CWE-640 · 273 kayıt
Weak Password Recovery Mechanism for Forgotten Password
Bu sınıftaki CVE’ler
273 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
97Hemen | CVE-2023-7028Silahlaştırılmış | Weak Password Recovery Mechanism for Forgotten Password in GitLabgitlab · gitlab · CWE-640 | Kritik9,8 | KEV | %94,6 | 12 Oca 2024 |
68Bu hafta | CVE-2019-18818Silahlaştırılmış | strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/strapi-plugin-users-pstrapi · strapi · CWE-640 | Kritik9,8 | — | %97,6 | 7 Kas 2019 |
62Bu hafta | CVE-2017-7615Silahlaştırılmış | MantisBT through 2.3.0 allows arbitrary password reset and unauthenticated admin access via an empty confirm_hash value to verify.php.mantisbt · mantisbt · CWE-640 | Yüksek8,8 | — | %91,1 | 16 Nis 2017 |
55Planlayın | CVE-2019-19844Kavram kanıtı | Django before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 allows account takeover.djangoproject · django · CWE-640 | Kritik9,8 | — | %53,6 | 18 Ara 2019 |
53Planlayın | CVE-2025-6216Kavram kanıtı | Allegra calculateTokenExpDate Password Recovery Authentication Bypass Vulnerabilityalltena · allegra · CWE-640 | Kritik9,8 | — | %47,8 | 20 Haz 2025 |
46Planlayın | CVE-2025-47646Kavram kanıtı | WordPress PSW Front-end Login & Registration plugin <= 1.13 - Broken Authentication Vulnerabilitygilblas ngunte possi · psw front-end login & registration · CWE-640 | Kritik9,8 | — | %24,9 | 23 May 2025 |
42Planlayın | CVE-2026-19632Kavram kanıtı | TranslatePress – Multilingual <= 3.3.1 - Unauthenticated Account Takeover via Password Reset Link Disclosurecozmoslabs · translatepress – translate multilingual sites with ai translation · CWE-640 | Kritik9,8 | — | %9,0 | 26 Ağu 2026 |
41Planlayın | CVE-2017-17097Kavram kanıtı | gps-server.net GPS Tracking Software (self hosted) 2.x has a password reset procedure that immediately resets passwords upon an unauthenticagps-server · gps tracking software · CWE-640 | Kritik9,8 | — | %6,9 | 2 Oca 2018 |
40Planlayın | CVE-2012-5686Kavram kanıtı | ZPanel 10.0.1 has insufficient entropy for its password reset process.zpanelcp · zpanel · CWE-640 | Kritik9,8 | — | %4,8 | 4 Şub 2020 |
40Planlayın | CVE-2018-19488İstismar yok | The WP-jobhunt plugin before version 2.4 for WordPress does not control AJAX requests sent to the cs_reset_pass() function through the adminwp-jobhunt project · wp-jobhunt · CWE-640 | Kritik9,8 | — | %4,1 | 21 Mar 2019 |
40Planlayın | CVE-2018-7811İstismar yok | An Unverified Password Change vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 whischneider-electric · modicom m340 firmware · CWE-640 | Kritik9,8 | — | %3,5 | 30 Kas 2018 |
40Planlayın | CVE-2018-12421İstismar yok | LTB (aka LDAP Tool Box) Self Service Password before 1.3 allows a change to a user password (without knowing the old password) via a craftedltb-project · ldap tool box self service password · CWE-640 | Kritik9,8 | — | %2,8 | 14 Haz 2018 |
40Planlayın | CVE-2018-7809İstismar yok | An Unverified Password Change vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 whischneider-electric · modicom m340 firmware · CWE-640 | Kritik9,8 | — | %2,5 | 30 Kas 2018 |
40Planlayın | CVE-2015-4689İstismar yok | Ellucian (formerly SunGard) Banner Student 8.5.1.2 through 8.7 allows remote attackers to reset arbitrary passwords via unspecified vectors,ellucian · banner student · CWE-640 | Kritik9,8 | — | %2,3 | 11 Eyl 2017 |
40Planlayın | CVE-2019-11393İstismar yok | An issue was discovered in /admin/users/update in M/Monit before 3.7.3.tildeslash · monit · CWE-640 | Kritik9,8 | — | %2,1 | 22 Nis 2019 |
40Planlayın | CVE-2021-22763İstismar yok | A CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability exists in PowerLogic PM55xx, PowerLogic PM8ECC, PowerLogic schneider-electric · powerlogic pm5560 firmware · CWE-640 | Kritik9,8 | — | %1,9 | 11 Haz 2021 |
