allowing attackers to brute for...

Jul 29, 2025

About CWE-307 (CWE-307)

Our database tracks 177 CVEs classified as CWE-307, with 69 rated critical and 72 rated high severity. The average CVSS score for CWE-307 vulnerabilities is 8.1.

External reference: View CWE-307 on MITRE CWE →

Monitor CWE-307 Vulnerabilities

Get alerted when new CWE-307 CVEs affect your infrastructure.

Start Monitoring Free