CWE-307: CWE-307

178
Total CVEs
69
Critical
73
High
8.1
Avg CVSS

Yearly Trend

2026
14
2025
57
2024
36
2023
33
2022
9

Top Affected Vendors

1 Ibm 9
2 Dell 7
3 Siemens 4
4 Nextcloud 4
5 Fortinet 3
6 Schneider Electric 3
7 Endress 3
8 Gl Inet 3
9 Moodle 2
10 Dlink 2

All CWE-307 CVEs (178)

CVE-2025-28172
6.5

Grandstream UCM6510 PBX systems running firmware v1.0.20.52 and earlier lack rate limiting on authentication attempts, allowing attackers to brute for...

Jul 29, 2025
CVE-2025-1496
6.5

This vulnerability allows attackers to perform password brute-forcing attacks against BG-TEK Coslat Hotspot systems due to insufficient rate limiting ...

Mar 20, 2025
CVE-2024-38488
6.5

Dell RecoverPoint for Virtual Machines 6.0.x has an authentication rate limiting vulnerability that allows attackers to perform brute-force or diction...

Dec 13, 2024
CVE-2024-5682
6.5

This vulnerability allows attackers to perform unlimited authentication attempts against the Yordam Library Automation System login interface, potenti...

Sep 18, 2024
CVE-2025-52997
5.9

File Browser versions before 2.34.1 lack password policy enforcement and brute-force protection, allowing attackers to guess passwords through repeate...

Jun 30, 2025
CVE-2025-55003
5.7

OpenBao's MFA system in versions 2.3.1 and below has a TOTP code validation flaw where whitespace in codes bypasses rate limiting, allowing attackers ...

Aug 9, 2025
CVE-2025-6015
5.7

This vulnerability allows attackers to bypass multi-factor authentication (MFA) rate limiting and reuse TOTP tokens in HashiCorp Vault, potentially en...

Aug 1, 2025
CVE-2025-52392
5.4

Soosyze CMS 2.0 has a brute-force vulnerability that allows attackers to make unlimited login attempts without rate limiting or account lockout. This ...

Aug 13, 2025
CVE-2023-34732
5.4

This vulnerability in Flytxt NEON-dX allows attackers to perform brute force attacks against the change password function by exploiting the userId par...

May 12, 2025
CVE-2025-12310
5.3

This vulnerability in VirtFusion allows attackers to bypass rate limiting on email change authentication attempts, potentially enabling brute-force at...

Oct 27, 2025
CVE-2025-22645
5.3

This vulnerability allows attackers to bypass CAPTCHA protection and perform unlimited password brute-force attempts against the Real Estate Manager W...

Feb 18, 2025
CVE-2024-3102
5.3

A JSON injection vulnerability in the anything-llm application allows attackers to perform brute force attacks against the login system without knowin...

Jun 6, 2024
CVE-2023-48745
5.3

This vulnerability allows attackers to bypass CAPTCHA protection in WebFactory Ltd's Captcha Code WordPress plugin by making excessive authentication ...

Jun 4, 2024
CVE-2023-48276
5.3

This vulnerability allows attackers to bypass the CAPTCHA protection in the WP Forms Puzzle Captcha WordPress plugin by making excessive authenticatio...

Jun 4, 2024
CVE-2023-48290
5.3

This vulnerability allows attackers to bypass CAPTCHA protection in the Form Maker by 10Web WordPress plugin by making excessive authentication attemp...

Jun 4, 2024
CVE-2023-45009
5.3

This vulnerability allows attackers to bypass CAPTCHA protection in the Contact Form 7 plugin for WordPress by exploiting improper rate limiting on au...

Jun 4, 2024
CVE-2023-44235
5.3

This vulnerability allows attackers to bypass CAPTCHA protection in the WP Captcha WordPress plugin by making excessive authentication attempts withou...

Jun 4, 2024
CVE-2024-32720
5.3

This vulnerability allows attackers to bypass CAPTCHA protection in the Appointment Hour Booking WordPress plugin through excessive authentication att...

May 17, 2024
CVE-2025-67090
5.1

The LuCI web interface on GL.Inet AX1800 routers lacks rate limiting or account lockout mechanisms on the authentication endpoint, allowing unauthenti...

Jan 8, 2026
CVE-2025-47951
4.9

Weblate versions before 5.12 lack rate limiting on second-factor authentication endpoints, allowing attackers with valid credentials to automate OTP g...

Jun 16, 2025
CVE-2025-3129
4.8

This vulnerability allows attackers to perform brute force attacks against Drupal Access code authentication mechanisms due to insufficient rate limit...

Apr 2, 2025
CVE-2024-51720
4.8

An insufficient entropy vulnerability in SecuSUITE Secure Client Authentication Server allows attackers to potentially enroll attacker-controlled devi...

Nov 12, 2024
CVE-2025-12896
4.4

This vulnerability in Solidigm DC Products firmware allows attackers with local or physical access to bypass storage device security locks. It affects...

Nov 7, 2025
CVE-2026-2110
3.7

This vulnerability allows attackers to perform unlimited authentication attempts against the SwiftBuy login page, potentially enabling brute-force att...

Feb 7, 2026
CVE-2026-1685
3.7

This vulnerability in D-Link DIR-823X routers allows attackers to bypass authentication attempt limits, potentially enabling brute-force attacks on lo...

Jan 30, 2026
CVE-2026-1409
2.0

This vulnerability in Beetel 777VR1 routers allows attackers to bypass authentication rate limiting via the UART interface, potentially gaining unauth...

Jan 26, 2026
CVE-2025-42615
N/A

This vulnerability allows attackers to brute-force two-factor authentication (2FA) codes without rate limiting or account lockout. An attacker who has...

Dec 8, 2025
CVE-2025-11566
N/A

This vulnerability allows attackers on the local network to brute-force authentication on the /REST/shutdownnow endpoint, potentially gaining unauthor...

Nov 12, 2025

About CWE-307 (CWE-307)

Our database tracks 178 CVEs classified as CWE-307, with 69 rated critical and 73 rated high severity. The average CVSS score for CWE-307 vulnerabilities is 8.1.

External reference: View CWE-307 on MITRE CWE →

Monitor CWE-307 Vulnerabilities

Get alerted when new CWE-307 CVEs affect your infrastructure.

Start Monitoring Free