CWE-307

CWE-307 · 13 records · 13 with a public proof-of-concept

Records the NVD classes under CWE-307, highest CVSS first.

  1. CRITICAL 9.1CVE-2026-85734public PoC

    LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, the POST /login endpoint in lightrag/api/lightrag_server.py does not impose a rate limit, account lockout, delay, or counter for failed authentication attempts. A network attacke…

    AI risk analysis on Exploit-DB.ai →

  2. CRITICAL 9.1CVE-2026-71213public PoC

    Typemill's login endpoint (POST /tm/login, ControllerWebAuth::login) performs no rate-limiting, failed-attempt counting, or account lockout when captcha is disabled, which is the default configuration. An unauthenticated attacker can send unlimited password-gu…

    AI risk analysis on Exploit-DB.ai →

  3. HIGH 7.4CVE-2026-102334public PoC

    Nginx Proxy Manager through 2.16.0 lacks rate-limiting on authentication endpoints, allowing unauthenticated attackers to make unlimited password guesses against any account. Attackers can brute-force login credentials via POST /api/tokens and subsequently gue…

    AI risk analysis on Exploit-DB.ai →

  4. MEDIUM 6.8CVE-2026-58271public PoC

    Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.4.0, `POST /api/app/sync/register` accepts credentials and a TOTP code to register a desktop sync client. On a failed TOTP, `SyncClientsManager.…

    AI risk analysis on Exploit-DB.ai →

  5. MEDIUM 6.5CVE-2026-100678public PoC

    stoatchat before 0.15.5 fails to enforce account-level attempt limits on MFA login challenges, allowing attackers who know a password to guess TOTP codes with only IP-based rate limiting. Attackers can reuse MFA challenge tickets across multiple failed attempt…

    AI risk analysis on Exploit-DB.ai →

  6. MEDIUM 6.5CVE-2026-100501public PoC

    Flame through 2.4.0 contains an improper restriction of excessive authentication attempts vulnerability in the POST /api/auth login endpoint that allows unauthenticated attackers to brute-force the admin password. Attackers can submit unlimited password guesse…

    AI risk analysis on Exploit-DB.ai →

  7. MEDIUM 6.5CVE-2026-37603public PoC

    Improper Restriction of Excessive Authentication Attempts in the administration login of pH7Software pH7Builder (pH7 Social Dating CMS) through 19.2.0. The CAPTCHA escalation flag is stored in the PHP session as captcha_admin_enabled and the CAPTCHA form eleme…

    AI risk analysis on Exploit-DB.ai →

  8. MEDIUM 6.5CVE-2026-71205public PoC

    changedetection.io's /login route checks the submitted password against a single PBKDF2-HMAC-SHA256 hash with no per-IP or per-session rate limiting, failed-attempt counter, or lockout (no rate-limiting library is present in requirements.txt).

    AI risk analysis on Exploit-DB.ai →

  9. MEDIUM 5.3CVE-2026-56682public PoC

    9Router is an AI router & token saver. Prior to 0.5.6, 9Router deployments that allow requests to reach Next.js without the sanitizing custom-server.js wrapper use the client-supplied X-9r-Real-Ip value as the bucket key in getClientIp, checkLock, and recordFa…

    AI risk analysis on Exploit-DB.ai →

  10. MEDIUM 5.3CVE-2026-77561public PoC

    Tinyauth is an authentication and authorization server. Prior to 5.1.0, an unauthenticated remote attacker can send POST /api/user/login requests with 257 distinct nonexistent usernames to fill MaxLoginAttemptRecords and activate a global login lockdown. inter…

    AI risk analysis on Exploit-DB.ai →

  11. UNSCOREDCVE-2026-84461public PoC

    Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, the two-factor login step let an attacker try unlimited password guesses for any account without triggering Zammad's normal lockout or rate limiting. The response also revealed…

    AI risk analysis on Exploit-DB.ai →

  12. UNSCOREDCVE-2026-49470public PoC

    GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, the time-based one-time password verification endpoint does not limit failed submissions per user. An attacker who has obtained a user's primary authentication credentials can r…

    AI risk analysis on Exploit-DB.ai →

  13. UNSCOREDCVE-2026-46649public PoC

    Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2, Joplin Server's GET /api/login_with_code/:id endpoint accepts a nine-digit SSO authentication code with a ten-minute lifetime without appl…

    AI risk analysis on Exploit-DB.ai →