CWE-307

Improper Restriction of Excessive Authentication Attempts

Parent: CWE-1390 - Weak Authentication

The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.

561 vulnerabilities with CWE-307
CVE-2024-39225 CRITICAL
Gl-inet Mt6000 Firmware - Brute Force
CVSS 9.8
CVE-2024-38888 MEDIUM
Horizoncloud Caterease < 24.0.1.2405 - Brute Force
CVSS 6.8
CVE-2024-38176 HIGH
GroupMe - Privilege Escalation
CVSS 8.1
CVE-2024-39917 HIGH
Neutrinolabs Xrdp < 0.10.0 - Brute Force
CVSS 7.2
CVE-2024-39874 HIGH
Siemens Sinema Remote Connect Server < 3.2 - Brute Force
CVSS 7.5
CVE-2024-39873 HIGH
Siemens Sinema Remote Connect Server < 3.2 - Brute Force
CVSS 7.5
CVE-2024-25031 MEDIUM
IBM Storage Defender - Resiliency Service <2.0.5 - Info Disclosure
CVSS 6.5
CVE-2024-5862 HIGH
Mia-Med Health Aplication <1.0.14 - Auth Bypass
CVSS 7.5
CVE-2024-28022 MEDIUM
Hitachienergy Foxman-un - Brute Force
CVSS 6.5
CVE-2024-35747 MEDIUM
Contact Form Builder < 2.1.7 - Brute Force
CVSS 5.3
CVE-2024-28833 MEDIUM
Checkmk - Brute Force
CVSS 5.9
CVE-2024-3102 MEDIUM
mintplex-labs/anything-llm - JSON Injection
CVSS 5.3
CVE-2024-32774 MEDIUM
Metagauss Profilegrid < 5.8.3 - Brute Force
CVSS 4.3
CVE-2024-32720 MEDIUM
CodePeople Appointment Hour Booking <1.4.56 - Auth Bypass
CVSS 5.3
CVE-2024-3461 MEDIUM
Kioware < 8.35 - Brute Force
CVSS 6.2
CVE-2024-32868 MEDIUM
ZITADEL - Info Disclosure
CVSS 6.5
CVE-2024-32676 MEDIUM
LoginPress Pro <3.0.0 - Auth Bypass
CVSS 5.3
CVE-2024-28825 MEDIUM
Checkmk < 2.0.0 - Brute Force
CVSS 5.9
CVE-2024-30390 MEDIUM
Juniper Junos OS Evolved < 21.4 - Brute Force
CVSS 5.3
CVE-2024-3202 LOW
Codelyfe Stupid Simple Cms < 1.2.4 - Brute Force
CVSS 3.7
CVE-2024-21662 HIGH
Argoproj Argo CD < 2.8.13 - Brute Force
CVSS 7.5
CVE-2024-21652 CRITICAL
Argoproj Argo CD < 2.8.13 - Brute Force
CVSS 9.8
CVE-2024-2051 CRITICAL
Login Form - Brute Force
CVSS 9.8
CVE-2024-24767 CRITICAL
CasaOS-UserService <0.4.7 - Privilege Escalation
CVSS 9.1
CVE-2024-24721 MEDIUM
Innovaphone PBX <14r1 - Auth Bypass
CVSS 6.5
Details
Vulnerabilities 561