Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CWE-307

Improper Restriction of Excessive Authentication Attempts

The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.

603
Assigned CVEs
69th
Commonality Rank
7.7
Avg CVSS
0.0%
In CISA KEV

Volume and Severity of Assigned CVEs Over Time

Volume of CVEs assigned to CWE-307 and their average CVSS base score over time.

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 3, 1998
28 years ago
Most Recent CVE
Jul 21, 2026
4 days ago

Top CVEs Assigned This CWE

Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.

603 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-17240CRITICAL
bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many different forged X-Forwarded-For or Client-IP HTTP headers.
Oct 6, 20199.863NOYES
CVE-2020-15906CRITICAL
tiki-login.php in Tiki before 21.2 sets the admin password to a blank value after 50 invalid login attempts.
Oct 22, 20209.857NOYES
CVE-2026-44596CRITICAL
Yamcs is a mission control framework. Prior to 5.12.7, the authentication endpoint POST /auth/token in yamcs-core, handled by yamcs-core/src/main/java/org/yamcs/http/auth/AuthHandl
Jul 16, 20269.850NOYES
CVE-2016-9361CRITICAL
An issue was discovered in Moxa NPort 5110 versions prior to 2.6, NPort 5130/5150 Series versions prior to 3.6, NPort 5200 Series versions prior to 2.8, NPort 5400 Series versions
Feb 13, 20179.847NOYES
CVE-2023-27100CRITICAL
Improper restriction of excessive authentication attempts in the SSHGuard component of Netgate pfSense Plus software v22.05.1 and pfSense CE software v2.6.0 allows attackers to byp
Mar 22, 20239.845NOYES
CVE-2001-1291CRITICAL
The telnet server for 3Com hardware such as PS40 SuperStack II does not delay or disconnect remote attackers who provide an incorrect username or password, which makes it easier to
Jul 12, 20019.845NOYES
CVE-2023-29301HIGH
Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0.0.330468 (and earlier) are affected by an Improper Restriction of Excessive Authentication Attempts
Jul 12, 20237.541NONO
CVE-2023-22960HIGH
Lexmark products through 2023-01-10 have Improper Control of Interaction Frequency.
Jan 23, 20237.538NONO
CVE-2019-17525HIGH
The login page on D-Link DIR-615 T1 20.10 devices allows remote attackers to bypass the CAPTCHA protection mechanism and conduct brute-force attacks.
Apr 21, 20208.838NOYES
CVE-2026-6853CRITICAL
Improper restriction of excessive authentication attempts vulnerability in Başbelen Group Food Cafe Businesses Industry and Trade Ltd. Co. Pause+ Mobile App allows Authentication B
Jun 12, 20269.837NONO
View all 603 CVEs →

CVE Severity & Scoring

This CWEGlobal (All CVEs)
0.0-0.9
1.0-1.9
2.0-2.9
3.0-3.9
10%
4.0-4.9
15%
19%
5.0-5.9
9%
16%
6.0-6.9
24%
26%
7.0-7.9
8%
11%
8.0-8.9
36%
14%
9.0-10.0
unknown
CVSS Score Range

Exploit Exposure

Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
0.2% of CVEs· 79th percentile
Nuclei
1 CVE
0.2% of CVEs· 78th percentile
ExploitDB
9 CVEs
1.5% of CVEs· 85th percentile

Social Chatter

Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.

Media Mentions

Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.

Top Affected Vendors

Top Affected Products