CWE-620 · 95 записей
Unverified Password Change
CVE этого класса
95 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
64На этой неделе | CVE-2024-20419Готовый эксплойт | A vulnerability in the authentication system of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote atcisco · smart software manager on-prem · CWE-620 | Критическая10,0 | — | 80,6 % | 17 июл. 2024 г. |
44В плане | CVE-2024-48887Proof of concept | A unverified password change vulnerability in Fortinet FortiSwitch GUI may allow a remote unauthenticated attacker to change admin passwordfortinet · fortiswitch · CWE-620 | Критическая9,8 | — | 15,7 % | 8 апр. 2025 г. |
44В плане | CVE-2025-4322Proof of concept | Motors <= 5.6.67 - Unauthenticated Privilege Escalation via Password Update/Account Takeoverstylemixthemes · motors - car dealer, rental & listing wordpress theme · CWE-620 | Критическая9,8 | — | 15,5 % | 20 мая 2025 г. |
40В плане | CVE-2024-12824Proof of concept | Nokri – Job Board WordPress Theme <= 1.6.2 - Unauthenticated Arbitrary Password Changescriptsbundle · nokri – job board wordpress theme · CWE-620 | Критическая9,8 | — | 2,4 % | 1 мар. 2025 г. |
39Наблюдать | CVE-2024-13375Эксплойта нет | Adifier System <= 3.1.7 - Unauthenticated Arbitrary Password Resetspoonthemes · adifier system · CWE-620 | Критическая9,8 | — | 1,4 % | 18 янв. 2025 г. |
39Наблюдать | CVE-2023-4214Эксплойта нет | AppPresser <= 4.2.5 - Insecure Password Reset Mechanismapppresser · apppresser · CWE-620 | Критическая9,8 | — | 0,9 % | 17 нояб. 2023 г. |
39Наблюдать | CVE-2023-2449Эксплойта нет | UserPro <= 5.1.1 - Insecure Password Reset Mechanismuserproplugin · userpro · CWE-620 | Критическая9,8 | — | 0,9 % | 22 нояб. 2023 г. |
39Наблюдать | CVE-2026-15964Proof of concept | Single Sign On For TNG <= 2.0.0 - Unauthenticated Privilege Escalation via Unverified Password Changebritcoder · single sign on for tng · CWE-620 | Критическая9,8 | — | 0,9 % | 1 авг. 2026 г. |
39Наблюдать | CVE-2025-10159Эксплойта нет | An authentication bypass vulnerability allows remote attackers to gain administrative privileges on Sophos AP6 Series Wireless Access Pointssophos · ap6 series wireless access points · CWE-620 | Критическая9,8 | — | 0,9 % | 9 сент. 2025 г. |
39Наблюдать | CVE-2025-2253Эксплойта нет | IMITHEMES Listing <= 3.3 - Unauthenticated Privilege Escalation via Unverified Password Resetimithemes · imithemes listing · CWE-620 | Критическая9,8 | — | 0,8 % | 9 мая 2025 г. |
39Наблюдать | CVE-2026-12692Эксплойта нет | Improper Authentication in Vimesoft's Enterprise Video Platformvimesoft inc. · enterprise video platform · CWE-620 | Критическая9,8 | — | 0,6 % | 17 июл. 2026 г. |
39Наблюдать | CVE-2025-4606Proof of concept | Sala - Startup & SaaS WordPress Theme <= 1.1.4 - Unauthenticated Privilege Escalation via Password Reset/Account Takeoveruxper · sala - startup & saas wordpress theme · CWE-620 | Критическая9,8 | — | 0,6 % | 9 июл. 2025 г. |
39Наблюдать | CVE-2023-3069Эксплойта нет | Unverified Password Change in tsolucio/coreboscorebos · corebos · CWE-620 | Критическая9,8 | — | 0,6 % | 2 июн. 2023 г. |
39Наблюдать | CVE-2025-63362Эксплойта нет | Waveshare RS232/485 TO WIFI ETH (B) Serial to Ethernet/Wi-Fi Gateway Firmware V3.1.1.0: HW 4.3.2.1: Webpage V7.04T.07.002880.0301 allows attwaveshare · rs232\/485 to wifi eth \(b\) firmware · CWE-620 | Критическая9,8 | — | 0,6 % | 4 дек. 2025 г. |
39Наблюдать | CVE-2025-3603Эксплойта нет | Flynax Bridge <= 2.2.0 - Unauthenticated Privilege Escalation via Password Updateflynax · flynax bridge · CWE-620 | Критическая9,8 | — | 0,6 % | 24 апр. 2025 г. |
