Falhas do tipo CWE-307

484 resultados

Falta de proteção contra tentativas excessivas de autenticação

A aplicação não limita ou não desacelera tentativas de login, permitindo que um atacante teste múltiplas credenciais rapidamente (força bruta, dicionário ou spray de senhas). Sem controle, a conta fica vulnerável a comprometimento, especialmente se senhas fracas forem usadas.

Exemplo

Um endpoint de login que aceita 10 mil requisições por segundo sem nenhuma restrição. Um atacante automatiza tentativas com senhas comuns contra mil usuários até acertar credenciais válidas em poucos minutos.

Como mitigar

Implemente rate limiting (máximo de tentativas por IP/usuário em período curto), atrasos progressivos (backoff exponencial) após falhas, bloqueio temporário de conta após N tentativas, e idealmente autenticação multifator para reduzir o dano de senhas comprometidas.

CVE-2025-46739HIGHImproper Restriction of Excessive Authentication AttemptsEPSS 0.4%CVE-2026-33580MEDIUMOpenClaw < 2026.3.28 - Brute Force Attack via Missing Rate Limiting on Webhook Shared Secret AuthenticationEPSS 0.4%CVE-2025-1928CRITICALImproper Authentication in Restajet's Online Food Delivery SystemEPSS 0.4%CVE-2026-11779MEDIUMPayloadCMS 3.84.1 - Authenticated account lockout bypass through default unlock accessEPSS 0.4%CVE-2025-46414CRITICALEG4 Electronics EG4 Inverters Improper Restriction of Excessive Authentication AttemptsEPSS 0.4%CVE-2025-62257MEDIUMPassword enumeration vulnerability in Liferay Portal 7.4.0 through 7.4.3.119, and older unsupported versions, and Liferay DXP 2024.Q1.1 throEPSS 0.4%CVE-2026-48084HIGHOpenReception doesn't rate limit passphrase login attemptsEPSS 0.4%CVE-2026-35623MEDIUMOpenClaw < 2026.3.25 - Brute-Force Attack via Missing Webhook Password Rate LimitingEPSS 0.4%CVE-2024-28022MEDIUMA vulnerability exists in the UNEM server / APIGateway that if exploited allows a malicious user to perform an arbitrary number of authenticEPSS 0.4%CVE-2025-1714MEDIUMUsername Enumeration in GliffyEPSS 0.4%CVE-2026-76940HIGHEbyte NA111-M Improper Restriction of Excessive Authentication AttemptsEPSS 0.4%CVE-2026-24696HIGHEveron api.everon.io Improper Restriction of Excessive Authentication AttemptsEPSS 0.4%CVE-2023-48745MEDIUMWordPress Captcha Code plugin <= 2.9 - Captcha Bypass vulnerabilityEPSS 0.4%CVE-2025-53544HIGHTrilium Notes is Vulnerable to Brute-force Protection Bypass via Initial Sync Seed RetrievalEPSS 0.4%CVE-2024-32720MEDIUMWordPress Appointment Hour Booking plugin <= 1.4.56 - Captcha Bypass vulnerabilityEPSS 0.4%CVE-2026-36959HIGHU-SPEED N300 router V1.0.0 does not implement rate limiting or account lockout protections on the /api/login endpoint. This allows an attackEPSS 0.3%CVE-2026-65948HIGHApache Ranger: UnixAuth lacks brute-force protectionEPSS 0.3%CVE-2025-2416HIGHOTP Bypass in Akinsoft's LimonDeskEPSS 0.3%CVE-2025-2413HIGHOTP Bypass in Akinsoft's ProKuaforEPSS 0.3%CVE-2025-2414HIGHOTP Bypass in Akinsoft's OctoCloudEPSS 0.3%