VYPR

CWE-307

Improper Restriction of Excessive Authentication Attempts

BaseDraft

Description

The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-16 · CAPEC-49 · CAPEC-560 · CAPEC-565 · CAPEC-600 · CAPEC-652 · CAPEC-653

CVEs mapped to this weakness (623)

page 26 of 32
  • CVE-2026-35597MedApr 10, 2026
    risk 0.31cvss 5.9epss 0.00

    Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the TOTP failed-attempt lockout mechanism is non-functional due to a database transaction handling bug. When a TOTP validation fails, the login handler in pkg/routes/api/v1/login.go calls…

  • CVE-2026-27801MedMar 4, 2026
    risk 0.31cvss 5.9epss 0.00

    Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Vaultwarden versions 1.34.3 and prior are susceptible to a 2FA bypass when performing protected actions. An attacker who gains authenticated access to a user’s account can…

  • CVE-2025-52997MedJun 30, 2025
    risk 0.31cvss 5.9epss 0.00

    File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Prior to version 2.34.1, a missing password policy and brute-force protection makes the authentication process insecure. Attackers…

  • CVE-2025-3129MedApr 2, 2025
    risk 0.31cvss 4.8epss 0.00

    Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Access code allows Brute Force.This issue affects Access code: from 0.0.0 before 2.0.4.

  • CVE-2024-51720MedNov 12, 2024
    risk 0.31cvss 4.8epss 0.00

    An insufficient entropy vulnerability in the SecuSUITE Secure Client Authentication (SCA) Server of SecuSUITE versions 5.0.420 and earlier could allow an attacker to potentially enroll an attacker-controlled device to the victim’s account and telephone number.

  • CVE-2024-21500MedFeb 17, 2024
    risk 0.31cvss 4.8epss 0.01

    All versions of the package github.com/greenpau/caddy-security are vulnerable to Improper Restriction of Excessive Authentication Attempts via the two-factor authentication (2FA). Although the application blocks the user after several failed attempts to provide 2FA codes,…

  • CVE-2026-49324MedMay 29, 2026
    risk 0.30cvss 4.6epss 0.00

    Uncontrolled resource consumption in the Wireless Control Module (WCM) of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker with write access to the in-vehicle network to permanently immobilize the motorcycle. The WCM enforces a…

  • CVE-2025-55003MedAug 9, 2025
    risk 0.30cvss 5.7epss 0.00

    OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. In versions 2.3.1 and below, OpenBao's Login Multi-Factor Authentication (MFA) system allows enforcing MFA using Time-based One Time Password…

  • CVE-2022-28386MedJun 8, 2022
    risk 0.30cvss 4.6epss 0.00

    An issue was discovered in certain Verbatim drives through 2022-03-31. The security feature for lockout (e.g., requiring a reformat of the drive after 20 failed unlock attempts) does not work as specified. More than 20 attempts may be made. This affects Keypad Secure USB 3.2 Gen…

  • CVE-2019-5309MedNov 29, 2019
    risk 0.30cvss 4.6epss 0.00

    Honor play smartphones with versions earlier than 9.1.0.333(C00E333R1P1T8) have an information disclosure vulnerability in certain Huawei . An attacker could view certain information after a series of operation without unlock the screen lock. Successful exploit could cause an…

  • CVE-2019-5217MedJun 4, 2019
    risk 0.30cvss 4.6epss 0.00

    There is an information disclosure vulnerability on Mate 9 Pro Huawei smartphones versions earlier than LON-AL00B9.0.1.150 (C00E61R1P8T8). An attacker could view the photos after a series of operations without unlocking the screen lock. Successful exploit could cause an…

  • CVE-2025-12896MedNov 7, 2025
    risk 0.29cvss 4.4epss 0.00

    Improper resource management in firmware of some Solidigm DC Products may allow an attacker with local or physical access to gain un-authorized access to a locked storage device.

  • CVE-2026-15079MedJul 10, 2026
    risk 0.28cvss 5.4epss 0.00

    Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Login Disable allows Brute Force. This issue affects Login Disable versions: from 0.0.0 to 2.1.4.

  • CVE-2024-8429MedDec 17, 2024
    risk 0.28cvss 4.3epss 0.00

    Improper Restriction of Excessive Authentication Attempts vulnerability in Digital Operation Services WiFiBurada allows Use of Known Domain Credentials. This issue affects WiFiBurada: before 1.0.5.

  • CVE-2024-32774MedMay 17, 2024
    risk 0.28cvss 4.3epss 0.00

    Improper Restriction of Excessive Authentication Attempts vulnerability in Metagauss ProfileGrid allows Removing Important Client Functionality.This issue affects ProfileGrid : from n/a through 5.8.2.

  • CVE-2021-42096MedOct 21, 2021
    risk 0.28cvss 4.3epss 0.01

    GNU Mailman before 2.1.35 may allow remote Privilege Escalation. A certain csrf_token value is derived from the admin password, and may be useful in conducting a brute-force attack against that password.

  • CVE-2019-15577MedDec 18, 2019
    risk 0.28cvss 4.3epss 0.01

    An information disclosure vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed project milestones to be disclosed via groups browsing.

  • CVE-2026-56234MedJun 23, 2026
    risk 0.27cvss 5.3epss 0.00

    Capgo before 12.128.2 contains a credential validation vulnerability in the POST /functions/v1/private/validate_password_compliance endpoint that is callable using only the public Supabase key without authentication. The endpoint is CORS-permissive with wildcard origin allowance…

  • CVE-2025-64526MedMay 14, 2026
    risk 0.27cvss 5.3epss 0.00

    Strapi is an open source headless content management system. In Strapi versions prior to 5.45.0, the rate-limit middleware in the users-permissions plugin derived its rate-limit key in part from `ctx.request.body.email`, including on routes whose body schema does not contain an…

  • CVE-2026-44195MedMay 13, 2026
    risk 0.27cvss 5.3epss 0.00

    OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.7, a logic flaw in the OPNsense lockout_handler allows an unauthenticated attacker to continuously reset the authentication failure counter for their IP address. By interjecting a crafted username…