Skip to main content

CWE archive

CWE-307 CVEs

Programmatic archive

602 CVEs tagged with CWE-307155 Critical, 197 High, 209 Medium, 40 Low, 1 Unrated.

CVE-2024-5862

Published Jun 24, 2024

Improper Restriction of Excessive Authentication Attempts vulnerability in Mia Technology Inc. Mia-Med Health Aplication allows Interface Manipulation. This issue affects Mia-Med…

CVSS 7.5 · High

CVE-2024-28833

Published Jun 10, 2024

Improper restriction of excessive authentication attempts with two factor authentication methods in Checkmk 2.3 before 2.3.0p6 facilitates brute-forcing of second factor mechanism…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-3102

Published Jun 6, 2024

A JSON Injection vulnerability exists in the `mintplex-labs/anything-llm` application, specifically within the username parameter during the login process at the `/api/request-tok…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-48745

Published Jun 4, 2024

Improper Restriction of Excessive Authentication Attempts vulnerability in WebFactory Ltd Captcha Code allows Functionality Bypass.This issue affects Captcha Code: from n/a throug…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2023-48318

Published Jun 4, 2024

Improper Restriction of Excessive Authentication Attempts vulnerability in CodePeople Contact Form Email allows Functionality Bypass.This issue affects Contact Form Email: from n/…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-48290

Published Jun 4, 2024

Improper Restriction of Excessive Authentication Attempts vulnerability in 10Web Form Builder Team Form Maker by 10Web allows Functionality Bypass.This issue affects Form Maker by…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-48276

Published Jun 4, 2024

Improper Restriction of Excessive Authentication Attempts vulnerability in Nitin Rathod WP Forms Puzzle Captcha allows Functionality Bypass.This issue affects WP Forms Puzzle Capt…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2023-45009

Published Jun 4, 2024

Improper Restriction of Excessive Authentication Attempts vulnerability in Forge12 Interactive GmbH Captcha/Honeypot for Contact Form 7 allows Functionality Bypass.This issue affe…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2023-44235

Published Jun 4, 2024

Improper Restriction of Excessive Authentication Attempts vulnerability in Devnath verma WP Captcha allows Functionality Bypass.This issue affects WP Captcha: from n/a through 2.0…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2023-34001

Published Jun 4, 2024

Improper Restriction of Excessive Authentication Attempts vulnerability in WPPlugins – WordPress Security Plugins Hide My WP Ghost allows Functionality Bypass.This issue affects H…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-23730

Published Jun 3, 2024

Improper Restriction of Excessive Authentication Attempts vulnerability in Brainstorm Force Spectra allows Functionality Bypass.This issue affects Spectra: from n/a through 2.3.0.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-32774

Published May 17, 2024

Improper Restriction of Excessive Authentication Attempts vulnerability in Metagauss ProfileGrid allows Removing Important Client Functionality.This issue affects ProfileGrid : fr…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-32720

Published May 17, 2024

Improper Restriction of Excessive Authentication Attempts vulnerability in CodePeople Appointment Hour Booking allows Removing Important Client Functionality.This issue affects Ap…

CVSS 5.3 · Medium

CVE-2024-3461

Published May 14, 2024

KioWare for Windows (versions all through 8.35) allows to brute force the PIN number, which protects the application from being closed, as there are no mechanisms preventing a use…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-32868

Published Apr 26, 2024

ZITADEL provides users the possibility to use Time-based One-Time-Password (TOTP) and One-Time-Password (OTP) through SMS and Email. While ZITADEL already gives administrators the…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-32676

Published Apr 25, 2024

Improper Restriction of Excessive Authentication Attempts vulnerability in LoginPress LoginPress Pro allows Removing Important Client Functionality.This issue affects LoginPress P…

CVSS 5.3 · Medium

CVE-2024-28825

Published Apr 24, 2024

Improper restriction of excessive authentication attempts on some authentication methods in Checkmk before 2.3.0b5 (beta), 2.2.0p26, 2.1.0p43, and in Checkmk 2.0.0 (EOL) facilitat…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-30390

Published Apr 12, 2024

An Improper Restriction of Excessive Authentication Attempts vulnerability in Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to cause a limite…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-3202

Published Apr 2, 2024

A vulnerability, which was classified as problematic, has been found in codelyfe Stupid Simple CMS 1.2.4. This issue affects some unknown processing of the component Login Page. T…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-21662

Published Mar 18, 2024

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior to versions 2.8.13, 2.9.9, and 2.10.4, an attacker can effectively bypass the rate limit and brute…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-21652

Published Mar 18, 2024

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior to versions 2.8.13, 2.9.9, and 2.10.4, an attacker can exploit a chain of vulnerabilities, includin…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-2051

Published Mar 18, 2024

CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could cause account takeover and unauthorized access to the system when an attacker co…

CVSS 9.8 · Critical

CVE-2024-24767

Published Mar 6, 2024

CasaOS-UserService provides user management functionalities to CasaOS. Starting in version 0.4.4.3 and prior to version 0.4.7, CasaOS doesn't defend against password brute force a…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort
Showing 251-275 of 602 CVEsPage 11 of 25