Falhas do tipo CWE-307

484 resultados

Falta de proteção contra tentativas excessivas de autenticação

A aplicação não limita ou não desacelera tentativas de login, permitindo que um atacante teste múltiplas credenciais rapidamente (força bruta, dicionário ou spray de senhas). Sem controle, a conta fica vulnerável a comprometimento, especialmente se senhas fracas forem usadas.

Exemplo

Um endpoint de login que aceita 10 mil requisições por segundo sem nenhuma restrição. Um atacante automatiza tentativas com senhas comuns contra mil usuários até acertar credenciais válidas em poucos minutos.

Como mitigar

Implemente rate limiting (máximo de tentativas por IP/usuário em período curto), atrasos progressivos (backoff exponencial) após falhas, bloqueio temporário de conta após N tentativas, e idealmente autenticação multifator para reduzir o dano de senhas comprometidas.

CVE-2026-1409LOWBeetel 777VR1 UART excessive authenticationEPSS 0.4%CVE-2025-24806LOWRegulation applies separately to Username-based logins to Email-based logins in autheliaEPSS 0.4%CVE-2025-69246MEDIUMLack of bruteforce protection in Raytha CMSEPSS 0.4%CVE-2023-48276MEDIUMWordPress WP Forms Puzzle Captcha plugin <= 4.1 - Captcha Bypass vulnerabilityEPSS 0.4%CVE-2024-5682MEDIUMUser Enumeration in Yordam Information Technology's Yordam Library Automation SystemEPSS 0.4%CVE-2026-46649CRITICALJoplin: SSO Auth Code Login Missing Rate Limiting — 9-Digit Numeric Code Brute-Forceable via Unprotected EndpointEPSS 0.4%CVE-2026-74868HIGHSiYuan before 3.7.4 Brute-Force Authentication via Publish ServiceEPSS 0.4%CVE-2026-37603MEDIUMImproper Restriction of Excessive Authentication Attempts in the administration login of pH7Software pH7Builder (pH7 Social Dating CMS) throEPSS 0.4%CVE-2026-89174HIGHKingdom Communication Associated|Smart Video Intercom System - Missing Burte-force ProtectionEPSS 0.4%CVE-2023-48290MEDIUMWordPress Form Maker by 10Web plugin <= 1.15.20 - Captcha Bypass Vulnerability vulnerabilityEPSS 0.4%CVE-2023-23730MEDIUMWordPress Spectra – WordPress Gutenberg Blocks plugin <= 2.3.0 - Captcha Bypass VulnerabilityEPSS 0.4%CVE-2024-35747MEDIUMWordPress Contact Form Builder, Contact Widget plugin <= 2.1.7 - Bypass Vulnerability vulnerabilityEPSS 0.4%CVE-2022-39314MEDIUMUser enumeration in the code-based login and password reset formsEPSS 0.4%CVE-2026-30959MEDIUMOneUptime has WhatsApp Resend Verification Authorization BypassEPSS 0.4%CVE-2026-19897MEDIUMmangroup dtale Login Endpoint auth.py login excessive authenticationEPSS 0.4%CVE-2025-9551MEDIUMProtected Pages - Moderately critical - Access bypass - SA-CONTRIB-2025-101EPSS 0.4%CVE-2026-22629LOWAn improper restriction of excessive authentication attempts vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4 EPSS 0.4%CVE-2025-46606MEDIUMDell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 contain an improper restEPSS 0.4%CVE-2025-4383CRITICALAuthentication Bypass in Art-In Systems' Wi-Fi Cloud HotspotEPSS 0.4%CVE-2025-49186MEDIUMNo brute-force protectionEPSS 0.4%