VYPR

CWE-307

Improper Restriction of Excessive Authentication Attempts

BaseDraft

Description

The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-16 · CAPEC-49 · CAPEC-560 · CAPEC-565 · CAPEC-600 · CAPEC-652 · CAPEC-653

CVEs mapped to this weakness (623)

page 28 of 32
  • CVE-2025-10761LowSep 21, 2025
    risk 0.24cvss 3.7epss 0.01

    A vulnerability has been found in Harness 3.3.0. Affected is an unknown function of the file /api/v1/login of the component Login Endpoint. The manipulation leads to improper restriction of excessive authentication attempts. Remote exploitation of the attack is possible. The…

  • CVE-2025-9004LowAug 15, 2025
    risk 0.24cvss 3.7epss 0.01

    A vulnerability was found in mtons mblog up to 3.5.0. This issue affects some unknown processing of the file /settings/password. The manipulation leads to improper restriction of excessive authentication attempts. The attack may be initiated remotely. The complexity of an attack…

  • CVE-2025-8927LowAug 13, 2025
    risk 0.24cvss 3.7epss 0.01

    A vulnerability was determined in mtons mblog up to 3.5.0. Affected by this issue is some unknown functionality of the file /email/send_code of the component Verification Code Handler. The manipulation of the argument email leads to improper restriction of excessive…

  • CVE-2025-8742LowAug 8, 2025
    risk 0.24cvss 3.7epss 0.01

    A vulnerability was found in macrozheng mall 1.0.3. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Admin Login. The manipulation leads to improper restriction of excessive authentication attempts. The attack may be…

  • CVE-2025-5864LowJun 9, 2025
    risk 0.24cvss 3.7epss 0.00

    A vulnerability was found in Tenda TDSEE App up to 1.7.12. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /app/ConfirmSmsCode of the component Password Reset Confirmation Code Handler. The manipulation leads to…

  • CVE-2025-3556LowApr 14, 2025
    risk 0.24cvss 3.7epss 0.01

    A vulnerability classified as problematic was found in ScriptAndTools eCommerce-website-in-PHP 3.0. Affected by this vulnerability is an unknown functionality of the file /admin/login.php. The manipulation leads to improper restriction of excessive authentication attempts. The…

  • CVE-2025-3555LowApr 14, 2025
    risk 0.24cvss 3.7epss 0.01

    A vulnerability classified as problematic has been found in ScriptAndTools eCommerce-website-in-PHP 3.0. Affected is an unknown function of the file /login.php. The manipulation leads to improper restriction of excessive authentication attempts. It is possible to launch the…

  • CVE-2024-3202LowApr 2, 2024
    risk 0.24cvss 3.7epss 0.01

    A vulnerability, which was classified as problematic, has been found in codelyfe Stupid Simple CMS 1.2.4. This issue affects some unknown processing of the component Login Page. The manipulation leads to improper restriction of excessive authentication attempts. The attack may…

  • CVE-2023-26209LowMar 9, 2023
    risk 0.24cvss 3.7epss 0.02

    A improper restriction of excessive authentication attempts vulnerability [CWE-307] in Fortinet FortiDeceptor 3.1.x and before allows a remote unauthenticated attacker to partially exhaust CPU and memory via sending numerous HTTP requests to the login form.

  • CVE-2023-26208LowMar 9, 2023
    risk 0.24cvss 3.7epss 0.02

    A improper restriction of excessive authentication attempts vulnerability [CWE-307] in Fortinet FortiAuthenticator 6.4.x and before allows a remote unauthenticated attacker to partially exhaust CPU and memory via sending numerous HTTP requests to the login form.

  • CVE-2022-29056LowMar 9, 2023
    risk 0.24cvss 3.7epss 0.02

    A improper restriction of excessive authentication attempts vulnerability [CWE-307] in Fortinet FortiMail version 6.4.0, version 6.2.0 through 6.2.4 and before 6.0.9 allows a remote unauthenticated attacker to partially exhaust CPU and memory via sending numerous HTTP requests…

  • CVE-2022-34389LowFeb 11, 2023
    risk 0.24cvss 3.7epss 0.00

    Dell SupportAssist contains a rate limit bypass issues in screenmeet API third party component. An unauthenticated attacker could potentially exploit this vulnerability and impersonate a legitimate dell customer to a dell support technician.

  • CVE-2022-30305LowDec 6, 2022
    risk 0.24cvss 3.7epss 0.01

    An insufficient logging [CWE-778] vulnerability in FortiSandbox versions 4.0.0 to 4.0.2, 3.2.0 to 3.2.3 and 3.1.0 to 3.1.5 and FortiDeceptor versions 4.2.0, 4.1.0 through 4.1.1, 4.0.0 through 4.0.2, 3.3.0 through 3.3.3, 3.2.0 through 3.2.2,3.1.0 through 3.1.1 and 3.0.0 through…

  • CVE-2022-3031LowOct 17, 2022
    risk 0.24cvss 3.7epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. It may be possible for an attacker to guess a user's password by brute force by sending crafted…

  • CVE-2020-29042LowNov 26, 2020
    risk 0.24cvss 3.7epss 0.01

    An issue was discovered in BigBlueButton through 2.2.29. A brute-force attack may occur because an unlimited number of codes can be entered for a meeting that is protected by an access code.

  • CVE-2025-1629LowFeb 24, 2025
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was found in Excitel Broadband Private my Excitel App 3.13.0 on Android. It has been classified as problematic. Affected is an unknown function of the component One-Time Password Handler. The manipulation leads to improper restriction of excessive authentication…

  • CVE-2023-41270LowNov 8, 2023
    risk 0.23cvss 3.5epss 0.00

    Improper Restriction of Excessive Authentication Attempts vulnerability in Samsung Smart TV UE40D7000 version T-GAPDEUC-1033.2 and before allows attackers to cause a denial of service via WPS attack tools.

  • CVE-2023-3669LowAug 3, 2023
    risk 0.21cvss 3.3epss 0.00

    A missing Brute-Force protection in CODESYS Development System prior to 3.5.19.20 allows a local attacker to have unlimited attempts of guessing the password within an import dialog.

  • CVE-2022-4797MedDec 28, 2022
    risk 0.21cvss 4.3epss 0.01

    Improper Restriction of Excessive Authentication Attempts in GitHub repository usememos/memos prior to 0.9.1.

  • CVE-2025-7882LowJul 20, 2025
    risk 0.20cvss 3.1epss 0.00

    A vulnerability was found in Mercusys MW301R 1.0.2 Build 190726 Rel.59423n. It has been rated as problematic. This issue affects some unknown processing of the component Login. The manipulation leads to improper restriction of excessive authentication attempts. The attack can…