39Наблюдать | CVE-2024-26520Эксплойта нет | An issue in Hangzhou Xiongwei Technology Development Co., Ltd.CWE-620 | Критическая9,8 | — | 0,5 % | 26 июл. 2024 г. |
39Наблюдать | CVE-2024-12860Эксплойта нет | CarSpot – Dealership Wordpress Classified Theme <= 2.4.3 - Unauthenticated Arbitrary Password Reset/Account Takeovercarspot project · carspot · CWE-620 | Критическая9,8 | — | 0,5 % | 18 февр. 2025 г. |
39Наблюдать | CVE-2025-9286Proof of concept | Appy Pie Connect for WooCommerce <= 1.1.2 - Missing Authorization to Unauthenticated Privilege Escalation via reset_user_passwordhancock11 · appy pie connect for woocommerce · CWE-620 | Критическая9,8 | — | 0,5 % | 3 окт. 2025 г. |
39Наблюдать | CVE-2025-1107Эксплойта нет | Unverified password change vulnerability in Jantoimpronta · janto · CWE-620 | Критическая9,9 | — | 0,4 % | 7 февр. 2025 г. |
39Наблюдать | CVE-2024-12827Эксплойта нет | DWT - Directory & Listing WordPress Theme <= 3.3.6 - Unauthenticated Arbitrary User Password Resetscriptsbundle · dwt - directory & listing wordpress theme · CWE-620 | Критическая9,8 | — | 0,4 % | 27 июн. 2025 г. |
39Наблюдать | CVE-2024-45647Эксплойта нет | IBM Security Verify Access unverified password changeibm · security verify access · CWE-620 | Критическая9,8 | — | 0,3 % | 20 янв. 2025 г. |
38Наблюдать | CVE-2024-33699Эксплойта нет | The LevelOne WBR-6012 router's web application has a vulnerability in its firmware version R0.40e6, allowing attackers to change the adminislevel1 · wbr-6012 firmware · CWE-620 | Высокая8,8 | — | 11,2 % | 30 окт. 2024 г. |
37Наблюдать | CVE-2020-7378Proof of concept | CRIXP OpenCRX Unverified Password Changeopencrx · opencrx · CWE-620 | Критическая9,1 | — | 2,6 % | 24 нояб. 2020 г. |
37Наблюдать | CVE-2026-91995Эксплойта нет | pig before 4.1.0 Unverified Password Change via /register/passwordpig-mesh · pig · CWE-620 | Критическая9,3 | — | 0,9 % | 15 сент. 2026 г. |
37Наблюдать | CVE-2025-4558Эксплойта нет | WormHole Tech GPM - Unverified Password Changewormhole tech · gpm · CWE-620 | Критическая9,3 | — | 0,5 % | 12 мая 2025 г. |
- CVE-2024-2041964На этой неделе
A vulnerability in the authentication system of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote at
КритическаяCVSS 10,0Готовый эксплойтEPSS 81 %cisco · smart software manager on-prem17 июл. 2024 г.
- CVE-2024-4888744В плане
A unverified password change vulnerability in Fortinet FortiSwitch GUI may allow a remote unauthenticated attacker to change admin password
КритическаяCVSS 9,8Proof of conceptEPSS 16 %fortinet · fortiswitch8 апр. 2025 г.
- CVE-2025-432244В плане
Motors <= 5.6.67 - Unauthenticated Privilege Escalation via Password Update/Account Takeover
КритическаяCVSS 9,8Proof of conceptEPSS 16 %stylemixthemes · motors - car dealer, rental & listing wordpress theme20 мая 2025 г.
- CVE-2024-1282440В плане
Nokri – Job Board WordPress Theme <= 1.6.2 - Unauthenticated Arbitrary Password Change
КритическаяCVSS 9,8Proof of conceptEPSS 2 %scriptsbundle · nokri – job board wordpress theme1 мар. 2025 г.
- CVE-2024-1337539Наблюдать
Adifier System <= 3.1.7 - Unauthenticated Arbitrary Password Reset
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %spoonthemes · adifier system18 янв. 2025 г.
- CVE-2023-421439Наблюдать
AppPresser <= 4.2.5 - Insecure Password Reset Mechanism
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %apppresser · apppresser17 нояб. 2023 г.
