VulnSea

CWE-307

CVEs classified under CWE-307, newest first.

55 CVEsRSS

CVE-2026-46649Critical· 9.1
yesterday

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2, Joplin Server's GET /api/login_with_code/:id endpoint accepts a nine-digit SSO authentication code with a ten-minut…

Midnightlaurent22 · joplinvia NVD
CVE-2026-58271Medium· 6.8
yesterday

Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing

Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.4.0, `POST /api/app/sync/register` accepts credentials and a TOTP code to register a desktop sync client. On a failed TOT…

SunlitSync-in · servervia NVD
CVE-2026-77561Medium· 5.3
yesterday

Tinyauth is an authentication and authorization server

Tinyauth is an authentication and authorization server. Prior to 5.1.0, an unauthenticated remote attacker can send POST /api/user/login requests with 257 distinct nonexistent usernames to fill MaxLoginAttemptRecords and activate a globa…

Sunlittinyauthapp · tinyauthvia NVD
CVE-2026-93650Low· 3.7PoC
4d ago

A vulnerability was determined in Saleor up to 3.20.118/3.21.54/3.22.47/3.23.14

A vulnerability was determined in Saleor up to 3.20.118/3.21.54/3.22.47/3.23.14. This vulnerability affects the function get_client_ip of the file saleor/account/throttling.py. Executing a manipulation can lead to improper restriction of…

TwilightEPSS 0.55%via NVD
CVE-2026-56592Medium· 6.5
4d ago

HCL BigFix Service Management is affected by an Improper Authentication validation vulnerability related to inadequate account lockouts, which could allow an unauthenticated attacker to execute sustained brute-force attacks against the l…

HCL BigFix Service Management is affected by an Improper Authentication validation vulnerability related to inadequate account lockouts, which could allow an unauthenticated attacker to execute sustained brute-force attacks against the l…

SunlitHCL Software · HCL BigFix Service ManagementEPSS 0.25%via NVD
CVE-2026-40538Low· 3.7
4d ago

An improper restriction of excessive authentication attempts vulnerability in Auto block in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote attackers to read limited files via brute…

An improper restriction of excessive authentication attempts vulnerability in Auto block in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote attackers to read limited files via brute…

SunlitSynology · DiskStation Manager (DSM)EPSS 0.25%via NVD
CVE-2026-92583Medium· 6.5PoC
6d ago

AVideo through 29.0 contains a race condition in the enforceRateLimit() function that fails to atomically increment rate limit counters, allowing attackers to bypass all rate limits including login brute-force protection by issuing concu…

AVideo through 29.0 contains a race condition in the enforceRateLimit() function that fails to atomically increment rate limit counters, allowing attackers to bypass all rate limits including login brute-force protection by issuing concu…

TwilightWWBN · AVideoEPSS 0.24%via NVD
CVE-2026-91973High· 7.5PoC
1w ago

Vikunja before 2.6.0 contains an authentication bypass vulnerability in CalDAV BasicAuth endpoints that lack rate limiting protection

Vikunja before 2.6.0 contains an authentication bypass vulnerability in CalDAV BasicAuth endpoints that lack rate limiting protection. Remote unauthenticated attackers can issue unbounded credential-guessing requests against /dav, /.well…

Midnightgo-vikunja · vikunjaEPSS 0.61%via NVD
CVE-2026-91972High· 7.5PoC
1w ago

Vikunja versions before 2.6.0 fail to apply rate limiting to /api/v2 public authentication endpoints including login, register, password-reset, and OAuth token routes

Vikunja versions before 2.6.0 fail to apply rate limiting to /api/v2 public authentication endpoints including login, register, password-reset, and OAuth token routes. Remote unauthenticated attackers can perform unbounded credential gue…

Midnightgo-vikunja · vikunjaEPSS 0.50%via NVD
CVE-2026-92082Medium· 6.3
1w ago

By default, Payara Server does not limit the number of failed login attempts, which can leave it vulnerable to brute force login attacks

By default, Payara Server does not limit the number of failed login attempts, which can leave it vulnerable to brute force login attacks. To mitigate this, Payara Server includes built-in automatic attack protection. For configuration de…

SunlitPayara · org.glassfish.admingui.common.securityEPSS 0.19%via NVD
CVE-2026-55795Medium· 6.9
1w ago

