Skip to main content

CWE archive

CWE-307 CVEs

Programmatic archive

603 CVEs tagged with CWE-307155 Critical, 198 High, 209 Medium, 40 Low, 1 Unrated.

CVE-2023-40834

Published Sep 12, 2023

OpenCart CMS v4.0.2.2 was discovered to lack a protective mechanism on its login page against excessive login attempts, allowing unauthenticated attackers to gain access to the ap…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-26271

Published Aug 28, 2023

IBM Security Guardium Data Encryption (IBM Guardium Cloud Key Manager (GCKM) 1.10.3)) uses an inadequate account lockout setting that could allow a remote attacker to brute force…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-43904

Published Aug 28, 2023

IBM Security Guardium 11.3 and 11.4 could disclose sensitive information to an attacker due to improper restriction of excessive authentication attempts. IBM X-Force ID: 240895.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-39958

Published Aug 10, 2023

Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 22.0.0 and prior to versions 22.2.10.13, 23.0.12.8, 24.0.12.5, 25.0.9, 26.…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-3669

Published Aug 3, 2023

A missing Brute-Force protection in CODESYS Development System prior to 3.5.19.20 allows a local attacker to have unlimited attempts of guessing the password within an import dial…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-32657

Published Jul 19, 2023

Weintek Weincloud v0.13.6 could allow an attacker to efficiently develop a brute force attack on credentials with authentication hints from error message responses.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-29301

Published Jul 12, 2023

Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0.0.330468 (and earlier) are affected by an Improper Restriction of Excessive Authentication Attempt…

CVSS 7.5 · High
evidence mentions
3
Buzz score
21.9
Vendor/product tagsBeta · best-effort

CVE-2023-36917

Published Jul 11, 2023

SAP BusinessObjects Business Intelligence Platform - version 420, 430, allows an unauthorized attacker who had hijacked a user session, to be able to bypass the victim’s old passw…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-3605

Published Jul 10, 2023

A vulnerability was found in PHPGurukul Online Shopping Portal 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component R…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-35172

Published Jun 23, 2023

NextCloud Server and NextCloud Enterprise Server provide file storage for Nextcloud, a self-hosted productivity platform. In NextCloud Server versions 25.0.0 until 25.0.7 and 26.0…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2023-32320

Published Jun 22, 2023

Nextcloud Server is a data storage system for Nextcloud, a self-hosted productivity platform. When multiple requests are sent in parallel, all of them were executed even if the am…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2022-32757

Published Jun 15, 2023

IBM Security Directory Suite VA 8.0.1 through 8.0.1.19 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-For…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-42478

Published Jun 13, 2023

An Improper Restriction of Excessive Authentication Attempts [CWE-307] in FortiSIEM below 7.0.0 may allow a non-privileged user with access to several endpoints to brute force att…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2023-3173

Published Jun 9, 2023

Improper Restriction of Excessive Authentication Attempts in GitHub repository froxlor/froxlor prior to 2.0.20.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-34243

Published Jun 8, 2023

TGstation is a toolset to manage production BYOND servers. In affected versions if a Windows user was registered in tgstation-server (TGS), an attacker could discover their userna…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-33754

Published Jun 1, 2023

The captive portal in Inpiazza Cloud WiFi versions prior to v4.2.17 does not enforce limits on the number of attempts for password recovery, allowing attackers to brute force vali…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-23755

Published May 30, 2023

An issue was discovered in Joomla! 4.2.0 through 4.3.1. The lack of rate limiting allowed brute force attacks against MFA methods.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-32319

Published May 26, 2023

Nextcloud server is an open source personal cloud implementation. Missing brute-force protection on the WebDAV endpoints via the basic auth header allowed to brute-force user cred…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2023-32074

Published May 25, 2023

user_oidc app is an OpenID Connect user backend for Nextcloud. Authentication can be broken/bypassed in user_oidc app. It is recommended that the Nextcloud user_oidc app is upgrad…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort
Showing 326-350 of 603 CVEsPage 14 of 25