Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'cwe-307'

View all threats tagged with 'cwe-307'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-307

Threats Tagged 'cwe-307'

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-56450: CWE-307 Improper Restriction of Excessive Authentication Attempts in ail project ail frameworkCVE-2026-56450
0

AIL did not restrict repeated failed attempts to verify a two-factor authentication (OTP) code. An attacker who had reached the 2FA verification step, such as after successfully completing the password-authentication stage, could submit an unlimited number of OTP guesses. This could enable brute-force guessing of a valid code and bypass the intended second authentication factor, resulting in unauthorized account access. The patch introduces per-user failed-OTP tracking, blocks verification after 30 failed attempts for one hour, clears the counter after a successful OTP verification, and provides administrator recovery actions to purge affected lockouts.

Join the discussion
CVE-2024-9342: CWE-307 Improper Restriction of Excessive Authentication Attempts in Eclipse Foundation Eclipse GlassfishCVE-2024-9342
0

In Eclipse GlassFish versions before 8.0.3 it is possible to perform Login Brute Force attacks as there is no limitation in the number of failed login attempts. GlassFish 8.0.3 adds automatic attack protection documented in https://glassfish.org/docs/latest/security-guide.html#brute-force-attack-protection .

Join the discussion
CVE-2026-6853: CWE-307 Improper restriction of excessive authentication attempts in Başbelen Group Food Cafe Businesses Industry and Trade Ltd. Co. Pause+ Mobile AppCVE-2026-6853
0

Improper restriction of excessive authentication attempts vulnerability in Başbelen Group Food Cafe Businesses Industry and Trade Ltd. Co. Pause+ Mobile App allows Authentication Bypass. This issue affects Pause+ Mobile App: from v1.0.6 before v1.5.

Join the discussion
CVE-2026-3329: CWE-307 Improper Restriction of Excessive Authentication Attempts in Sonatype Nexus Repository ManagerCVE-2026-3329
0

A remote unauthenticated attacker may be able to conduct credential-guessing attacks against user accounts in Sonatype Nexus Repository via authentication endpoints.

Join the discussion
CVE-2025-1496: CWE-307 Improper Restriction of Excessive Authentication Attempts in BG-TEK Coslat HotspotCVE-2025-1496
0

Improper Restriction of Excessive Authentication Attempts vulnerability in BG-TEK Coslat Hotspot allows Password Brute Forcing, Authentication Abuse. This issue affects Coslat Hotspot: before 6.26.0.R.20250227.

Join the discussion
CVE-2024-5862: CWE-307 Improper Restriction of Excessive Authentication Attempts in Mia Technology Inc. Mia-Med Health AplicationCVE-2024-5862
0

Improper Restriction of Excessive Authentication Attempts vulnerability in Mia Technology Inc. Mia-Med Health Aplication allows Interface Manipulation. This issue affects Mia-Med Health Aplication: before 1.0.14.

Join the discussion
CVE-2024-5682: CWE-307 Improper Restriction of Excessive Authentication Attempts in Yordam Information Technology Yordam Library Automation SystemCVE-2024-5682
0

Improper Restriction of Excessive Authentication Attempts vulnerability in Yordam Information Technology Yordam Library Automation System allows Interface Manipulation. This issue affects Yordam Library Automation System: before 20.1.

Join the discussion
CVE-2024-8429: CWE-307 Improper Restriction of Excessive Authentication Attempts in Digital Operation Services WiFiBuradaCVE-2024-8429
0

Improper Restriction of Excessive Authentication Attempts vulnerability in Digital Operation Services WiFiBurada allows Use of Known Domain Credentials. This issue affects WiFiBurada: before 1.0.5.

Join the discussion
CVE-2026-49324: CWE-400 Uncontrolled Resource Consumption in Indian Motorcycle (Polaris Inc.) Scout Bobber + TechCVE-2026-49324
0

Uncontrolled resource consumption in the Wireless Control Module (WCM) of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker with write access to the in-vehicle network to permanently immobilize the motorcycle. The WCM enforces a brute-force lockout on the immobilizer authentication algorithm, but the lockout counter is reachable by any unauthenticated message, has no session binding, and does not reset on power cycle. An attacker can deliberately trip the lockout with a small number of crafted frames, leaving the bike un-startable until dealer service. Specific thresholds have been withheld pending vendor remediation.

Join the discussion
CVE-2026-8760: CWE-307 Improper Restriction of Excessive Authentication Attempts in india-web-developer Login with OTPCVE-2026-8760
0

The Login with OTP plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.6. This is due to an incomplete fix for CVE-2024-11178: the rate-limit/lockout check added to `otpl_login_action()` was placed only inside the OTP-generation branch and is never evaluated on the OTP-validation branch, and the generated 6-digit OTP additionally has no expiration. This makes it possible for unauthenticated attackers to brute-force the 900,000-value OTP space for any user account (including administrators) and obtain a valid `wp_set_auth_cookie()` session, leading to full site compromise.

Join the discussion

Showing 1 to 10 of 10 results

Filters:Tag: cwe-307
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses