Weaknesses of type CWE-307

484 results

Falta de Proteção contra Tentativas Excessivas de Autenticação

É a ausência de mecanismos que limitam o número de tentativas de login ou autenticação em um curto período. Um atacante pode fazer força bruta (testar muitas senhas ou códigos) sem ser bloqueado, permitindo descobrir credenciais válidas ou contornar fatores de autenticação como OTP.

Example

Um sistema de login não bloqueia a conta após 5 tentativas erradas nem implementa delay progressivo. Um atacante automático testa 10 mil combinações de senha em minutos contra um usuário-alvo e consegue acesso. Ou um atacante bruta-força códigos de 2FA sem que o sistema limite as tentativas.

How to mitigate

Implemente bloqueio ou throttling: limitar tentativas (ex: máx 5 por minuto), aumentar delay entre tentativas, bloquear conta temporariamente após falhas consecutivas, usar CAPTCHA após N tentativas, e registrar/alertar sobre picos de tentativas suspeitas.

CVE-2026-1409LOWBeetel 777VR1 UART excessive authenticationEPSS 0.4%CVE-2025-24806LOWRegulation applies separately to Username-based logins to Email-based logins in autheliaEPSS 0.4%CVE-2025-69246MEDIUMLack of bruteforce protection in Raytha CMSEPSS 0.4%CVE-2023-48276MEDIUMWordPress WP Forms Puzzle Captcha plugin <= 4.1 - Captcha Bypass vulnerabilityEPSS 0.4%CVE-2024-5682MEDIUMUser Enumeration in Yordam Information Technology's Yordam Library Automation SystemEPSS 0.4%CVE-2026-46649CRITICALJoplin: SSO Auth Code Login Missing Rate Limiting — 9-Digit Numeric Code Brute-Forceable via Unprotected EndpointEPSS 0.4%CVE-2026-74868HIGHSiYuan before 3.7.4 Brute-Force Authentication via Publish ServiceEPSS 0.4%CVE-2026-37603MEDIUMImproper Restriction of Excessive Authentication Attempts in the administration login of pH7Software pH7Builder (pH7 Social Dating CMS) throEPSS 0.4%CVE-2026-89174HIGHKingdom Communication Associated|Smart Video Intercom System - Missing Burte-force ProtectionEPSS 0.4%CVE-2023-48290MEDIUMWordPress Form Maker by 10Web plugin <= 1.15.20 - Captcha Bypass Vulnerability vulnerabilityEPSS 0.4%CVE-2023-23730MEDIUMWordPress Spectra – WordPress Gutenberg Blocks plugin <= 2.3.0 - Captcha Bypass VulnerabilityEPSS 0.4%CVE-2024-35747MEDIUMWordPress Contact Form Builder, Contact Widget plugin <= 2.1.7 - Bypass Vulnerability vulnerabilityEPSS 0.4%CVE-2022-39314MEDIUMUser enumeration in the code-based login and password reset formsEPSS 0.4%CVE-2026-30959MEDIUMOneUptime has WhatsApp Resend Verification Authorization BypassEPSS 0.4%CVE-2026-19897MEDIUMmangroup dtale Login Endpoint auth.py login excessive authenticationEPSS 0.4%CVE-2025-9551MEDIUMProtected Pages - Moderately critical - Access bypass - SA-CONTRIB-2025-101EPSS 0.4%CVE-2026-22629LOWAn improper restriction of excessive authentication attempts vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4 EPSS 0.4%CVE-2025-46606MEDIUMDell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 contain an improper restEPSS 0.4%CVE-2025-4383CRITICALAuthentication Bypass in Art-In Systems' Wi-Fi Cloud HotspotEPSS 0.4%CVE-2025-49186MEDIUMNo brute-force protectionEPSS 0.4%