VulnSea

CWE-307

CVEs classified under CWE-307, newest first.

63 CVEsRSS

CVE-2026-62862Critical· 9.1PoC
1mo ago

Typebot is an open-source chatbot builder

Typebot is an open-source chatbot builder. In self-hosted versions up to and including 3.17.1, the default passwordless email magic-link authentication is vulnerable to login-code brute forcing that leads to account takeover. The email p…

▾ AbyssalbaptisteArno · typebot.ioEPSS 0.53%via NVD
CVE-2026-69183High· 7.5
1mo ago

Monkeytype is a minimalistic and customizable typing test

Monkeytype is a minimalistic and customizable typing test. In 26.26.0 and earlier, the backend rate-limit key generator in backend/src/middlewares/rate-limit.ts uses client-controlled cf-connecting-ip and x-forwarded-for headers before t…

▾ TwilightEPSS 0.48%via NVD
CVE-2026-73529Medium· 5.3
1mo ago

Plainpad through 1.1.1, fixed in commit d3823fc, contains a missing rate limiting vulnerability that allows unauthenticated attackers to send unbounded login requests to the POST /v1/sessions endpoint due to dead code in App\Http\Kernel.…

Plainpad through 1.1.1, fixed in commit d3823fc, contains a missing rate limiting vulnerability that allows unauthenticated attackers to send unbounded login requests to the POST /v1/sessions endpoint due to dead code in App\Http\Kernel.…

▾ SunlitEPSS 0.41%via NVD
CVE-2026-73046Critical· 9.8
1mo ago

SiYuan before v3.7.4 improperly restricts excessive authentication attempts in the CheckAuth() middleware

SiYuan before v3.7.4 improperly restricts excessive authentication attempts in the CheckAuth() middleware. The HTTP Basic Authentication branch, which guards nearly the entire /api/* surface, accepts the workspace access code (Conf.Acces…

▾ MidnightEPSS 0.79%via NVD
CVE-2026-73045High· 7.5
1mo ago

SiYuan before 3.7.4 contains an improper restriction of excessive authentication attempts vulnerability in the authFilePublishAccess endpoint that allows unauthenticated attackers to brute-force per-notebook publish passwords

SiYuan before 3.7.4 contains an improper restriction of excessive authentication attempts vulnerability in the authFilePublishAccess endpoint that allows unauthenticated attackers to brute-force per-notebook publish passwords. Attackers …

▾ TwilightEPSS 0.52%via NVD
CVE-2026-19898Low· 3.7
1mo ago

A vulnerability was found in VictoriaMetrics up to 1.146.0

A vulnerability was found in VictoriaMetrics up to 1.146.0. Impacted is the function requestHandler of the file app/vmauth/main.go of the component VMAuth Authentication Endpoint. Performing a manipulation results in improper restriction…

▾ SunlitEPSS 0.75%via NVD
CVE-2026-19897Low· 3.7
1mo ago

A vulnerability has been found in mangroup dtale up to 3.22.0

A vulnerability has been found in mangroup dtale up to 3.22.0. This issue affects the function Login of the file dtale/auth.py of the component Login Endpoint. Such manipulation leads to improper restriction of excessive authentication a…

▾ SunlitEPSS 0.57%via NVD
CVE-2026-19895Low· 3.7
1mo ago

A vulnerability was detected in opensourcepos Open Source Point of Sale up to 3.4.2

A vulnerability was detected in opensourcepos Open Source Point of Sale up to 3.4.2. This affects the function Login::index of the file app/Config/Filters.php of the component Login Endpoint. The manipulation results in improper restrict…

▾ SunlitEPSS 0.63%via NVD
CVE-2026-48084High· 7.4
1mo ago

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Versions prior to 1.0.2 don't throttle failed passphrase login attempts. An attacker can submit unlimited wrong passphrase guesse…

▾ TwilightEPSS 0.39%via NVD
CVE-2026-48071Medium· 5.8
1mo ago

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.4, the PIN-type challenge throttle uses `emailHash` as the only key. The throttle rows live in the central `…

▾ SunlitEPSS 0.40%via NVD
CVE-2026-71213Critical· 9.1
1mo ago

Typemill's login endpoint (POST /tm/login, ControllerWebAuth::login) performs no rate-limiting, failed-attempt counting, or account lockout when captcha is disabled, which is the default configuration

