The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.
Volume of CVEs assigned to CWE-307 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
603 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-17240CRITICAL bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many different forged X-Forwarded-For or Client-IP HTTP headers. | Oct 6, 2019 | 9.8 | 63 | NO | YES |
CVE-2020-15906CRITICAL tiki-login.php in Tiki before 21.2 sets the admin password to a blank value after 50 invalid login attempts. | Oct 22, 2020 | 9.8 | 57 | NO | YES |
CVE-2026-44596CRITICAL Yamcs is a mission control framework. Prior to 5.12.7, the authentication endpoint POST /auth/token in yamcs-core, handled by yamcs-core/src/main/java/org/yamcs/http/auth/AuthHandl | Jul 16, 2026 | 9.8 | 50 | NO | YES |
CVE-2016-9361CRITICAL An issue was discovered in Moxa NPort 5110 versions prior to 2.6, NPort 5130/5150 Series versions prior to 3.6, NPort 5200 Series versions prior to 2.8, NPort 5400 Series versions | Feb 13, 2017 | 9.8 | 47 | NO | YES |
CVE-2023-27100CRITICAL Improper restriction of excessive authentication attempts in the SSHGuard component of Netgate pfSense Plus software v22.05.1 and pfSense CE software v2.6.0 allows attackers to byp | Mar 22, 2023 | 9.8 | 45 | NO | YES |
CVE-2001-1291CRITICAL The telnet server for 3Com hardware such as PS40 SuperStack II does not delay or disconnect remote attackers who provide an incorrect username or password, which makes it easier to | Jul 12, 2001 | 9.8 | 45 | NO | YES |
CVE-2023-29301HIGH Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0.0.330468 (and earlier) are affected by an Improper Restriction of Excessive Authentication Attempts | Jul 12, 2023 | 7.5 | 41 | NO | NO |
CVE-2023-22960HIGH Lexmark products through 2023-01-10 have Improper Control of Interaction Frequency. | Jan 23, 2023 | 7.5 | 38 | NO | NO |
CVE-2019-17525HIGH The login page on D-Link DIR-615 T1 20.10 devices allows remote attackers to bypass the CAPTCHA protection mechanism and conduct brute-force attacks. | Apr 21, 2020 | 8.8 | 38 | NO | YES |
CVE-2026-6853CRITICAL Improper restriction of excessive authentication attempts vulnerability in Başbelen Group Food Cafe Businesses Industry and Trade Ltd. Co. Pause+ Mobile App allows Authentication B | Jun 12, 2026 | 9.8 | 37 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.