← Back
CWE-307

607 CVEs • Abstraction: Base

Improper Restriction of Excessive Authentication Attempts

The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it more susceptible to brute force attacks.

JSON object

Loading...

CVEs (607)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
-
-
Jun 17, 2026
Jun 21, 2025
N/A· v4
2.2 LOW· v3
N/A· v2
Yealink RPS before 2025-06-04 lacks SN verification attempt limits, enabling brute-force enumeration (last five digits).
1Weblate
1Weblate
Jun 17, 2026
Jun 16, 2025
N/A· v4
4.9 MEDIUM· v3
N/A· v2
Weblate is a web based localization tool. Prior to version 5.12, the verification of the second factor was not subject to rate limiting. The absence of rate limiting on the second factor endpoint allows an attacker with...Show more
Weblate is a web based localization tool. Prior to version 5.12, the verification of the second factor was not subject to rate limiting. The absence of rate limiting on the second factor endpoint allows an attacker with valid credentials to automate OTP guessing. This issue has been patched in version 5.12.Show less
-
-
Jun 17, 2026
Jun 13, 2025
9.4 CRITICAL· v4
N/A· v3
N/A· v2
Use of fixed learning codes, one code to lock the car and the other code to unlock it, in the Key Fob Transmitter in Cyclone Matrix TRF Smart Keyless Entry System, which allows a replay attack. Research was completed o...Show more
Use of fixed learning codes, one code to lock the car and the other code to unlock it, in the Key Fob Transmitter in Cyclone Matrix TRF Smart Keyless Entry System, which allows a replay attack. Research was completed on the 2024 KIA Soluto.  Attack confirmed on other KIA Models in Ecuador.Show less
-
-
Jun 17, 2026
Jun 13, 2025
9.4 CRITICAL· v4
N/A· v3
N/A· v2
Use of fixed learning codes, one code to lock the car and the other code to unlock it, the Key Fob Transmitter in KIA-branded Aftermarket Generic Smart Keyless Entry System, primarily distributed in Ecuador, which allow...Show more
Use of fixed learning codes, one code to lock the car and the other code to unlock it, the Key Fob Transmitter in KIA-branded Aftermarket Generic Smart Keyless Entry System, primarily distributed in Ecuador, which allows a replay attack. Manufacture is unknown at the time of release.  CVE Record will be updated once this is clarified.Show less
1Vantage6
1Vantage6
Jun 17, 2026
Jun 12, 2025
1.7 LOW· v4
9.8 CRITICAL· v3
N/A· v2
vantage6 is an open source framework built to enable, manage and deploy privacy enhancing technologies like Federated Learning and Multi-Party Computation. If attacker gets access to an authenticated session, they can tr...Show more
vantage6 is an open source framework built to enable, manage and deploy privacy enhancing technologies like Federated Learning and Multi-Party Computation. If attacker gets access to an authenticated session, they can try to brute-force the user password by using the change password functionality: they can call that route infinitely which will return the message that password is wrong until it is correct. This vulnerability is fixed in 4.11.Show less
1Sick
1Media Server
Jun 17, 2026
Jun 12, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The FTP server’s login mechanism does not restrict authentication attempts, allowing an attacker to brute-force user passwords and potentially compromising the FTP server.
2Avaya
Sick
6Baggage Analytics
Field AnalyticsLogistic Diagnostic Analytics+3 more
Jun 17, 2026
Jun 12, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it susceptible to brute-force attacks.
-
-
Jun 17, 2026
Jun 9, 2025
2.9 LOW· v4
3.7 LOW· v3
2.6 LOW· v2
A vulnerability was found in Tenda TDSEE App up to 1.7.12. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /app/ConfirmSmsCode of the component Password Reset C...Show more
A vulnerability was found in Tenda TDSEE App up to 1.7.12. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /app/ConfirmSmsCode of the component Password Reset Confirmation Code Handler. The manipulation leads to improper restriction of excessive authentication attempts. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 1.7.15 is able to address this issue. It is recommended to upgrade the affected component.Show less
-
-
Jun 17, 2026
May 20, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
Password guessing limits could be bypassed when using LDAP authentication.
1Infiniflow
1Ragflow
Jun 17, 2026
May 17, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
RAGFlow through 0.18.1 allows account takeover because it is possible to conduct successful brute-force attacks against email verification codes to perform arbitrary account registration, login, and password reset. Codes...Show more