- CVE-2023-244939Наблюдать
UserPro <= 5.1.1 - Insecure Password Reset Mechanism
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %userproplugin · userpro22 нояб. 2023 г.
- CVE-2026-1596439Наблюдать
Single Sign On For TNG <= 2.0.0 - Unauthenticated Privilege Escalation via Unverified Password Change
КритическаяCVSS 9,8Proof of conceptEPSS 1 %britcoder · single sign on for tng1 авг. 2026 г.
- CVE-2025-1015939Наблюдать
An authentication bypass vulnerability allows remote attackers to gain administrative privileges on Sophos AP6 Series Wireless Access Points
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %sophos · ap6 series wireless access points9 сент. 2025 г.
- CVE-2025-225339Наблюдать
IMITHEMES Listing <= 3.3 - Unauthenticated Privilege Escalation via Unverified Password Reset
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %imithemes · imithemes listing9 мая 2025 г.
- CVE-2026-1269239Наблюдать
Improper Authentication in Vimesoft's Enterprise Video Platform
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %vimesoft inc. · enterprise video platform17 июл. 2026 г.
- CVE-2025-460639Наблюдать
Sala - Startup & SaaS WordPress Theme <= 1.1.4 - Unauthenticated Privilege Escalation via Password Reset/Account Takeover
КритическаяCVSS 9,8Proof of conceptEPSS 1 %uxper · sala - startup & saas wordpress theme9 июл. 2025 г.
- CVE-2023-306939Наблюдать
Unverified Password Change in tsolucio/corebos
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %corebos · corebos2 июн. 2023 г.
- CVE-2025-6336239Наблюдать
Waveshare RS232/485 TO WIFI ETH (B) Serial to Ethernet/Wi-Fi Gateway Firmware V3.1.1.0: HW 4.3.2.1: Webpage V7.04T.07.002880.0301 allows att
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %waveshare · rs232\/485 to wifi eth \(b\) firmware4 дек. 2025 г.
- CVE-2025-360339Наблюдать
Flynax Bridge <= 2.2.0 - Unauthenticated Privilege Escalation via Password Update
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %flynax · flynax bridge24 апр. 2025 г.
- CVE-2024-2652039Наблюдать
An issue in Hangzhou Xiongwei Technology Development Co., Ltd.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %26 июл. 2024 г.
- CVE-2024-1286039Наблюдать
CarSpot – Dealership Wordpress Classified Theme <= 2.4.3 - Unauthenticated Arbitrary Password Reset/Account Takeover
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %carspot project · carspot18 февр. 2025 г.
- CVE-2025-928639Наблюдать
Appy Pie Connect for WooCommerce <= 1.1.2 - Missing Authorization to Unauthenticated Privilege Escalation via reset_user_password
КритическаяCVSS 9,8Proof of conceptEPSS 0 %hancock11 · appy pie connect for woocommerce3 окт. 2025 г.
- CVE-2025-110739Наблюдать
Unverified password change vulnerability in Janto
КритическаяCVSS 9,9Эксплойта нетEPSS 0 %impronta · janto7 февр. 2025 г.
- CVE-2024-1282739Наблюдать
DWT - Directory & Listing WordPress Theme <= 3.3.6 - Unauthenticated Arbitrary User Password Reset
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %scriptsbundle · dwt - directory & listing wordpress theme27 июн. 2025 г.
- CVE-2024-4564739Наблюдать
IBM Security Verify Access unverified password change
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %ibm · security verify access20 янв. 2025 г.
- CVE-2024-3369938Наблюдать
The LevelOne WBR-6012 router's web application has a vulnerability in its firmware version R0.40e6, allowing attackers to change the adminis
ВысокаяCVSS 8,8Эксплойта нетEPSS 11 %level1 · wbr-6012 firmware30 окт. 2024 г.
- CVE-2020-737837Наблюдать
CRIXP OpenCRX Unverified Password Change
КритическаяCVSS 9,1Proof of conceptEPSS 3 %opencrx · opencrx24 нояб. 2020 г.
- CVE-2026-9199537Наблюдать
pig before 4.1.0 Unverified Password Change via /register/password
КритическаяCVSS 9,3Эксплойта нетEPSS 1 %pig-mesh · pig15 сент. 2026 г.
- CVE-2025-455837Наблюдать
WormHole Tech GPM - Unverified Password Change
КритическаяCVSS 9,3Эксплойта нетEPSS 1 %wormhole tech · gpm12 мая 2025 г.