Typemill's login endpoint (POST /tm/login, ControllerWebAuth::login) performs no rate-limiting, failed-attempt counting, or account lockout when captcha is disabled, which is the default configuration. An unauthenticated attacker can sen…

▾ MidnightEPSS 0.45%via NVD
CVE-2026-71205Medium· 6.5PoC
1mo ago

changedetection.io's /login route checks the submitted password against a single PBKDF2-HMAC-SHA256 hash with no per-IP or per-session rate limiting, failed-attempt counter, or lockout (no rate-limiting library is present in requirements…

changedetection.io's /login route checks the submitted password against a single PBKDF2-HMAC-SHA256 hash with no per-IP or per-session rate limiting, failed-attempt counter, or lockout (no rate-limiting library is present in requirements…

▾ TwilightEPSS 0.27%via NVD
CVE-2026-8793NonePoC
1mo ago

PaperCut NG/MF does not properly restrict excessive authentication attempts within its login component

PaperCut NG/MF does not properly restrict excessive authentication attempts within its login component. An unauthenticated remote attacker can exploit this vulnerability to perform unrestricted brute-force or credential-stuffing attacks …

▾ TwilightEPSS 0.68%via NVD
CVE-2026-42952High· 7.5
2mo ago

Previously, there was no throttling on repeated authentication attempts to the charging station backend, which could allow an attacker to execute a denial-of-service attack.

Previously, there was no throttling on repeated authentication attempts to the charging station backend, which could allow an attacker to execute a denial-of-service attack.

▾ TwilightEPSS 0.54%via NVD
CVE-2026-15079None
2mo ago

Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Login Disable allows Brute Force

Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Login Disable allows Brute Force. This issue affects Login Disable versions: from 0.0.0 to 2.1.4.

▾ SunlitEPSS 0.28%via NVD
CVE-2026-55501High· 7.3
2mo ago

9router: Login brute-force protection bypass via spoofed X-Forwarded-For header

9router: Login brute-force protection bypass via spoofed X-Forwarded-For header

▾ Twilight9router · 9routerEPSS 0.52%via GHSA
GHSA-r4v7-6wcg-ghj5Medium· 6.5
3mo ago

FileBrowser: Missing Rate Limiting on Authentication Endpoint Enables Brute Force Attacks

FileBrowser: Missing Rate Limiting on Authentication Endpoint Enables Brute Force Attacks

▾ Sunlitgtsteffaniak · github.com/gtsteffaniak/filebrowservia GHSA
CVE-2025-31991Medium· 6.8
5mo ago

Rate Limiting for attempting a user login is not being properly enforced, making HCL DevOps Velocity susceptible to brute-force attacks past the unsuccessful login attempt limit.  This vulnerability is fixed in 5.1.7.

Rate Limiting for attempting a user login is not being properly enforced, making HCL DevOps Velocity susceptible to brute-force attacks past the unsuccessful login attempt limit.  This vulnerability is fixed in 5.1.7.

▾ Sunlithcltech · devops_velocityEPSS 0.23%via NVD
CVE-2026-34505Medium· 6.5
6mo ago

OpenClaw before 2026.3.12 applies rate limiting only after successful webhook authentication, allowing attackers to bypass rate limits and brute-force webhook secrets

OpenClaw before 2026.3.12 applies rate limiting only after successful webhook authentication, allowing attackers to bypass rate limits and brute-force webhook secrets. Attackers can submit repeated authentication requests with invalid se…

▾ Sunlitopenclaw · openclawEPSS 0.36%via NVD
CVE-2026-33580Medium· 6.5
6mo ago

OpenClaw before 2026.3.28 contains a missing rate limiting vulnerability in the Nextcloud Talk webhook authentication that allows attackers to brute-force weak shared secrets

OpenClaw before 2026.3.28 contains a missing rate limiting vulnerability in the Nextcloud Talk webhook authentication that allows attackers to brute-force weak shared secrets. Attackers who can reach the webhook endpoint can exploit this…

▾ Sunlitopenclaw · openclawEPSS 0.43%via NVD
CVE-2025-36363Medium· 5.9
6mo ago

IBM DevOps Plan 3.0.0 through 3.0.5 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials.

