Skip to main content

CWE archive

CWE-307 CVEs

Programmatic archive

602 CVEs tagged with CWE-307155 Critical, 197 High, 209 Medium, 40 Low, 1 Unrated.

CVE-2021-27782

Published Jan 20, 2023

HCL BigFix Mobile / Modern Client Management Admin and Config UI passwords can be brute-forced. User should be locked out for multiple invalid attempts.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-38491

Published Jan 10, 2023

An issue was discovered in EasyVista 2020.2.125.3 and 2022.1.109.0.03. Part of the application does not implement protection against brute-force attacks. Version 2022.1.133.0 corr…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2022-4797

Published Dec 28, 2022

Improper Restriction of Excessive Authentication Attempts in GitHub repository usememos/memos prior to 0.9.1.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-26964

Published Dec 26, 2022

Weak password derivation for export in Devolutions Remote Desktop Manager before 2022.1 allows information disclosure via a password brute-force attack. An error caused base64 to…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2022-45893

Published Dec 25, 2022

Planet eStream before 6.72.10.07 allows a low-privileged user to gain access to administrative and high-privileged user accounts by changing the value of the ON cookie. A brute-fo…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-23746

Published Nov 30, 2022

The IPsec VPN blade has a dedicated portal for downloading and connecting through SSL Network Extender (SNX). If the portal is configured for username/password authentication, it…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-2650

Published Nov 24, 2022

Improper Restriction of Excessive Authentication Attempts in GitHub repository wger-project/wger prior to 2.2.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-37772

Published Nov 23, 2022

Maarch RM 2.8.3 solution contains an improper restriction of excessive authentication attempts due to excessive verbose responses from the application. An unauthenticated remote a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-2166

Published Nov 16, 2022

Improper Restriction of Excessive Authentication Attempts in GitHub repository mastodon/mastodon prior to 4.0.0.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-4006

Published Nov 15, 2022

A vulnerability, which was classified as problematic, has been found in WBCE CMS. Affected by this issue is the function increase_attempts of the file wbce/framework/class.login.p…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-3993

Published Nov 14, 2022

Improper Restriction of Excessive Authentication Attempts in GitHub repository kareadita/kavita prior to 0.6.0.3.

CVSS 9.4 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-3945

Published Nov 11, 2022

Improper Restriction of Excessive Authentication Attempts in GitHub repository kareadita/kavita prior to 0.6.0.3.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-44023

Published Oct 30, 2022

PwnDoc through 0.5.3 might allow remote attackers to identify disabled user account names by leveraging response messages for authentication attempts.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-44022

Published Oct 30, 2022

PwnDoc through 0.5.3 might allow remote attackers to identify valid user account names by leveraging response timings for authentication attempts.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-3741

Published Oct 28, 2022

Impact varies for each individual vulnerability in the application. For generation of accounts, it may be possible, depending on the amount of system resources available, to creat…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-39314

Published Oct 24, 2022

Kirby is a flat-file CMS. In versions prior to 3.5.8.2, 3.6.6.2, 3.7.5.1, and 3.8.1, Kirby is subject to user enumeration due to Improper Restriction of Excessive Authentication A…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-35846

Published Oct 18, 2022

An improper restriction of excessive authentication attempts vulnerability [CWE-307] in FortiTester Telnet port 2.3.0 through 3.9.1, 4.0.0 through 4.2.0, 7.0.0 through 7.1.0 may a…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2022-3031

Published Oct 17, 2022

An issue has been discovered in GitLab CE/EE affecting all versions before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. It…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort
Showing 376-400 of 602 CVEsPage 16 of 25