Skip to main content

CWE archive

CWE-307 CVEs

Programmatic archive

606 CVEs tagged with CWE-307155 Critical, 200 High, 209 Medium, 41 Low, 1 Unrated.

CVE-2026-15144

Published Jul 29, 2026

@fastify/rate-limit before 11.2.0 keys rate-limit buckets by the verbatim client IP string returned from request.ip. Because a single IPv6 client can control a large address range…

CVSS 7.3 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-16347

Published Jul 28, 2026

MikroTik RouterOS contains a weakness in its API authentication handling that lacks effective safeguards against excessive login attempts. The system does not enforce meaningful r…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-55977

Published Jul 28, 2026

Successful exploitation of this vulnerability could allow an attacker with local network access to bypass the application's rate-limiting mechanism, enabling brute-forcing of the…

CVSS 3.3 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-65894

Published Jul 27, 2026

This vulnerability exists in CP PLUS EZ-P21 IP Camera due to improper authentication of HTTP endpoints. A remote attacker could exploit this vulnerability by conducting brute-forc…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-8285

Published Jul 21, 2026

Improper restriction of excessive authentication attempts vulnerability in Universal Software Inc. FlexCity allows Excessive Allocation. This issue affects FlexCity: from 5.536.0…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-32825

Published Jul 20, 2026

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framew…

CVSS 7.3 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-62220

Published Jul 17, 2026

OpenClaw 2026.2.25 before 2026.5.26 allow a lower-trust caller or configured input path to bypass non-browser rate limits on WebSocket authentication attempts. When the affected f…

CVSS 6.3 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-44596

Published Jul 16, 2026

Yamcs is a mission control framework. Prior to 5.12.7, the authentication endpoint POST /auth/token in yamcs-core, handled by yamcs-core/src/main/java/org/yamcs/http/auth/AuthHand…

CVSS 6.5 · Medium
evidence mentions
5
Buzz score
22.9
Vendor/product tagsBeta · best-effort

CVE-2026-14254

Published Jul 16, 2026

A race condition in the account lockout mechanism in Delphix Continous Data allowed the lockout threshold to be bypassed through concurrent authentication requests. Parallel login…

CVSS 8.3 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-61458

Published Jul 13, 2026

PasswordPusher before 2.9.2 contains a brute-force vulnerability in the POST /p/:token/access endpoint that lacks route-specific rate limiting and per-push lockout mechanisms. Att…

CVSS 8.7 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-42952

Published Jul 10, 2026

Previously, there was no throttling on repeated authentication attempts to the charging station backend, which could allow an attacker to execute a denial-of-service attack.

CVSS 8.7 · High
evidence mentions
3
Buzz score
28.9

CVE-2026-11915

Published Jul 10, 2026

vulnerability in Drupal Brute force attack protection allows . This issue affects Brute force attack protection versions: *.*.

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-15079

Published Jul 10, 2026

Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Login Disable allows Brute Force. This issue affects Login Disable versions: from 0.0.0 to 2.1.4.

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-55501

Published Jul 10, 2026

9Router is an AI router & token saver. Prior to 0.4.80, the dashboard login rate limiter in src/lib/auth/loginLimiter.js derives the client identity from the attacker-controlled X…

CVSS 7.3 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-53904

Published Jul 1, 2026

MCO is vulnerable to Account Denial of Service due to improper implementation of password reset functionality. Each password reset request invalidates previously set password as w…

CVSS 6.3 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-35098

Published Jun 30, 2026

KTM System e-BOK does not implement any limit or timeout on consecutive login attempts, allowing an attacker to perform unlimited authentication requests. This lack of rate‑limiti…

CVSS 6.9 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-11779

Published Jun 26, 2026

An Improper Authorization vulnerability exists in PayloadCMS version 3.84.1 due to insufficient access control on the account unlock operation.

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2026-50176

Published Jun 25, 2026

The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-…

CVSS 8.7 · High
evidence mentions
3
Buzz score
28.9

CVE-2026-47380

Published Jun 23, 2026

NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, sign-in response timing differed between known and unknown email addresses because the unknown-user…

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-56234

Published Jun 23, 2026

Capgo before 12.128.2 contains a credential validation vulnerability in the POST /functions/v1/private/validate_password_compliance endpoint that is callable using only the public…

CVSS 6.9 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2026-56450

Published Jun 22, 2026

AIL did not restrict repeated failed attempts to verify a two-factor authentication (OTP) code. An attacker who had reached the 2FA verification step, such as after successfully c…

CVSS 5.1 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-47203

Published Jun 19, 2026

Authelia is an open-source authentication and authorization server providing two-factor authentication and single sign-on (SSO) for applications via a web portal. In versions 4.38…

CVSS 2.9 · Low
evidence mentions
2
Buzz score
16.0

CVE-2026-6853

Published Jun 12, 2026

Improper restriction of excessive authentication attempts vulnerability in Başbelen Group Food Cafe Businesses Industry and Trade Ltd. Co. Pause+ Mobile App allows Authentication…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-3329

Published Jun 11, 2026

A remote unauthenticated attacker may be able to conduct credential-guessing attacks against user accounts in Sonatype Nexus Repository via authentication endpoints.

CVSS 8.7 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-43926

Published Jun 4, 2026

FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, the password reset confirmation endpoint `/client/reset-password-confirm/:hash` is…

CVSS 6.3 · Medium
evidence mentions
2
Buzz score
16.0
Showing 1-25 of 606 CVEsPage 1 of 25