Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-307
Weakness type CWE-307 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 103 | 98 | 0 |
Monthly trend
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▄▄██▁
2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 2 · 2026-04 0 · 2026-05 5 · 2026-06 13 · 2026-07 15 · 2026-08 31 · 2026-09 31 · 2026-10 1
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-44596 | 9.8 | 80.7 | — | Yamcs: No Rate Limiting on Authentication Endpoint |
| CVE-2023-21709 | 9.8 | 79.8 | — | Microsoft Exchange Server Elevation of Privilege Vulnerability |
| CVE-2021-29023 | 5.3 | 65.8 | — | — |
| CVE-2026-8760 | 9.8 | 63.7 | — | Login with OTP <= 1.6 - Unauthenticated Authentication Bypass via OTP Brute Force |
| CVE-2025-23368 | 8.1 | 57.8 | — | Org.wildfly.core:wildfly-elytron-integration: wildfly elytron brute force attack via cli |
| CVE-2026-73046 | 9.3 | 54.7 | — | SiYuan before v3.7.4 Authentication Bypass via HTTP Basic Auth |
| CVE-2026-73056 | 9.3 | 54.7 | — | SiYuan kernel before 3.7.4 Unthrottled Brute-Force via API Token |
| CVE-2026-19898 | 2.9 | 53.4 | — | VictoriaMetrics VMAuth Authentication Endpoint main.go requestHandler excessive authent… |
| CVE-2026-50176 | 8.7 | 51.9 | — | EVoke Systems EVoke CSMS Improper Restriction of Excessive Authentication Attempts |
| CVE-2026-93650 | 2.9 | 51.1 | — | Saleor throttling.py get_client_ip excessive authentication |
| CVE-2023-27172 | 9.1 | 51.0 | — | — |
| CVE-2026-8793 | 6.9 | 50.8 | — | PaperCut NG/MF: Insufficient brute-force protection |
| CVE-2026-91973 | 8.7 | 50.4 | — | Vikunja before 2.6.0 Authentication Bypass via CalDAV BasicAuth |
| CVE-2026-31851 | 7.7 | 50.2 | — | Nexxt Nebula 300+ - Lack of Rate Limiting Enables Brute-Force Attacks |
| CVE-2026-65894 | 8.7 | 49.9 | — | Improper Authentication Vulnerability in CP PLUS EZ-P21 IP Camera |
| CVE-2026-75773 | 2.9 | 49.5 | — | karakeep-app karakeep Login Endpoint auth.ts authorize excessive authentication |
| CVE-2026-78551 | 8.8 | 49.3 | — | RansomLook Login Endpoint Allows Timing-Based Username Enumeration and Unthrottled Auth… |
| CVE-2026-6853 | 9.8 | 49.0 | — | OTP Bypass in Başbelen Group's Pause+ Mobile App |
| CVE-2026-3329 | 8.7 | 48.5 | — | Nexus Repository Manager - Improper Restriction of Excessive Authentication Attempts |
| CVE-2026-91972 | 8.7 | 48.5 | — | Vikunja before 2.6.0 Authentication Bypass via Unthrottled API |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| wwbn | 5 |
| siyuan-note | 4 |
| drupal | 3 |
| decolua | 2 |
| go-vikunja | 2 |
| hcl software | 2 |
| mediatek | 2 |
| open-reception | 2 |
| openclaw | 2 |
| red hat | 2 |
| thorsten | 2 |
| @fastify/rate-limit | 1 |
| ail project | 1 |
| akinsoft | 1 |
| alextselegidis | 1 |