Craft Commerce is an ecommerce platform for Craft CMS

Craft Commerce is an ecommerce platform for Craft CMS. From 4.0.0 until 4.11.2 and 5.6.5, CartController in src/controllers/CartController.php activates its RateLimiter only when the number POST or GET parameter is supplied. An unauthent…

Sunlitcraftcms · commerceEPSS 0.29%via NVD
CVE-2026-89174High· 7.5
1w ago

Smart Video Intercom System developed by Kingdom Communication Associated has a Missing Brute-force Protection vulnerability

Smart Video Intercom System developed by Kingdom Communication Associated has a Missing Brute-force Protection vulnerability. Unauthenticated remote attackers can gain access to valid accounts through a large number of login attempts.

TwilightKingdom Communication Associated · EH3040EPSS 0.38%via NVD
CVE-2026-88770Medium· 6.5
1w ago

A flaw was found in the Device Authorization Grant flow of Keycloak, an identity and access management solution

A flaw was found in the Device Authorization Grant flow of Keycloak, an identity and access management solution. The issue occurs because the token redemption process fails to check if a user account is currently locked due to brute-forc…

SunlitRed Hat · keycloak/rhbk-openshift-rhel9EPSS 0.21%via NVD
CVE-2026-78490High· 7.5
1w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Restriction of Excessive Authentication Attempts vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Restriction of Excessive Authentication Attempts vulnerability. An unauthenticated attacker with remote a…

Twilightdell · secure_connect_gatewayEPSS 0.29%via NVD
CVE-2026-86729High· 7.4
2w ago

WWBN AVideo through commit e01e41ecc (no patched version available) exposes get_api_preauthorize in plugin/API/API.php as a second, undocumented login path

WWBN AVideo through commit e01e41ecc (no patched version available) exposes get_api_preauthorize in plugin/API/API.php as a second, undocumented login path. Unlike get_api_signIn, which enforces a rate limit of 10 attempts per 5 minutes …

TwilightWWBN · AVideoEPSS 0.22%via NVD
CVE-2026-6223Critical· 9.4
2w ago

Improper restriction of excessive authentication attempts vulnerability in Bahçelievler Muncipality BiHayat App allows Authentication Bypass. This issue affects BiHayat App: from 2.1.7 through 07092026. NOTE: The vendor was contacted ea…

Improper restriction of excessive authentication attempts vulnerability in Bahçelievler Muncipality BiHayat App allows Authentication Bypass. This issue affects BiHayat App: from 2.1.7 through 07092026. NOTE: The vendor was contacted ea…

MidnightBahçelievler Muncipality · BiHayat AppEPSS 0.44%via NVD
CVE-2026-20514Medium· 4.4
2w ago

In Audio HAL, there is a possible information disclosure due to a missing permission check

In Audio HAL, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed fo…

SunlitEPSS 0.11%via NVD
CVE-2026-20512Medium· 6.7
2w ago

In Audio HAL, there is a possible escalation of privilege due to improper input validation

In Audio HAL, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed f…

SunlitMediaTek, Inc. · MediaTek chipsetEPSS 0.11%via NVD
CVE-2026-86186Medium· 6.5PoC
2w ago

AVideo API fails to enforce rate limits when clients send a bot User-Agent header, allowing attackers to bypass all eight protected operations including login brute-force protection

AVideo API fails to enforce rate limits when clients send a bot User-Agent header, allowing attackers to bypass all eight protected operations including login brute-force protection. Attackers can send requests with a bot User-Agent to d…

TwilightWWBN · AVideoEPSS 0.18%via NVD
CVE-2026-85237High· 8.1
2w ago

A vulnerability in MISP's email-based one-time password (OTP) authentication flow allowed an attacker to perform an unrestricted number of OTP verification attempts. The email_otp() endpoint did not apply brute-force protection when va…

A vulnerability in MISP's email-based one-time password (OTP) authentication flow allowed an attacker to perform an unrestricted number of OTP verification attempts. The email_otp() endpoint did not apply brute-force protection when va…

Twilightmisp-project · mispEPSS 0.27%via NVD
CVE-2026-82644High· 7.5
3w ago

WWBN AVideo (current e01e41ecc and earlier) contains a brute-force rate limiting bypass in enforceRateLimit(), which protects login.json.php and 13 other endpoints

