Skip to main content

CWE archive

CWE-307 CVEs

Programmatic archive

602 CVEs tagged with CWE-307155 Critical, 197 High, 209 Medium, 40 Low, 1 Unrated.

CVE-2023-48028

Published Nov 18, 2023

kodbox 1.46.01 has a security flaw that enables user enumeration. This problem is present on the login page, where an attacker can identify valid users based on varying response m…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-46745

Published Nov 17, 2023

LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring which includes support for a wide range of network hardware and operating systems. In affected versions the…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-45582

Published Nov 14, 2023

An improper restriction of excessive authentication attempts vulnerability [CWE-307] in FortiMail webmail version 7.2.0 through 7.2.4, 7.0.0 through 7.0.6 and before 6.4.8 may all…

CVSS 5.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-42480

Published Nov 14, 2023

The unauthenticated attacker in NetWeaver AS Java Logon application - version 7.50, can brute force the login functionality to identify the legitimate user ids. This will have an…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-2675

Published Nov 7, 2023

Improper Restriction of Excessive Authentication Attempts in GitHub repository linagora/twake prior to 2023.Q1.1223.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-41350

Published Nov 3, 2023

Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of insufficient measures to prevent multiple failed authentication attempts. An unauthenticated remote attacker can execute a c…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-20110

Published Oct 31, 2023

JHipster generator-jhipster before 2.23.0 allows a timing attack against validateToken due to a string comparison that stops at the first character that is different. Attackers ca…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-46123

Published Oct 25, 2023

jumpserver is an open source bastion machine, professional operation and maintenance security audit system that complies with 4A specifications. A flaw in the Core API allows atta…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-37635

Published Oct 23, 2023

UVDesk Community Skeleton v1.1.1 allows unauthenticated attackers to perform brute force attacks on the login page to gain access to the application.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-27152

Published Oct 23, 2023

DECISO OPNsense 23.1 does not impose rate limits for authentication, allowing attackers to perform a brute-force attack to bypass authentication.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-24402

Published Oct 19, 2023

The TETRA TEA1 keystream generator implements a key register initialization function that compresses the 80-bit key to only 32 bits for usage during the keystream generation phase…

CVSS 8.8 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2023-45149

Published Oct 16, 2023

Nextcloud talk is a chat module for the Nextcloud server platform. In affected versions brute force protection of public talk conversation passwords can be bypassed, as there was…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-45148

Published Oct 16, 2023

Nextcloud is an open source home cloud server. When Memcached is used as `memcache.distributed` the rate limiting in Nextcloud Server could be reset unexpectedly resetting the rat…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-39960

Published Oct 13, 2023

Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. In Nextcloud Server starting with 25.0.0 and prior to 25.09 and 26.04; as well as Nextcloud En…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-44111

Published Oct 11, 2023

Vulnerability of brute-force attacks on the device authentication module.Successful exploitation of this vulnerability may affect service confidentiality.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-43699

Published Oct 9, 2023

Improper Restriction of Excessive Authentication Attempts in RDT400 in SICK APU allows an unprivileged remote attacker to guess the password via trial-and-error as the login attem…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-42818

Published Sep 27, 2023

JumpServer is an open source bastion host. When users enable MFA and use a public key for authentication, the Koko SSH server does not verify the corresponding SSH private key. An…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-40834

Published Sep 12, 2023

OpenCart CMS v4.0.2.2 was discovered to lack a protective mechanism on its login page against excessive login attempts, allowing unauthenticated attackers to gain access to the ap…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 301-325 of 602 CVEsPage 13 of 25