CWE-640 · 273 записей
Weak Password Recovery Mechanism for Forgotten Password
CVE этого класса
274 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
97Срочно | CVE-2023-7028Готовый эксплойт | Weak Password Recovery Mechanism for Forgotten Password in GitLabgitlab · gitlab · CWE-640 | Критическая9,8 | KEV | 94,6 % | 12 янв. 2024 г. |
68На этой неделе | CVE-2019-18818Готовый эксплойт | strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/strapi-plugin-users-pstrapi · strapi · CWE-640 | Критическая9,8 | — | 97,6 % | 7 нояб. 2019 г. |
62На этой неделе | CVE-2017-7615Готовый эксплойт | MantisBT through 2.3.0 allows arbitrary password reset and unauthenticated admin access via an empty confirm_hash value to verify.php.mantisbt · mantisbt · CWE-640 | Высокая8,8 | — | 91,1 % | 16 апр. 2017 г. |
55В плане | CVE-2019-19844Proof of concept | Django before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 allows account takeover.djangoproject · django · CWE-640 | Критическая9,8 | — | 53,6 % | 18 дек. 2019 г. |
53В плане | CVE-2025-6216Proof of concept | Allegra calculateTokenExpDate Password Recovery Authentication Bypass Vulnerabilityalltena · allegra · CWE-640 | Критическая9,8 | — | 47,8 % | 20 июн. 2025 г. |
46В плане | CVE-2025-47646Proof of concept | WordPress PSW Front-end Login & Registration plugin <= 1.13 - Broken Authentication Vulnerabilitygilblas ngunte possi · psw front-end login & registration · CWE-640 | Критическая9,8 | — | 24,9 % | 23 мая 2025 г. |
42В плане | CVE-2026-19632Proof of concept | TranslatePress – Multilingual <= 3.3.1 - Unauthenticated Account Takeover via Password Reset Link Disclosurecozmoslabs · translatepress – translate multilingual sites with ai translation · CWE-640 | Критическая9,8 | — | 9,0 % | 26 авг. 2026 г. |
41В плане | CVE-2017-17097Proof of concept | gps-server.net GPS Tracking Software (self hosted) 2.x has a password reset procedure that immediately resets passwords upon an unauthenticagps-server · gps tracking software · CWE-640 | Критическая9,8 | — | 6,9 % | 2 янв. 2018 г. |
40В плане | CVE-2012-5686Proof of concept | ZPanel 10.0.1 has insufficient entropy for its password reset process.zpanelcp · zpanel · CWE-640 | Критическая9,8 | — | 4,8 % | 4 февр. 2020 г. |
40В плане | CVE-2018-19488Эксплойта нет | The WP-jobhunt plugin before version 2.4 for WordPress does not control AJAX requests sent to the cs_reset_pass() function through the adminwp-jobhunt project · wp-jobhunt · CWE-640 | Критическая9,8 | — | 4,1 % | 21 мар. 2019 г. |
40В плане | CVE-2018-7811Эксплойта нет | An Unverified Password Change vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 whischneider-electric · modicom m340 firmware · CWE-640 | Критическая9,8 | — | 3,5 % | 30 нояб. 2018 г. |
40В плане | CVE-2018-12421Эксплойта нет | LTB (aka LDAP Tool Box) Self Service Password before 1.3 allows a change to a user password (without knowing the old password) via a craftedltb-project · ldap tool box self service password · CWE-640 | Критическая9,8 | — | 2,8 % | 14 июн. 2018 г. |
40В плане | CVE-2018-7809Эксплойта нет | An Unverified Password Change vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 whischneider-electric · modicom m340 firmware · CWE-640 | Критическая9,8 | — | 2,5 % | 30 нояб. 2018 г. |
40В плане | CVE-2015-4689Эксплойта нет | Ellucian (formerly SunGard) Banner Student 8.5.1.2 through 8.7 allows remote attackers to reset arbitrary passwords via unspecified vectors,ellucian · banner student · CWE-640 | Критическая9,8 | — | 2,3 % | 11 сент. 2017 г. |
40В плане | CVE-2019-11393Эксплойта нет | An issue was discovered in /admin/users/update in M/Monit before 3.7.3.tildeslash · monit · CWE-640 | Критическая9,8 | — | 2,1 % | 22 апр. 2019 г. |
