CWE-307: CWE-307
Yearly Trend
Top Affected Vendors
All CWE-307 CVEs (178)
Grandstream UCM6510 PBX systems running firmware v1.0.20.52 and earlier lack rate limiting on authentication attempts, allowing attackers to brute for...
Jul 29, 2025This vulnerability allows attackers to perform password brute-forcing attacks against BG-TEK Coslat Hotspot systems due to insufficient rate limiting ...
Mar 20, 2025Dell RecoverPoint for Virtual Machines 6.0.x has an authentication rate limiting vulnerability that allows attackers to perform brute-force or diction...
Dec 13, 2024This vulnerability allows attackers to perform unlimited authentication attempts against the Yordam Library Automation System login interface, potenti...
Sep 18, 2024File Browser versions before 2.34.1 lack password policy enforcement and brute-force protection, allowing attackers to guess passwords through repeate...
Jun 30, 2025OpenBao's MFA system in versions 2.3.1 and below has a TOTP code validation flaw where whitespace in codes bypasses rate limiting, allowing attackers ...
Aug 9, 2025This vulnerability allows attackers to bypass multi-factor authentication (MFA) rate limiting and reuse TOTP tokens in HashiCorp Vault, potentially en...
Aug 1, 2025Soosyze CMS 2.0 has a brute-force vulnerability that allows attackers to make unlimited login attempts without rate limiting or account lockout. This ...
Aug 13, 2025This vulnerability in Flytxt NEON-dX allows attackers to perform brute force attacks against the change password function by exploiting the userId par...
May 12, 2025This vulnerability in VirtFusion allows attackers to bypass rate limiting on email change authentication attempts, potentially enabling brute-force at...
Oct 27, 2025This vulnerability allows attackers to bypass CAPTCHA protection and perform unlimited password brute-force attempts against the Real Estate Manager W...
Feb 18, 2025A JSON injection vulnerability in the anything-llm application allows attackers to perform brute force attacks against the login system without knowin...
Jun 6, 2024This vulnerability allows attackers to bypass CAPTCHA protection in WebFactory Ltd's Captcha Code WordPress plugin by making excessive authentication ...
Jun 4, 2024This vulnerability allows attackers to bypass the CAPTCHA protection in the WP Forms Puzzle Captcha WordPress plugin by making excessive authenticatio...
Jun 4, 2024This vulnerability allows attackers to bypass CAPTCHA protection in the Form Maker by 10Web WordPress plugin by making excessive authentication attemp...
Jun 4, 2024This vulnerability allows attackers to bypass CAPTCHA protection in the Contact Form 7 plugin for WordPress by exploiting improper rate limiting on au...
Jun 4, 2024This vulnerability allows attackers to bypass CAPTCHA protection in the WP Captcha WordPress plugin by making excessive authentication attempts withou...
Jun 4, 2024This vulnerability allows attackers to bypass CAPTCHA protection in the Appointment Hour Booking WordPress plugin through excessive authentication att...
May 17, 2024The LuCI web interface on GL.Inet AX1800 routers lacks rate limiting or account lockout mechanisms on the authentication endpoint, allowing unauthenti...
Jan 8, 2026Weblate versions before 5.12 lack rate limiting on second-factor authentication endpoints, allowing attackers with valid credentials to automate OTP g...
Jun 16, 2025This vulnerability allows attackers to perform brute force attacks against Drupal Access code authentication mechanisms due to insufficient rate limit...
Apr 2, 2025An insufficient entropy vulnerability in SecuSUITE Secure Client Authentication Server allows attackers to potentially enroll attacker-controlled devi...
Nov 12, 2024This vulnerability in Solidigm DC Products firmware allows attackers with local or physical access to bypass storage device security locks. It affects...
Nov 7, 2025This vulnerability allows attackers to perform unlimited authentication attempts against the SwiftBuy login page, potentially enabling brute-force att...
Feb 7, 2026This vulnerability in D-Link DIR-823X routers allows attackers to bypass authentication attempt limits, potentially enabling brute-force attacks on lo...
Jan 30, 2026This vulnerability in Beetel 777VR1 routers allows attackers to bypass authentication rate limiting via the UART interface, potentially gaining unauth...
Jan 26, 2026This vulnerability allows attackers to brute-force two-factor authentication (2FA) codes without rate limiting or account lockout. An attacker who has...
Dec 8, 2025This vulnerability allows attackers on the local network to brute-force authentication on the /REST/shutdownnow endpoint, potentially gaining unauthor...
Nov 12, 2025About CWE-307 (CWE-307)
Our database tracks 178 CVEs classified as CWE-307, with 69 rated critical and 73 rated high severity. The average CVSS score for CWE-307 vulnerabilities is 8.1.
External reference: View CWE-307 on MITRE CWE →
Monitor CWE-307 Vulnerabilities
Get alerted when new CWE-307 CVEs affect your infrastructure.
Start Monitoring Free