IBM DevOps Plan 3.0.0 through 3.0.5 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials.

▾ Sunlithcltech · devops_planEPSS 0.24%via NVD
CVE-2025-65427Medium· 6.5PoC
9mo ago

An issue was discovered in Dbit N300 T1 Pro Easy Setup Wireless Wi-Fi Router on firmware version V1.0.0 does not implement rate limiting to /api/login allowing attackers to brute force password enumerations.

An issue was discovered in Dbit N300 T1 Pro Easy Setup Wireless Wi-Fi Router on firmware version V1.0.0 does not implement rate limiting to /api/login allowing attackers to brute force password enumerations.

▾ Twilightdbitnet · dbit_n300_t1_pro_firmwareEPSS 0.27%via NVD
CVE-2025-12995High· 8.1
9mo ago

Medtronic CareLink Network allows an unauthenticated remote attacker to perform a brute force attack on an API endpoint that could be used to determine a valid password under certain circumstances

Medtronic CareLink Network allows an unauthenticated remote attacker to perform a brute force attack on an API endpoint that could be used to determine a valid password under certain circumstances. This issue affects CareLink Network: be…

▾ Twilightmedtronic · carelink_networkEPSS 0.33%via NVD
CVE-2025-56224High· 8.1PoC
11mo ago

A lack of rate limiting in the One-Time Password (OTP) verification endpoint of SigningHub v8.6.8 allows attackers to bypass verification via a bruteforce attack.

A lack of rate limiting in the One-Time Password (OTP) verification endpoint of SigningHub v8.6.8 allows attackers to bypass verification via a bruteforce attack.

▾ Midnightascertia · signinghubEPSS 0.39%via NVD
CVE-2023-32251Low· 3.70day
1y ago

A vulnerability has been identified in the Linux kernel's ksmbd component (kernel SMB/CIFS server)

A vulnerability has been identified in the Linux kernel's ksmbd component (kernel SMB/CIFS server). A security control designed to prevent dictionary attacks, which introduces a 5-second delay during session setup, can be bypassed throug…

▾ TwilightEPSS 0.44%via NVD
CVE-2025-23368High· 8.1
1y ago

A flaw was found in Wildfly Elytron integration

A flaw was found in Wildfly Elytron integration. The component does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it more susceptible to brute force attacks via CLI.

▾ Twilightredhat · wildfly_coreEPSS 0.87%via NVD
CVE-2024-32868Medium· 6.5
2y ago

ZITADEL provides users the possibility to use Time-based One-Time-Password (TOTP) and One-Time-Password (OTP) through SMS and Email

ZITADEL provides users the possibility to use Time-based One-Time-Password (TOTP) and One-Time-Password (OTP) through SMS and Email. While ZITADEL already gives administrators the option to define a `Lockout Policy` with a maximum amount…

▾ Sunlitzitadel · zitadelEPSS 0.46%via NVD
CVE-2023-27172Critical· 9.1
2y ago

Xpand IT Write-back Manager v2.3.1 uses weak secret keys to sign JWT tokens

Xpand IT Write-back Manager v2.3.1 uses weak secret keys to sign JWT tokens. This allows attackers to easily obtain the secret key used to sign JWT tokens via a bruteforce attack.

▾ Midnightxpand-it · write-back_managerEPSS 0.69%via NVD
CVE-2022-37145High· 7.5
4y ago

The PlexTrac platform prior to version 1.17.0 does not restrict excessive authentication attempts for accounts configured to use the PlexTrac authentication provider

The PlexTrac platform prior to version 1.17.0 does not restrict excessive authentication attempts for accounts configured to use the PlexTrac authentication provider. An unauthenticated remote attacker could perform a bruteforce attack o…

▾ Twilightplextrac · plextracEPSS 1.0%via NVD
CVE-2022-37144High· 8.8
4y ago

The PlexTrac platform prior to API version 1.17.0 does not restrict excessive MFA TOTP submission attempts

The PlexTrac platform prior to API version 1.17.0 does not restrict excessive MFA TOTP submission attempts. An unauthenticated remote attacker in possession of a valid username and password can bruteforce their way past MFA protections t…

▾ Twilightplextrac · plextracEPSS 0.94%via NVD
CWE-307 vulnerabilities (CVEs) — page 2 · VulnSea