Skip to main content

CWE archive

CWE-307 CVEs

Programmatic archive

602 CVEs tagged with CWE-307155 Critical, 197 High, 209 Medium, 40 Low, 1 Unrated.

CVE-2024-24721

Published Feb 27, 2024

An issue was discovered on Innovaphone PBX before 14r1 devices. The password form, used to authenticate, allows a Brute Force Attack through which an attacker may be able to acces…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-1104

Published Feb 22, 2024

An unauthenticated remote attacker can bypass the brute force prevention mechanism and disturb the webservice for all users.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-1345

Published Feb 19, 2024

Weak MySQL database root password in LaborOfficeFree affects version 19.10. This vulnerability allows an attacker to perform a brute force attack and easily discover the root pass…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-21500

Published Feb 17, 2024

All versions of the package github.com/greenpau/caddy-security are vulnerable to Improper Restriction of Excessive Authentication Attempts via the two-factor authentication (2FA).…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-22425

Published Feb 16, 2024

Dell RecoverPoint for Virtual Machines 5.3.x, 6.0.SP1 contains a brute force/dictionary attack vulnerability. An unauthenticated remote attacker could potentially exploit this vul…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-45191

Published Feb 9, 2024

IBM Engineering Lifecycle Optimization 7.0.2 and 7.0.3 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-For…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-38273

Published Feb 2, 2024

IBM Cloud Pak System 2.3.1.1, 2.3.2.0, and 2.3.3.7 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force I…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-50326

Published Feb 2, 2024

IBM PowerSC 1.3, 2.0, and 2.1 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 275107.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-33759

Published Jan 25, 2024

SpliceCom Maximiser Soft PBX v1.5 and before does not restrict excessive authentication attempts, allowing attackers to bypass authentication via a brute force attack.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-22317

Published Jan 18, 2024

IBM App Connect Enterprise 11.0.0.1 through 11.0.0.24 and 12.0.1.0 through 12.0.11.0 could allow a remote attacker to obtain sensitive information or cause a denial of service due…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-50123

Published Jan 11, 2024

The number of attempts to bring the Hozard Alarm system (alarmsystemen) v1.0 to a disarmed state is not limited. This could allow an attacker to perform a brute force on the SMS a…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2023-49810

Published Jan 10, 2024

A login attempt restriction bypass vulnerability exists in the checkLoginAttempts functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can l…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2023-49792

Published Dec 22, 2023

Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. In Nextcloud Server prior to versions 26.0.9 and 27.1.4; as well as Nextcloud Enterprise Serve…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-6912

Published Dec 20, 2023

Lack of protection against brute force attacks in M-Files Server before 23.12.13205.0 allows an attacker unlimited authentication attempts, potentially compromising targeted M-Fil…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-27172

Published Dec 20, 2023

Xpand IT Write-back Manager v2.3.1 uses weak secret keys to sign JWT tokens. This allows attackers to easily obtain the secret key used to sign JWT tokens via a bruteforce attack.

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-6928

Published Dec 19, 2023

EuroTel ETL3100 versions v01c01 and v01x37 does not limit the number of attempts to guess administrative credentials in remote password attacks to gain full control of the system.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-6272

Published Dec 18, 2023

The Theme My Login 2FA WordPress plugin before 1.2 does not rate limit 2FA validation attempts, which may allow an attacker to brute-force all possibilities, which shouldn't be to…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-6756

Published Dec 13, 2023

A vulnerability was found in Thecosy IceCMS 2.0.1. It has been classified as problematic. Affected is an unknown function of the file /login of the component Captcha Handler. The…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-49278

Published Dec 12, 2023

Umbraco is an ASP.NET content management system (CMS). Starting in version 8.0.0 and prior to versions 8.18.10, 10.8.1, and 12.3.4, a brute force exploit can be used to collect va…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-49443

Published Dec 8, 2023

DoraCMS v2.1.8 was discovered to re-use the same code for verification of valid usernames and passwords. This vulnerability allows attackers to gain access to the application via…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 276-300 of 602 CVEsPage 12 of 25