WWBN AVideo (current e01e41ecc and earlier) contains a brute-force rate limiting bypass in enforceRateLimit(), which protects login.json.php and 13 other endpoints. The function stores its attempt counter via a cache layer (ObjectYPT::se…

TwilightEPSS 0.26%via NVD
CVE-2026-82643Medium· 6.5
3w ago

WWBN AVideo contains an unauthenticated credential submission vulnerability in plugin/Live/api/preauthorize.json.php that accepts credentials over GET without rate limiting

WWBN AVideo contains an unauthenticated credential submission vulnerability in plugin/Live/api/preauthorize.json.php that accepts credentials over GET without rate limiting. Attackers can submit correct credentials repeatedly to trigger …

SunlitEPSS 0.20%via NVD
CVE-2026-75575Medium· 5.3
4w ago

Rocket.Chat exposes the sendForgotPasswordEmail Meteor method without a DDP rate limit, so an unauthenticated caller may invoke it as often as it likes

Rocket.Chat exposes the sendForgotPasswordEmail Meteor method without a DDP rate limit, so an unauthenticated caller may invoke it as often as it likes. The method is reachable over DDP and over the HTTP route POST /api/v1/method.callAno…

SunlitRocketChat · Rocket.ChatEPSS 0.23%via NVD
CVE-2026-62862Critical· 9.1PoC
4w ago

Typebot is an open-source chatbot builder

Typebot is an open-source chatbot builder. In self-hosted versions up to and including 3.17.1, the default passwordless email magic-link authentication is vulnerable to login-code brute forcing that leads to account takeover. The email p…

AbyssalbaptisteArno · typebot.ioEPSS 0.51%via NVD
CVE-2026-69183High· 7.5
1mo ago

Monkeytype is a minimalistic and customizable typing test

Monkeytype is a minimalistic and customizable typing test. In 26.26.0 and earlier, the backend rate-limit key generator in backend/src/middlewares/rate-limit.ts uses client-controlled cf-connecting-ip and x-forwarded-for headers before t…

TwilightEPSS 0.33%via NVD
CVE-2026-73529Medium· 5.3
1mo ago

Plainpad through 1.1.1, fixed in commit d3823fc, contains a missing rate limiting vulnerability that allows unauthenticated attackers to send unbounded login requests to the POST /v1/sessions endpoint due to dead code in App\Http\Kernel.…

Plainpad through 1.1.1, fixed in commit d3823fc, contains a missing rate limiting vulnerability that allows unauthenticated attackers to send unbounded login requests to the POST /v1/sessions endpoint due to dead code in App\Http\Kernel.…

SunlitEPSS 0.30%via NVD
CVE-2026-73046Critical· 9.8
1mo ago

SiYuan before v3.7.4 improperly restricts excessive authentication attempts in the CheckAuth() middleware

SiYuan before v3.7.4 improperly restricts excessive authentication attempts in the CheckAuth() middleware. The HTTP Basic Authentication branch, which guards nearly the entire /api/* surface, accepts the workspace access code (Conf.Acces…

MidnightEPSS 0.43%via NVD
CVE-2026-73045High· 7.5
1mo ago

SiYuan before 3.7.4 contains an improper restriction of excessive authentication attempts vulnerability in the authFilePublishAccess endpoint that allows unauthenticated attackers to brute-force per-notebook publish passwords

SiYuan before 3.7.4 contains an improper restriction of excessive authentication attempts vulnerability in the authFilePublishAccess endpoint that allows unauthenticated attackers to brute-force per-notebook publish passwords. Attackers …

TwilightEPSS 0.30%via NVD
CVE-2026-19898Low· 3.7
1mo ago

A vulnerability was found in VictoriaMetrics up to 1.146.0

A vulnerability was found in VictoriaMetrics up to 1.146.0. Impacted is the function requestHandler of the file app/vmauth/main.go of the component VMAuth Authentication Endpoint. Performing a manipulation results in improper restriction…

SunlitEPSS 0.48%via NVD
CVE-2026-19897Low· 3.7
1mo ago

A vulnerability has been found in mangroup dtale up to 3.22.0

A vulnerability has been found in mangroup dtale up to 3.22.0. This issue affects the function Login of the file dtale/auth.py of the component Login Endpoint. Such manipulation leads to improper restriction of excessive authentication a…

SunlitEPSS 0.37%via NVD
CWE-307 vulnerabilities (CVEs) · VulnSea