40Planlayın | CVE-2018-17298İstismar yok | An issue was discovered in Enalean Tuleap before 10.5.enalean · tuleap · CWE-640 | Kritik9,8 | — | %1,8 | 21 Eyl 2018 |
40Planlayın | CVE-2019-15929İstismar yok | In Craft CMS through 3.1.7, the elevated session password prompt was not being rate limited like normal login forms, leading to the possibilcraftcms · craft cms · CWE-640 | Kritik9,8 | — | %1,8 | 24 Eki 2019 |
40Planlayın | CVE-2022-23855İstismar yok | An issue was discovered in Saviynt Enterprise Identity Cloud (EIC) 5.5 SP2.x.saviynt · enterprise identity cloud · CWE-640 | Kritik9,8 | — | %1,7 | 23 Oca 2022 |
40Planlayın | CVE-2024-8878İstismar yok | Unauthenticated Password Resetriello-ups · netman 204 firmware · CWE-640 | Kritik10,0 | — | %1,3 | 24 Eyl 2024 |
40Planlayın | CVE-2025-63314Kavram kanıtı | A static password reset token in the password reset function of DDSN Interactive Acora CMS v10.7.1 allows attackers to arbitrarily reset theddsn · cm3 acora cms · CWE-640 | Kritik10,0 | — | %0,3 | 12 Oca 2026 |
39İzleyin | CVE-2018-18871İstismar yok | Missing password verification in the web interface on Gigaset Maxwell Basic VoIP phones with firmware 2.22.7 would allow a remote attacker (gigasetpro · maxwell basic firmware · CWE-640 | Kritik9,8 | — | %1,7 | 20 Ara 2018 |
39İzleyin | CVE-2017-2766İstismar yok | EMC Documentum eRoom version 7.4.4, EMC Documentum eRoom version 7.4.4 SP1, EMC Documentum eRoom version prior to 7.4.5 P04, EMC Documentum emc · documentum eroom · CWE-640 | Kritik9,8 | — | %1,6 | 3 Şub 2017 |
39İzleyin | CVE-2018-16988İstismar yok | An issue was discovered in Open XDMoD through 7.5.0.buffalo · open xdmod · CWE-640 | Kritik9,8 | — | %1,6 | 2 May 2019 |
39İzleyin | CVE-2021-28293İstismar yok | Seceon aiSIEM before 6.3.2 (build 585) is prone to an unauthenticated account takeover vulnerability in the Forgot Password feature.seceon · aisiem · CWE-640 | Kritik9,8 | — | %1,6 | 8 Haz 2021 |
- CVE-2023-702897Hemen
Weak Password Recovery Mechanism for Forgotten Password in GitLab
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %95gitlab · gitlab12 Oca 2024
- CVE-2019-1881868Bu hafta
strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/strapi-plugin-users-p
KritikCVSS 9,8SilahlaştırılmışEPSS %98strapi · strapi7 Kas 2019
- CVE-2017-761562Bu hafta
MantisBT through 2.3.0 allows arbitrary password reset and unauthenticated admin access via an empty confirm_hash value to verify.php.
YüksekCVSS 8,8SilahlaştırılmışEPSS %91mantisbt · mantisbt16 Nis 2017
- CVE-2019-1984455Planlayın
Django before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 allows account takeover.
KritikCVSS 9,8Kavram kanıtıEPSS %54djangoproject · django18 Ara 2019
- CVE-2025-621653Planlayın
Allegra calculateTokenExpDate Password Recovery Authentication Bypass Vulnerability
KritikCVSS 9,8Kavram kanıtıEPSS %48alltena · allegra20 Haz 2025
- CVE-2025-4764646Planlayın
WordPress PSW Front-end Login & Registration plugin <= 1.13 - Broken Authentication Vulnerability
KritikCVSS 9,8Kavram kanıtıEPSS %25gilblas ngunte possi · psw front-end login & registration23 May 2025
- CVE-2026-1963242Planlayın
TranslatePress – Multilingual <= 3.3.1 - Unauthenticated Account Takeover via Password Reset Link Disclosure
KritikCVSS 9,8Kavram kanıtıEPSS %9cozmoslabs · translatepress – translate multilingual sites with ai translation26 Ağu 2026
- CVE-2017-1709741Planlayın
gps-server.net GPS Tracking Software (self hosted) 2.x has a password reset procedure that immediately resets passwords upon an unauthentica
KritikCVSS 9,8Kavram kanıtıEPSS %7gps-server · gps tracking software2 Oca 2018
- CVE-2012-568640Planlayın
ZPanel 10.0.1 has insufficient entropy for its password reset process.
