Falhas do tipo CWE-307

484 resultados

Falta de proteção contra tentativas excessivas de autenticação

A aplicação não limita ou não desacelera tentativas de login, permitindo que um atacante teste múltiplas credenciais rapidamente (força bruta, dicionário ou spray de senhas). Sem controle, a conta fica vulnerável a comprometimento, especialmente se senhas fracas forem usadas.

Exemplo

Um endpoint de login que aceita 10 mil requisições por segundo sem nenhuma restrição. Um atacante automatiza tentativas com senhas comuns contra mil usuários até acertar credenciais válidas em poucos minutos.

Como mitigar

Implemente rate limiting (máximo de tentativas por IP/usuário em período curto), atrasos progressivos (backoff exponencial) após falhas, bloqueio temporário de conta após N tentativas, e idealmente autenticação multifator para reduzir o dano de senhas comprometidas.

CVE-2026-33935HIGHMyTube has Unauthenticated Account Lockout via Shared Login Attempt StateEPSS 0.5%CVE-2025-48187CRITICALRAGFlow through 0.18.1 allows account takeover because it is possible to conduct successful brute-force attacks against email verification cEPSS 0.5%CVE-2023-32657MEDIUMWeintek Weincloud Improper Restriction of Excessive Authentication AttemptsEPSS 0.5%CVE-2024-8462MEDIUMWindmill HTTP Request users.rs excessive authenticationEPSS 0.5%CVE-2025-3709CRITICALFlowring Technology Agentflow - Account Lockout BypassEPSS 0.5%CVE-2024-41904HIGHA vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V2.0). The affected application do not prEPSS 0.5%CVE-2026-42952HIGHHydro-Québec Le Circuit Electrique charging station backend Improper Restriction of Excessive Authentication AttemptsEPSS 0.5%CVE-2023-54347HIGHOpenEMR 7.0.1 Authentication Brute Force Mitigation BypassEPSS 0.5%CVE-2024-21500MEDIUMAll versions of the package github.com/greenpau/caddy-security are vulnerable to Improper Restriction of Excessive Authentication Attempts vEPSS 0.5%CVE-2025-54833MEDIUMOPEXUS FOIAXpress Public Access Link (PAL) account-lockout and CAPTCHA protection bypassEPSS 0.5%CVE-2022-42478HIGHAn Improper Restriction of Excessive Authentication Attempts [CWE-307] in FortiSIEM below 7.0.0 may allow a non-privileged user with access EPSS 0.5%CVE-2022-38491HIGHAn issue was discovered in EasyVista 2020.2.125.3 and 2022.1.109.0.03. Part of the application does not implement protection against brute-fEPSS 0.5%CVE-2026-32292CRITICALGL-iNet Comet (GL-RM1) KVM insufficient login rate-limitingEPSS 0.5%CVE-2026-75773MEDIUMkarakeep-app karakeep Login Endpoint auth.ts authorize excessive authenticationEPSS 0.5%CVE-2023-45582MEDIUMAn improper restriction of excessive authentication attempts vulnerability [CWE-307] in FortiMail webmail version 7.2.0 through 7.2.4, 7.0.0EPSS 0.5%CVE-2025-52997MEDIUMFile Browser Insecurely Handles PasswordsEPSS 0.5%CVE-2026-25945HIGHEV2GO ev2go.io Improper Restriction of Excessive Authentication AttemptsEPSS 0.5%CVE-2024-28825MEDIUMBrute-force protection ineffective for some login methodsEPSS 0.5%CVE-2026-62220MEDIUMOpenClaw 2026.2.25 < 2026.5.26 WebSocket Rate Limit BypassEPSS 0.5%CVE-2025-49195MEDIUMNo protection against brute-force attacksEPSS 0.5%