CWE-307: Improper Restriction of Excessive Authentication Attempts
The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.
418 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-64310 — EPSON WebConfig and Epson Web Control for SEIKO EPSON Projector Products do not restrict excessive authentication attemp
- CVE-2025-3709 — Flowring Technology Agentflow - Account Lockout Bypass
- CVE-2024-42466 — Lack of resources and rate limiting - login
- CVE-2025-6030 — Autoeastern Smart Keyless Entry System Replay Attack
- CVE-2025-6029 — KIA-branded Aftermarket Generic Smart Keyless Entry System Replay Attack
- CVE-2026-32295 — JetKVM insufficient login rate limiting
- CVE-2026-32292 — GL-iNet Comet (GL-RM1) KVM insufficient login rate-limiting
- CVE-2024-9832 — No limit on failed login attempts with Clinician Password or Serial Number Clinician Password on Life2000 Ventilator
- CVE-2024-51558 — Brute Force Attack Vulnerability in Wave 2.0
- CVE-2024-47656 — User Enumeration vulnerability
- CVE-2024-47088 — User Enumeration vulnerability
- CVE-2025-46414 — EG4 Electronics EG4 Inverters Improper Restriction of Excessive Authentication Attempts
- CVE-2026-33640 — Outline has a rate limit bypass that allows brute force of email login OTP
- CVE-2026-33419 — MinIO: LDAP login brute-force via user enumeration and missing rate limit
- CVE-2026-33152 — Tandoor Recipes Vulnerable to Unrestricted Brute-Force via BasicAuthentication
- CVE-2025-48187 — RAGFlow through 0.18.1 allows account takeover because it is possible to conduct successful brute-force attacks against
- CVE-2024-24767 — CasaOS Improper Restriction of Excessive Authentication Attempts vulnerability
- CVE-2024-22317 — IBM App Connect Enterprise denial of service
- CVE-2024-42465 — Lack of resources and rate limiting - two factor authentication
- CVE-2026-31904 — CTEK Chargeportal Improper Restriction of Excessive Authentication Attempts
Recently published
- CVE-2026-78490 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains
- CVE-2026-86729 — WWBN AVideo Unrestricted Authentication Attempts via get_api_preauthorize
- CVE-2026-6223 — OTP Bypass in Bahçelievler Muncipality's BiHayat App
- CVE-2026-20514 — In Audio HAL, there is a possible information disclosure due to a missing permission check. This could lead to local inf
- CVE-2026-20512 — In Audio HAL, there is a possible escalation of privilege due to improper input validation. This could lead to local esc
- CVE-2026-86186 — AVideo API Rate Limit Bypass via Bot User-Agent Header
- CVE-2026-85237 — Missing Rate Limiting in Email OTP Verification Allows Brute-Force Authentication Bypass
- CVE-2026-13348 — CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could allow an attacker to
- CVE-2026-16675 — Rockwell Automation FactoryTalk® Activation Manager - Privilege Escalation
- CVE-2026-82644 — WWBN AVideo Brute-force Rate Limiting Bypass via Missing User-Agent
- CVE-2026-82643 — WWBN AVideo Unauthenticated Rate Limit Bypass via preauthorize.json.php
- CVE-2026-78617 — WatchGuard Dimension Web UI Authentication Brute-Force Due to Missing Rate Limiting
- CVE-2026-76940 — Ebyte NA111-M Improper Restriction of Excessive Authentication Attempts
- CVE-2026-18260 — Disable Login Page - Moderately critical - Access bypass - SA-CONTRIB-2026-110
- CVE-2026-62862 — TypeBot: Account takeover via brute-forceable 6-digit magic-link code
- CVE-2026-78655 — Punk::Plugin::TOTP versions before 0.05 for Perl allow the second-factor attempt limit to be reset by replaying an earlier session cookie because the challenge route counts failures in the session
- CVE-2026-75575 — Rocket.Chat Missing DDP Rate Limit on the sendForgotPasswordEmail Meteor Method
- CVE-2026-78551 — RansomLook Login Endpoint Allows Timing-Based Username Enumeration and Unthrottled Authentication Attempts
- CVE-2026-21755 — HCL Hive is affected by a missing rate limit
- CVE-2026-69183 — Monkeytype: Rate-limit and anti-brute-force controls bypassable via spoofed HTTP headers (forgotPasswordEmail/verificationEmail mail bombing and badAuth bypass)