VYPR

CWE-307

Improper Restriction of Excessive Authentication Attempts

BaseDraft

Description

The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-16 · CAPEC-49 · CAPEC-560 · CAPEC-565 · CAPEC-600 · CAPEC-652 · CAPEC-653

CVEs mapped to this weakness (623)

page 29 of 32
  • CVE-2024-11126LowNov 12, 2024
    risk 0.20cvss 3.1epss 0.00

    A vulnerability was found in Digistar AG-30 Plus 2.6b. It has been classified as problematic. Affected is an unknown function of the component Login Page. The manipulation leads to improper restriction of excessive authentication attempts. The complexity of an attack is rather…

  • CVE-2026-41333LowApr 23, 2026
    risk 0.17cvss 3.7epss 0.00

    OpenClaw before 2026.3.31 contains an authentication rate limiting bypass vulnerability that allows attackers to circumvent shared authentication protections using fake device tokens. Attackers can exploit the mixed WebSocket authentication flow to bypass rate limiting controls…

  • CVE-2023-32251LowJul 31, 2025
    risk 0.17cvss 3.7epss 0.00

    A vulnerability has been identified in the Linux kernel's ksmbd component (kernel SMB/CIFS server). A security control designed to prevent dictionary attacks, which introduces a 5-second delay during session setup, can be bypassed through the use of asynchronous requests. This…

  • CVE-2024-42176LowMar 19, 2025
    risk 0.17cvss 2.6epss 0.00

    HCL MyXalytics is affected by concurrent login vulnerability. A concurrent login vulnerability occurs when simultaneous active sessions are allowed for a single credential allowing an attacker to potentially obtain access to a user's account or sensitive information.

  • CVE-2024-32771LowSep 6, 2024
    risk 0.17cvss 2.6epss 0.00

    An improper restriction of excessive authentication attempts vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow local network authenticated administrators to perform an arbitrary number of authentication…

  • CVE-2024-8462LowSep 5, 2024
    risk 0.17cvss 3.7epss 0.01

    A vulnerability was found in Windmill 1.380.0. It has been classified as problematic. Affected is an unknown function of the file backend/windmill-api/src/users.rs of the component HTTP Request Handler. The manipulation leads to improper restriction of excessive authentication…

  • CVE-2022-39314LowOct 24, 2022
    risk 0.17cvss 3.7epss 0.00

    Kirby is a flat-file CMS. In versions prior to 3.5.8.2, 3.6.6.2, 3.7.5.1, and 3.8.1, Kirby is subject to user enumeration due to Improper Restriction of Excessive Authentication Attempts. This vulnerability affects you only if you are using the `code` or `password-reset` auth…

  • CVE-2026-31863LowMar 11, 2026
    risk 0.16cvss 3.6epss 0.00

    Anytype Heart is the middleware library for Anytype. The challenge-based authentication for the local gRPC client API can be bypassed, allowing an attacker to gain access without the 4-digit code. This vulnerability is fixed in anytype-heart 0.48.4, anytype-cli 0.1.11, and…

  • CVE-2025-52916LowJun 21, 2025
    risk 0.14cvss 2.2epss 0.00

    Yealink RPS before 2025-06-04 lacks SN verification attempt limits, enabling brute-force enumeration (last five digits).

  • CVE-2026-1409LowJan 26, 2026
    risk 0.13cvss 2.0epss 0.00

    A security vulnerability has been detected in Beetel 777VR1 up to 01.00.09/01.00.09_55. This issue affects some unknown processing of the component UART Interface. The manipulation leads to improper restriction of excessive authentication attempts. It is possible to launch the…

  • CVE-2026-47203LowJun 19, 2026
    risk 0.12cvss epss 0.00

    Authelia is an open-source authentication and authorization server providing two-factor authentication and single sign-on (SSO) for applications via a web portal. In versions 4.38.0 through 4.39.19, when a user authenticates via Basic Auth (i.e via the `Authorization` header…

  • CVE-2025-24806LowFeb 19, 2025
    risk 0.08cvss epss 0.00

    Authelia is an open-source authentication and authorization server providing two-factor authentication and single sign-on (SSO) for applications via a web portal. If users are allowed to sign in via both username and email the regulation system treats these as separate login…

  • CVE-2019-17240CriOct 6, 2019
    risk 0.06cvss 9.8epss 0.40

    bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many different forged X-Forwarded-For or Client-IP HTTP headers.

  • CVE-2026-8793MedAug 3, 2026
    risk 0.00cvss epss 0.01

    PaperCut NG/MF does not properly restrict excessive authentication attempts within its login component. An unauthenticated remote attacker can exploit this vulnerability to perform unrestricted brute-force or credential-stuffing attacks without triggering account lockout or…

  • CVE-2026-55977LowJul 28, 2026
    risk 0.00cvss 3.3epss 0.00

    Successful exploitation of this vulnerability could allow an attacker with local network access to bypass the application's rate-limiting mechanism, enabling brute-forcing of the screen-sharing code and potentially displaying harmful content on the affected screen.

  • CVE-2026-65894HigJul 27, 2026
    risk 0.00cvss epss 0.00

    This vulnerability exists in CP PLUS EZ-P21 IP Camera due to improper authentication of HTTP endpoints. A remote attacker could exploit this vulnerability by conducting brute-force attacks against HTTP endpoint on the targeted device. Successful exploitation of this…

  • CVE-2026-8285MedJul 21, 2026
    risk 0.00cvss 4.3epss 0.00

    Improper restriction of excessive authentication attempts vulnerability in Universal Software Inc. FlexCity allows Excessive Allocation. This issue affects FlexCity: from 5.536.0 before 5.542.0.

  • CVE-2026-32825HigJul 20, 2026
    risk 0.00cvss 7.3epss 0.00

    dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, the application accepts unlimited password guesses…

  • CVE-2026-62220MedJul 17, 2026
    risk 0.00cvss 5.3epss 0.00

    OpenClaw 2026.2.25 before 2026.5.26 allow a lower-trust caller or configured input path to bypass non-browser rate limits on WebSocket authentication attempts. When the affected feature is enabled and reachable by lower-trust input, this can consume gateway resources and reduce…

  • CVE-2026-14254HigJul 16, 2026
    risk 0.00cvss epss 0.00

    A race condition in the account lockout mechanism in Delphix Continous Data allowed the lockout threshold to be bypassed through concurrent authentication requests. Parallel login attempts were processed before the failed-login counter and lockout status were updated,…