CWE-307
607 CVEs • Abstraction: Base
Improper Restriction of Excessive Authentication Attempts
The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it more susceptible to brute force attacks.
CVEs (607)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Improper Authentication in Lin-CMS-Flask v0.1.1 allows remote attackers to launch brute force login attempts without restriction via the 'login' function in the component 'app/api/cms/user.py'. |
IBM Security Guardium 11.2 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 196314. |
OpenStack Keystone 10.x through 16.x before 16.0.2, 17.x before 17.0.1, 18.x before 18.0.1, and 19.x before 19.0.1 allows information disclosure during account locking (related to PCI DSS features). By guessing the name...Show more |
1Vizio 2E50x E1 Firmware P65 F1 FirmwareJun 17, 2026 Aug 2, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The pairing procedure used by the Vizio P65-F1 6.0.31.4-2 and E50x-E1 10.0.31.4-2 Smart TVs and mobile application is vulnerable to a brute-force attack (against only 10000 possibilities), allowing a threat actor to forc...Show more |
2Debian Lemonldap Ng2Debian Linux Lemonldap\Jun 17, 2026 Jul 30, 2021 N/A· v4 8.8 HIGH· v3 6.0 MEDIUM· v2 An issue was discovered in LemonLDAP::NG before 2.0.12. Session cache corruption can lead to authorization bypass or spoofing. By running a loop that makes many authentication attempts, an attacker might alternately be a...Show more |
firefly-iii is vulnerable to Improper Restriction of Excessive Authentication Attempts |
Information disclosure in Logon Page in MV's mConnect application v02.001.00 allows an attacker to know valid users from the application's database via brute force. |
2Fedoraproject Nextcloud2Fedora Nextcloud ServerJun 17, 2026 Jul 12, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, there was a lack of ratelimiting on the public DAV endpoint. This may have allowed an attacker to enume...Show more |
2Fedoraproject Nextcloud2Fedora Nextcloud ServerJun 17, 2026 Jul 12, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, there was a lack of ratelimiting on the shareinfo endpoint. This may have allowed an attacker to enumer...Show more |
2Fedoraproject Nextcloud2Fedora Nextcloud ServerJun 17, 2026 Jul 12, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.0.11, and 21.0.3, ratelimits are not applied to OCS API responses. This affects any OCS API controller (`OCSController`)...Show more |
IBM Guardium Data Encryption (GDE) 4.0.0.4 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 196217. |
1Qsan 3Sanos Storage ManagerXevoJun 17, 2026 Jul 7, 2021 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 Improper restriction of excessive authentication attempts vulnerability in QSAN Storage Manager, XEVO, SANOS allows remote attackers to discover users’ credentials and obtain access via a brute force attack. Suggest cont...Show more |
1Stormshield 1Stormshield Network Security Jun 17, 2026 Jul 1, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Stormshield SNS through 4.2.1. A brute-force attack can occur. |
2Fedoraproject Nextcloud2Fedora Nextcloud ServerJun 17, 2026 Jun 11, 2021 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 Nextcloud server before 19.0.11, 20.0.10, 21.0.2 is vulnerable to brute force attacks due to lack of inclusion of IPv6 subnets in rate-limiting considerations. This could potentially result in an attacker bypassing rate-...Show more |
In Apache APISIX Dashboard version 2.6, we changed the default value of listen host to 0.0.0.0 in order to facilitate users to configure external network access. In the IP allowed list restriction, a risky function was u...Show more |
1Redhat 23scale 3scale Api ManagementJun 17, 2026 Jun 1, 2021 N/A· v4 7.3 HIGH· v3 5.0 MEDIUM· v2 It was found that all versions of 3Scale developer portal lacked brute force protections. An attacker could use this gap to bypass login controls, and access privileged information, or possibly conduct further attacks. |
1Schneider Electric 2Homelynk Firmware Spacelynk FirmwareJun 17, 2026 May 26, 2021 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 Insufficiently Protected Credentials vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior that could cause unauthorized access of when credentials are discovered after a brute force attack. |
1Bluetooth 2Bluetooth Core Specification Mesh ProfileJun 17, 2026 May 24, 2021 N/A· v4 7.5 HIGH· v3 2.9 LOW· v2 Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device, able to conduct a successful brute-force attack on an insufficiently random AuthValue before the provisioning procedure times out,...Show more |
InvoicePlane 1.5.11 doesn't have any rate-limiting for password reset and the reset token is generated using a weak mechanism that is predictable. |
Gestsup before 3.2.10 allows account takeover through the password recovery functionality (remote). The affected component is the file forgot_pwd.php - it uses a weak algorithm for the generation of password recovery tok...Show more |