Weaknesses of type CWE-307

484 results

Falta de Proteção contra Tentativas Excessivas de Autenticação

É a ausência de mecanismos que limitam o número de tentativas de login ou autenticação em um curto período. Um atacante pode fazer força bruta (testar muitas senhas ou códigos) sem ser bloqueado, permitindo descobrir credenciais válidas ou contornar fatores de autenticação como OTP.

Example

Um sistema de login não bloqueia a conta após 5 tentativas erradas nem implementa delay progressivo. Um atacante automático testa 10 mil combinações de senha em minutos contra um usuário-alvo e consegue acesso. Ou um atacante bruta-força códigos de 2FA sem que o sistema limite as tentativas.

How to mitigate

Implemente bloqueio ou throttling: limitar tentativas (ex: máx 5 por minuto), aumentar delay entre tentativas, bloquear conta temporariamente após falhas consecutivas, usar CAPTCHA após N tentativas, e registrar/alertar sobre picos de tentativas suspeitas.

CVE-2025-46739HIGHImproper Restriction of Excessive Authentication AttemptsEPSS 0.4%CVE-2026-33580MEDIUMOpenClaw < 2026.3.28 - Brute Force Attack via Missing Rate Limiting on Webhook Shared Secret AuthenticationEPSS 0.4%CVE-2025-1928CRITICALImproper Authentication in Restajet's Online Food Delivery SystemEPSS 0.4%CVE-2026-11779MEDIUMPayloadCMS 3.84.1 - Authenticated account lockout bypass through default unlock accessEPSS 0.4%CVE-2025-46414CRITICALEG4 Electronics EG4 Inverters Improper Restriction of Excessive Authentication AttemptsEPSS 0.4%CVE-2025-62257MEDIUMPassword enumeration vulnerability in Liferay Portal 7.4.0 through 7.4.3.119, and older unsupported versions, and Liferay DXP 2024.Q1.1 throEPSS 0.4%CVE-2026-48084HIGHOpenReception doesn't rate limit passphrase login attemptsEPSS 0.4%CVE-2026-35623MEDIUMOpenClaw < 2026.3.25 - Brute-Force Attack via Missing Webhook Password Rate LimitingEPSS 0.4%CVE-2024-28022MEDIUMA vulnerability exists in the UNEM server / APIGateway that if exploited allows a malicious user to perform an arbitrary number of authenticEPSS 0.4%CVE-2025-1714MEDIUMUsername Enumeration in GliffyEPSS 0.4%CVE-2026-76940HIGHEbyte NA111-M Improper Restriction of Excessive Authentication AttemptsEPSS 0.4%CVE-2026-24696HIGHEveron api.everon.io Improper Restriction of Excessive Authentication AttemptsEPSS 0.4%CVE-2023-48745MEDIUMWordPress Captcha Code plugin <= 2.9 - Captcha Bypass vulnerabilityEPSS 0.4%CVE-2025-53544HIGHTrilium Notes is Vulnerable to Brute-force Protection Bypass via Initial Sync Seed RetrievalEPSS 0.4%CVE-2024-32720MEDIUMWordPress Appointment Hour Booking plugin <= 1.4.56 - Captcha Bypass vulnerabilityEPSS 0.4%CVE-2026-36959HIGHU-SPEED N300 router V1.0.0 does not implement rate limiting or account lockout protections on the /api/login endpoint. This allows an attackEPSS 0.3%CVE-2026-65948HIGHApache Ranger: UnixAuth lacks brute-force protectionEPSS 0.3%CVE-2025-2416HIGHOTP Bypass in Akinsoft's LimonDeskEPSS 0.3%CVE-2025-2413HIGHOTP Bypass in Akinsoft's ProKuaforEPSS 0.3%CVE-2025-2414HIGHOTP Bypass in Akinsoft's OctoCloudEPSS 0.3%