CWE•Base•Draft•20 recent CVEs
CWE-307Improper Restriction of Excessive Authentication Attempts
Description
The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.
Common consequences
- Access Control→Bypass Protection MechanismAn attacker could perform an arbitrary number of authentication attempts using different passwords, and eventually gain access to the targeted account using a brute force attack.
Potential mitigations
- Architecture and Design[object Object]
- Architecture and Design[object Object]
Related CWEs
Recent CVEs classified under this CWE
CVE-2026-151447.32026-07-29CVE-2026-163478.82026-07-28CVE-2026-559773.32026-07-28CVE-2026-658942026-07-27CVE-2026-82854.32026-07-21CVE-2026-328257.32026-07-20CVE-2026-622205.32026-07-17CVE-2026-445966.52026-07-16CVE-2026-142542026-07-16CVE-2026-614587.52026-07-13CVE-2026-429527.52026-07-10CVE-2026-119155.92026-07-10CVE-2026-150795.42026-07-10CVE-2026-555017.32026-07-10CVE-2026-539047.12026-07-01CVE-2026-117792026-06-26CVE-2026-501767.52026-06-25CVE-2026-473802026-06-23CVE-2026-564502026-06-22CVE-2026-472032026-06-19