RAGFlow through 0.18.1 allows account takeover because it is possible to conduct successful brute-force attacks against email verification codes to perform arbitrary account registration, login, and password reset. Codes are six digits and there is no rate limiting.Show less
1Flytxt
1Neon Dx
Jun 17, 2026
May 12, 2025
N/A· v4
5.4 MEDIUM· v3
N/A· v2
An issue in the userId parameter in the change password function of Flytxt NEON-dX v0.0.1-SNAPSHOT-6.9-qa-2-9-g5502a0c allows attackers to execute brute force attacks to discover user passwords.
-
-
Jun 17, 2026
May 12, 2025
N/A· v4
8.1 HIGH· v3
N/A· v2
An unauthenticated user could discover account credentials via a brute-force attack without rate limiting
1Cisco
7807 Industrial Integrated Services Router Firmware
809 Industrial Integrated Services Router Firmware829 Industrial Integrated Services Router Firmware+4 more
Jun 17, 2026
May 7, 2025
N/A· v4
5.3 MEDIUM· v3
N/A· v2
A vulnerability in the Cisco IOx application hosting environment of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the Cisco IOx application hosting environment to s...Show more
A vulnerability in the Cisco IOx application hosting environment of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the Cisco IOx application hosting environment to stop responding, resulting in a denial of service (DoS) condition. This vulnerability is due to the improper handling of HTTP requests. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to cause the Cisco IOx application hosting environment to stop responding. The IOx process will need to be manually restarted to recover services.Show less
1Flowring
1Agentflow
Jun 17, 2026
May 2, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Agentflow from Flowring Technology has an Account Lockout Bypass vulnerability, allowing unauthenticated remote attackers to exploit this vulnerability to perform password brute force attack.
-
-
Jun 17, 2026
Apr 23, 2025
8.2 HIGH· v4
N/A· v3
N/A· v2
This vulnerability exists in Meon KYC solutions due to missing restrictions on the number of incorrect One-Time Password (OTP) attempts through certain API endpoints of login process. A remote attacker could exploit this...Show more
This vulnerability exists in Meon KYC solutions due to missing restrictions on the number of incorrect One-Time Password (OTP) attempts through certain API endpoints of login process. A remote attacker could exploit this vulnerability by performing a brute force attack on OTP, which could lead to gain unauthorized access to other user accounts.Show less
1Scriptandtools
1Ecommerce Website In Php
Jun 17, 2026
Apr 14, 2025
6.3 MEDIUM· v4
8.1 HIGH· v3
2.6 LOW· v2
A vulnerability classified as problematic was found in ScriptAndTools eCommerce-website-in-PHP 3.0. Affected by this vulnerability is an unknown functionality of the file /admin/login.php. The manipulation leads to impro...Show more
A vulnerability classified as problematic was found in ScriptAndTools eCommerce-website-in-PHP 3.0. Affected by this vulnerability is an unknown functionality of the file /admin/login.php. The manipulation leads to improper restriction of excessive authentication attempts. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.Show less
1Scriptandtools
1Ecommerce Website In Php
Jun 17, 2026
Apr 14, 2025
6.3 MEDIUM· v4
8.1 HIGH· v3
2.6 LOW· v2
A vulnerability classified as problematic has been found in ScriptAndTools eCommerce-website-in-PHP 3.0. Affected is an unknown function of the file /login.php. The manipulation leads to improper restriction of excessive...Show more
A vulnerability classified as problematic has been found in ScriptAndTools eCommerce-website-in-PHP 3.0. Affected is an unknown function of the file /login.php. The manipulation leads to improper restriction of excessive authentication attempts. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.Show less
1Access Code Project
1Access Code
Jun 17, 2026
Apr 2, 2025
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Access code allows Brute Force.This issue affects Access code: from 0.0.0 before 2.0.4.
-
-
Jun 17, 2026
Apr 1, 2025
7.0 HIGH· v4
N/A· v3
N/A· v2
Lack of protection against brute force attacks in Valmet DNA visualization in DNA Operate. The possibility to make an arbitrary number of login attempts without any rate limit gives an attacker an increased chance of gue...Show more
Lack of protection against brute force attacks in Valmet DNA visualization in DNA Operate. The possibility to make an arbitrary number of login attempts without any rate limit gives an attacker an increased chance of guessing passwords and then performing switching operations.Show less
1Email Tfa Project
1Email Tfa
Jun 17, 2026
Mar 31, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
Weak Authentication vulnerability in Drupal Email TFA allows Brute Force.This issue affects Email TFA: from 0.0.0 before 2.0.3.