CWE-640
317 CVEs • Abstraction: Base • Likelihood of Exploit: High
Weak Password Recovery Mechanism for Forgotten Password
The product contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak.
CVEs (317)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Soar Cloud Ltd. HR Portal has a weak Password Recovery Mechanism for Forgotten Password. The reset password link sent out through e-mail, and the link will remain valid after the password has been reset and after the ex...Show more |
1Password Recovery Project 1Password Recovery Jun 17, 2026 Sep 4, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Vulnerability in the password recovery mechanism of Password Recovery plugin for Roundcube, in its 1.2 version, which could allow a remote attacker to change an existing user´s password by adding a 6-digit numeric token....Show more |
A vulnerability was found in OpenRapid RapidCMS 1.3.1 and classified as critical. This issue affects some unknown processing of the file admin/run-movepass.php. The manipulation of the argument password/password2 leads t...Show more |
Weintek Weincloud v0.13.6
could allow an attacker to reset a password with the corresponding account’s JWT token only.
|
1Malwarebytes 2Endpoint Detection And Response MalwarebytesJun 17, 2026 Jun 30, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 The Malwarebytes EDR 1.0.11 for Linux driver doesn't properly ensure whitelisting of executable libraries loaded by executable files, allowing arbitrary code execution. The attacker can set LD_LIBRARY_PATH, set LD_PRELOA...Show more |
The password reset function in ILIAS 7.0_beta1 through 7.20 and 8.0_beta1 through 8.1 allows remote attackers to take over the account. |
D-Link DIR-823G firmware version 1.02B05 has a password reset vulnerability, which originates from the SetMultipleActions API, allowing unauthorized attackers to reset the WEB page management password. |
1Apple 5Ipados Iphone OsMacos+2 moreJun 17, 2026 Jun 23, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 This issue was addressed with improved state management. This issue is fixed in iOS 16.5 and iPadOS 16.5, watchOS 9.5, tvOS 16.5, macOS Ventura 13.4. An app firewall setting may not take effect after exiting the Settings...Show more |
A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13. A user may accidentally add a participant to a Shared Album by pressing the Delete key |
1Kabir M Alhasan 1Student Management System Jun 17, 2026 May 31, 2023 N/A· v4 9.8 CRITICAL· v3 6.4 MEDIUM· v2 A vulnerability was found in ningzichun Student Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file resetPassword.php of the component Password Reset Han...Show more |
A vulnerability in the Connect Mobility Router component of Mitel MiVoice Connect versions 9.6.2208.101 and earlier could allow an unauthenticated attacker with internal network access to authenticate with administrative...Show more |
Concrete CMS (previously concrete5) before 9.1 did not have a rate limit for password resets. |
1Milesight 21Ms N1004 Uc Firmware Ms N1004 Upc FirmwareMs N1008 Uc Firmware+18 moreJun 17, 2026 Apr 28, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 This vulnerability exists in Milesight 4K/H.265 Series NVR models (MS-Nxxxx-xxG, MS-Nxxxx-xxE, MS-Nxxxx-xxT, MS-Nxxxx-xxH and MS-Nxxxx-xxC), due to a weak password reset mechanism at the Milesight NVR web-based managemen...Show more |
An issue was discovered in Serenity Serene (and StartSharp) before 6.7.0. Password reset links are sent by email. A link contains a token that is used to reset the password. This token remains valid even after the passwo...Show more |
An issue in Mobicint Backend for Credit Unions v3 allows attackers to retrieve partial email addresses and user entered information via submission to the forgotten-password endpoint. |
An insecure password reset issue discovered in MEGAFEIS, BOFEI DBD+ Application for IOS & Android v1.4.4 service via insecure expiry mechanism. |
1Comfast Project 1Cf Wr623n Firmware Jun 17, 2026 Jan 31, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 COMFAST (Shenzhen Sihai Zhonglian Network Technology Co., Ltd) CF-WR623N Router firmware V2.3.0.1 and before is vulnerable to Account takeover. Anyone can reset the password of the admin accounts. |
AMI Megarac Password reset interception via API |
1Gitter 1Ez Publish Modern Legacy Nov 21, 2024 Jan 19, 2023 N/A· v4 7.5 HIGH· v3 1.4 LOW· v2 A vulnerability was found in gitter-badger ezpublish-modern-legacy. It has been rated as problematic. This issue affects some unknown processing of the file kernel/user/forgotpassword.php. The manipulation leads to weak...Show more |
1Rocketsoftware 1Trufusion Enterprise Jun 17, 2026 Jan 12, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 The Forgotten Password functionality of Rocket TRUfusion Portal v7.9.2.1 allows remote attackers to bypass authentication and access restricted pages by validating the user's session token when the "Password forgotten?"...Show more |