CWE-620
95 CVEs • Abstraction: Base
Unverified Password Change
When setting a new password for a user, the product does not require knowledge of the original password, or using another form of authentication.
CVEs (95)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The WP User Control plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and including 1.5.3. This is due to the plugin using native password reset functionality, with insufficient valida...Show more |
Unverified Password Change in GitHub repository instantsoft/icms2 prior to 2.16.1-git. |
Unverified Password Change in GitHub repository tsolucio/corebos prior to 8. |
The Profile Builder – User Profile & User Registration Forms plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and including 3.9.0. This is due to the plugin using native password res...Show more |
1Medtronic 2Interstim X Clinician Micro ClinicianJun 17, 2026 Mar 1, 2023 N/A· v4 6.8 MEDIUM· v3 N/A· v2 Medtronic identified that the Pelvic Health clinician apps, which are installed on the Smart Programmer mobile device, have a password vulnerability that requires a security update to fix. Not updating could potentially...Show more |
Unverified Password Change in GitHub repository phpfusion/phpfusion prior to 9.10.20. |
Unverified Password Change in GitHub repository octoprint/octoprint prior to 1.8.3. |
1Johnsoncontrols 3Metasys Application And Data Server Metasys Extended Application And Data ServerMetasys Open Application ServerJun 17, 2026 Jun 15, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability in Metasys ADS/ADX/OAS 10 versions prior to 10.1.5 and Metasys ADS/ADX/OAS 11 versions prior to 11.0.2 allows unverified password change. |
1Johnsoncontrols 3Metasys Application And Data Server Metasys Extended Application And Data ServerMetasys Open Application ServerJun 17, 2026 May 6, 2022 N/A· v4 8.8 HIGH· v3 6.0 MEDIUM· v2 Under certain circumstances an authenticated user could lock other users out of the system or take over their accounts in Metasys ADS/ADX/OAS server 10 versions prior to 10.1.5 and Metasys ADS/ADX/OAS server 11 versions...Show more |
1Cisco 1Broadworks Commpilot Application Software Jun 17, 2026 Sep 9, 2021 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 Multiple vulnerabilities in Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacker to delete arbitrary user accounts or gain elevated privileges on an affected system. |
1Cisco 1Broadworks Commpilot Application Software Jun 17, 2026 Sep 9, 2021 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Multiple vulnerabilities in Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacker to delete arbitrary user accounts or gain elevated privileges on an affected system. |
1Schneider Electric 6Evlink City Evc1s22p4 Firmware Evlink City Evc1s7p4 FirmwareEvlink Parking Ev.2 Firmware+3 moreJun 17, 2026 Jul 21, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A CWE-620: Unverified Password Change vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (EVW2 / EVF2 / EV.2 all versions prior to R8 V3.4.0.1), and EVlink Smart...Show more |
CRIXP OpenCRX version 4.30 and 5.0-20200717 and prior suffers from an unverified password change vulnerability. An attacker who is able to connect to the affected OpenCRX instance can change the password of any user, inc...Show more |
Unverified password change vulnerability in Change Password in Synology DiskStation Manager (DSM) before 6.2-23739 allows remote authenticated users to reset password without verification. |
1Prominent 1Multiflex M10a Controller Firmware May 13, 2026 Oct 17, 2017 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 An Unverified Password Change issue was discovered in ProMinent MultiFLEX M10a Controller web interface. When setting a new password for a user, the application does not require the user to know the original password. An...Show more |