KritikCVSS 9,8Kavram kanıtıEPSS %5zpanelcp · zpanel4 Şub 2020
- CVE-2018-1948840Planlayın
The WP-jobhunt plugin before version 2.4 for WordPress does not control AJAX requests sent to the cs_reset_pass() function through the admin
KritikCVSS 9,8İstismar yokEPSS %4wp-jobhunt project · wp-jobhunt21 Mar 2019
- CVE-2018-781140Planlayın
An Unverified Password Change vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 whi
KritikCVSS 9,8İstismar yokEPSS %3schneider-electric · modicom m340 firmware30 Kas 2018
- CVE-2018-1242140Planlayın
LTB (aka LDAP Tool Box) Self Service Password before 1.3 allows a change to a user password (without knowing the old password) via a crafted
KritikCVSS 9,8İstismar yokEPSS %3ltb-project · ldap tool box self service password14 Haz 2018
- CVE-2018-780940Planlayın
An Unverified Password Change vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 whi
KritikCVSS 9,8İstismar yokEPSS %2schneider-electric · modicom m340 firmware30 Kas 2018
- CVE-2015-468940Planlayın
Ellucian (formerly SunGard) Banner Student 8.5.1.2 through 8.7 allows remote attackers to reset arbitrary passwords via unspecified vectors,
KritikCVSS 9,8İstismar yokEPSS %2ellucian · banner student11 Eyl 2017
- CVE-2019-1139340Planlayın
An issue was discovered in /admin/users/update in M/Monit before 3.7.3.
KritikCVSS 9,8İstismar yokEPSS %2tildeslash · monit22 Nis 2019
- CVE-2021-2276340Planlayın
A CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability exists in PowerLogic PM55xx, PowerLogic PM8ECC, PowerLogic
KritikCVSS 9,8İstismar yokEPSS %2schneider-electric · powerlogic pm5560 firmware11 Haz 2021
- CVE-2018-1729840Planlayın
An issue was discovered in Enalean Tuleap before 10.5.
KritikCVSS 9,8İstismar yokEPSS %2enalean · tuleap21 Eyl 2018
- CVE-2019-1592940Planlayın
In Craft CMS through 3.1.7, the elevated session password prompt was not being rate limited like normal login forms, leading to the possibil
KritikCVSS 9,8İstismar yokEPSS %2craftcms · craft cms24 Eki 2019
- CVE-2022-2385540Planlayın
An issue was discovered in Saviynt Enterprise Identity Cloud (EIC) 5.5 SP2.x.
KritikCVSS 9,8İstismar yokEPSS %2saviynt · enterprise identity cloud23 Oca 2022
- CVE-2024-887840Planlayın
Unauthenticated Password Reset
KritikCVSS 10,0İstismar yokEPSS %1riello-ups · netman 204 firmware24 Eyl 2024
- CVE-2025-6331440Planlayın
A static password reset token in the password reset function of DDSN Interactive Acora CMS v10.7.1 allows attackers to arbitrarily reset the
KritikCVSS 10,0Kavram kanıtıEPSS %0ddsn · cm3 acora cms12 Oca 2026
- CVE-2018-1887139İzleyin
Missing password verification in the web interface on Gigaset Maxwell Basic VoIP phones with firmware 2.22.7 would allow a remote attacker (
KritikCVSS 9,8İstismar yokEPSS %2gigasetpro · maxwell basic firmware20 Ara 2018
- CVE-2017-276639İzleyin
EMC Documentum eRoom version 7.4.4, EMC Documentum eRoom version 7.4.4 SP1, EMC Documentum eRoom version prior to 7.4.5 P04, EMC Documentum
KritikCVSS 9,8İstismar yokEPSS %2emc · documentum eroom3 Şub 2017
- CVE-2018-1698839İzleyin
An issue was discovered in Open XDMoD through 7.5.0.
KritikCVSS 9,8İstismar yokEPSS %2buffalo · open xdmod2 May 2019
- CVE-2021-2829339İzleyin
Seceon aiSIEM before 6.3.2 (build 585) is prone to an unauthenticated account takeover vulnerability in the Forgot Password feature.
KritikCVSS 9,8İstismar yokEPSS %2seceon · aisiem8 Haz 2021