40В плане | CVE-2021-22763Эксплойта нет | A CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability exists in PowerLogic PM55xx, PowerLogic PM8ECC, PowerLogic schneider-electric · powerlogic pm5560 firmware · CWE-640 | Критическая9,8 | — | 1,9 % | 11 июн. 2021 г. |
40В плане | CVE-2018-17298Эксплойта нет | An issue was discovered in Enalean Tuleap before 10.5.enalean · tuleap · CWE-640 | Критическая9,8 | — | 1,8 % | 21 сент. 2018 г. |
40В плане | CVE-2019-15929Эксплойта нет | In Craft CMS through 3.1.7, the elevated session password prompt was not being rate limited like normal login forms, leading to the possibilcraftcms · craft cms · CWE-640 | Критическая9,8 | — | 1,8 % | 24 окт. 2019 г. |
40В плане | CVE-2022-23855Эксплойта нет | An issue was discovered in Saviynt Enterprise Identity Cloud (EIC) 5.5 SP2.x.saviynt · enterprise identity cloud · CWE-640 | Критическая9,8 | — | 1,7 % | 23 янв. 2022 г. |
40В плане | CVE-2024-8878Эксплойта нет | Unauthenticated Password Resetriello-ups · netman 204 firmware · CWE-640 | Критическая10,0 | — | 1,3 % | 24 сент. 2024 г. |
40В плане | CVE-2025-63314Proof of concept | A static password reset token in the password reset function of DDSN Interactive Acora CMS v10.7.1 allows attackers to arbitrarily reset theddsn · cm3 acora cms · CWE-640 | Критическая10,0 | — | 0,3 % | 12 янв. 2026 г. |
39Наблюдать | CVE-2018-18871Эксплойта нет | Missing password verification in the web interface on Gigaset Maxwell Basic VoIP phones with firmware 2.22.7 would allow a remote attacker (gigasetpro · maxwell basic firmware · CWE-640 | Критическая9,8 | — | 1,7 % | 20 дек. 2018 г. |
39Наблюдать | CVE-2017-2766Эксплойта нет | EMC Documentum eRoom version 7.4.4, EMC Documentum eRoom version 7.4.4 SP1, EMC Documentum eRoom version prior to 7.4.5 P04, EMC Documentum emc · documentum eroom · CWE-640 | Критическая9,8 | — | 1,6 % | 3 февр. 2017 г. |
39Наблюдать | CVE-2018-16988Эксплойта нет | An issue was discovered in Open XDMoD through 7.5.0.buffalo · open xdmod · CWE-640 | Критическая9,8 | — | 1,6 % | 2 мая 2019 г. |
39Наблюдать | CVE-2021-28293Эксплойта нет | Seceon aiSIEM before 6.3.2 (build 585) is prone to an unauthenticated account takeover vulnerability in the Forgot Password feature.seceon · aisiem · CWE-640 | Критическая9,8 | — | 1,6 % | 8 июн. 2021 г. |
- CVE-2023-702897Срочно
Weak Password Recovery Mechanism for Forgotten Password in GitLab
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 95 %gitlab · gitlab12 янв. 2024 г.
- CVE-2019-1881868На этой неделе
strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/strapi-plugin-users-p
КритическаяCVSS 9,8Готовый эксплойтEPSS 98 %strapi · strapi7 нояб. 2019 г.
- CVE-2017-761562На этой неделе
MantisBT through 2.3.0 allows arbitrary password reset and unauthenticated admin access via an empty confirm_hash value to verify.php.
ВысокаяCVSS 8,8Готовый эксплойтEPSS 91 %mantisbt · mantisbt16 апр. 2017 г.
- CVE-2019-1984455В плане
Django before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 allows account takeover.
КритическаяCVSS 9,8Proof of conceptEPSS 54 %djangoproject · django18 дек. 2019 г.
- CVE-2025-621653В плане
Allegra calculateTokenExpDate Password Recovery Authentication Bypass Vulnerability
КритическаяCVSS 9,8Proof of conceptEPSS 48 %alltena · allegra20 июн. 2025 г.
- CVE-2025-4764646В плане
WordPress PSW Front-end Login & Registration plugin <= 1.13 - Broken Authentication Vulnerability
КритическаяCVSS 9,8Proof of conceptEPSS 25 %gilblas ngunte possi · psw front-end login & registration23 мая 2025 г.
