İçeriğe atla
Noroxi

CWE-640 · 273 kayıt

Weak Password Recovery Mechanism for Forgotten Password

Bu sınıftaki CVE’ler

273 kayıt

  • Weak Password Recovery Mechanism for Forgotten Password in GitLab

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %95

    gitlab · gitlab12 Oca 2024

  • CVE-2019-18818
    68Bu hafta

    strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/strapi-plugin-users-p

    KritikCVSS 9,8SilahlaştırılmışEPSS %98

    strapi · strapi7 Kas 2019

  • CVE-2017-7615
    62Bu hafta

    MantisBT through 2.3.0 allows arbitrary password reset and unauthenticated admin access via an empty confirm_hash value to verify.php.

    YüksekCVSS 8,8SilahlaştırılmışEPSS %91

    mantisbt · mantisbt16 Nis 2017

  • CVE-2019-19844
    55Planlayın

    Django before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 allows account takeover.

    KritikCVSS 9,8Kavram kanıtıEPSS %54

    djangoproject · django18 Ara 2019

  • CVE-2025-6216
    53Planlayın

    Allegra calculateTokenExpDate Password Recovery Authentication Bypass Vulnerability

    KritikCVSS 9,8Kavram kanıtıEPSS %48

    alltena · allegra20 Haz 2025

  • CVE-2025-47646
    46Planlayın

    WordPress PSW Front-end Login & Registration plugin <= 1.13 - Broken Authentication Vulnerability

    KritikCVSS 9,8Kavram kanıtıEPSS %25

    gilblas ngunte possi · psw front-end login & registration23 May 2025

  • CVE-2026-19632
    42Planlayın

    TranslatePress – Multilingual <= 3.3.1 - Unauthenticated Account Takeover via Password Reset Link Disclosure

    KritikCVSS 9,8Kavram kanıtıEPSS %9

    cozmoslabs · translatepress – translate multilingual sites with ai translation26 Ağu 2026

  • CVE-2017-17097
    41Planlayın

    gps-server.net GPS Tracking Software (self hosted) 2.x has a password reset procedure that immediately resets passwords upon an unauthentica

    KritikCVSS 9,8Kavram kanıtıEPSS %7

    gps-server · gps tracking software2 Oca 2018

  • CVE-2012-5686
    40Planlayın

    ZPanel 10.0.1 has insufficient entropy for its password reset process.

    KritikCVSS 9,8Kavram kanıtıEPSS %5

    zpanelcp · zpanel4 Şub 2020

  • CVE-2018-19488
    40Planlayın

    The WP-jobhunt plugin before version 2.4 for WordPress does not control AJAX requests sent to the cs_reset_pass() function through the admin

    KritikCVSS 9,8İstismar yokEPSS %4

    wp-jobhunt project · wp-jobhunt21 Mar 2019

  • CVE-2018-7811
    40Planlayın

    An Unverified Password Change vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 whi

    KritikCVSS 9,8İstismar yokEPSS %3

    schneider-electric · modicom m340 firmware30 Kas 2018

  • CVE-2018-12421
    40Planlayın

    LTB (aka LDAP Tool Box) Self Service Password before 1.3 allows a change to a user password (without knowing the old password) via a crafted

    KritikCVSS 9,8İstismar yokEPSS %3

    ltb-project · ldap tool box self service password14 Haz 2018

  • CVE-2018-7809
    40Planlayın

    An Unverified Password Change vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 whi

    KritikCVSS 9,8İstismar yokEPSS %2

    schneider-electric · modicom m340 firmware30 Kas 2018

  • CVE-2015-4689
    40Planlayın

    Ellucian (formerly SunGard) Banner Student 8.5.1.2 through 8.7 allows remote attackers to reset arbitrary passwords via unspecified vectors,

    KritikCVSS 9,8İstismar yokEPSS %2

    ellucian · banner student11 Eyl 2017

  • CVE-2019-11393
    40Planlayın

    An issue was discovered in /admin/users/update in M/Monit before 3.7.3.

    KritikCVSS 9,8İstismar yokEPSS %2

    tildeslash · monit22 Nis 2019

  • CVE-2021-22763
    40Planlayın

    A CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability exists in PowerLogic PM55xx, PowerLogic PM8ECC, PowerLogic

    KritikCVSS 9,8İstismar yokEPSS %2

    schneider-electric · powerlogic pm5560 firmware11 Haz 2021

  • CVE-2018-17298
    40Planlayın

    An issue was discovered in Enalean Tuleap before 10.5.

    KritikCVSS 9,8İstismar yokEPSS %2

    enalean · tuleap21 Eyl 2018

  • CVE-2019-15929
    40Planlayın

    In Craft CMS through 3.1.7, the elevated session password prompt was not being rate limited like normal login forms, leading to the possibil

    KritikCVSS 9,8İstismar yokEPSS %2

    craftcms · craft cms24 Eki 2019

  • CVE-2022-23855
    40Planlayın

    An issue was discovered in Saviynt Enterprise Identity Cloud (EIC) 5.5 SP2.x.

    KritikCVSS 9,8İstismar yokEPSS %2

    saviynt · enterprise identity cloud23 Oca 2022

  • CVE-2024-8878
    40Planlayın

    Unauthenticated Password Reset

    KritikCVSS 10,0İstismar yokEPSS %1

    riello-ups · netman 204 firmware24 Eyl 2024

  • CVE-2025-63314
    40Planlayın

    A static password reset token in the password reset function of DDSN Interactive Acora CMS v10.7.1 allows attackers to arbitrarily reset the

    KritikCVSS 10,0Kavram kanıtıEPSS %0

    ddsn · cm3 acora cms12 Oca 2026

  • CVE-2018-18871
    39İzleyin

    Missing password verification in the web interface on Gigaset Maxwell Basic VoIP phones with firmware 2.22.7 would allow a remote attacker (

    KritikCVSS 9,8İstismar yokEPSS %2

    gigasetpro · maxwell basic firmware20 Ara 2018

  • CVE-2017-2766
    39İzleyin

    EMC Documentum eRoom version 7.4.4, EMC Documentum eRoom version 7.4.4 SP1, EMC Documentum eRoom version prior to 7.4.5 P04, EMC Documentum

    KritikCVSS 9,8İstismar yokEPSS %2

    emc · documentum eroom3 Şub 2017

  • CVE-2018-16988
    39İzleyin

    An issue was discovered in Open XDMoD through 7.5.0.

    KritikCVSS 9,8İstismar yokEPSS %2

    buffalo · open xdmod2 May 2019

  • CVE-2021-28293
    39İzleyin

    Seceon aiSIEM before 6.3.2 (build 585) is prone to an unauthenticated account takeover vulnerability in the Forgot Password feature.

    KritikCVSS 9,8İstismar yokEPSS %2

    seceon · aisiem8 Haz 2021

Tüm zafiyet sınıfları