- CVE-2026-1963242В плане
TranslatePress – Multilingual <= 3.3.1 - Unauthenticated Account Takeover via Password Reset Link Disclosure
КритическаяCVSS 9,8Proof of conceptEPSS 9 %cozmoslabs · translatepress – translate multilingual sites with ai translation26 авг. 2026 г.
- CVE-2017-1709741В плане
gps-server.net GPS Tracking Software (self hosted) 2.x has a password reset procedure that immediately resets passwords upon an unauthentica
КритическаяCVSS 9,8Proof of conceptEPSS 7 %gps-server · gps tracking software2 янв. 2018 г.
- CVE-2012-568640В плане
ZPanel 10.0.1 has insufficient entropy for its password reset process.
КритическаяCVSS 9,8Proof of conceptEPSS 5 %zpanelcp · zpanel4 февр. 2020 г.
- CVE-2018-1948840В плане
The WP-jobhunt plugin before version 2.4 for WordPress does not control AJAX requests sent to the cs_reset_pass() function through the admin
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %wp-jobhunt project · wp-jobhunt21 мар. 2019 г.
- CVE-2018-781140В плане
An Unverified Password Change vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 whi
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %schneider-electric · modicom m340 firmware30 нояб. 2018 г.
- CVE-2018-1242140В плане
LTB (aka LDAP Tool Box) Self Service Password before 1.3 allows a change to a user password (without knowing the old password) via a crafted
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %ltb-project · ldap tool box self service password14 июн. 2018 г.
- CVE-2018-780940В плане
An Unverified Password Change vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 whi
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %schneider-electric · modicom m340 firmware30 нояб. 2018 г.
- CVE-2015-468940В плане
Ellucian (formerly SunGard) Banner Student 8.5.1.2 through 8.7 allows remote attackers to reset arbitrary passwords via unspecified vectors,
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %ellucian · banner student11 сент. 2017 г.
- CVE-2019-1139340В плане
An issue was discovered in /admin/users/update in M/Monit before 3.7.3.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %tildeslash · monit22 апр. 2019 г.
- CVE-2021-2276340В плане
A CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability exists in PowerLogic PM55xx, PowerLogic PM8ECC, PowerLogic
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %schneider-electric · powerlogic pm5560 firmware11 июн. 2021 г.
- CVE-2018-1729840В плане
An issue was discovered in Enalean Tuleap before 10.5.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %enalean · tuleap21 сент. 2018 г.
- CVE-2019-1592940В плане
In Craft CMS through 3.1.7, the elevated session password prompt was not being rate limited like normal login forms, leading to the possibil
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %craftcms · craft cms24 окт. 2019 г.
- CVE-2022-2385540В плане
An issue was discovered in Saviynt Enterprise Identity Cloud (EIC) 5.5 SP2.x.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %saviynt · enterprise identity cloud23 янв. 2022 г.
- CVE-2024-887840В плане
Unauthenticated Password Reset
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %riello-ups · netman 204 firmware24 сент. 2024 г.
- CVE-2025-6331440В плане
A static password reset token in the password reset function of DDSN Interactive Acora CMS v10.7.1 allows attackers to arbitrarily reset the
КритическаяCVSS 10,0Proof of conceptEPSS 0 %ddsn · cm3 acora cms12 янв. 2026 г.
- CVE-2018-1887139Наблюдать
Missing password verification in the web interface on Gigaset Maxwell Basic VoIP phones with firmware 2.22.7 would allow a remote attacker (
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %gigasetpro · maxwell basic firmware20 дек. 2018 г.
- CVE-2017-276639Наблюдать
EMC Documentum eRoom version 7.4.4, EMC Documentum eRoom version 7.4.4 SP1, EMC Documentum eRoom version prior to 7.4.5 P04, EMC Documentum
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %emc · documentum eroom3 февр. 2017 г.
- CVE-2018-1698839Наблюдать
An issue was discovered in Open XDMoD through 7.5.0.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %buffalo · open xdmod2 мая 2019 г.
- CVE-2021-2829339Наблюдать
Seceon aiSIEM before 6.3.2 (build 585) is prone to an unauthenticated account takeover vulnerability in the Forgot Password feature.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %seceon · aisiem8 июн. 2021 г.