Skip to main content

CWE archive

CWE-640 CVEs

Programmatic archive

291 CVEs tagged with CWE-64088 Critical, 116 High, 72 Medium, 14 Low, 1 Unrated.

CVE-2009-5025

Published Jan 15, 2020

A backdoor (aka BMSA-2009-07) was found in PyForum v1.0.3 where an attacker who knows a valid user email could force a password reset on behalf of that user.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-17392

Published Nov 26, 2019

Progress Sitefinity 12.1 has a Weak Password Recovery Mechanism for a Forgotten Password because the HTTP Host header is mishandled.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-18818

Published Nov 7, 2019

strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/strapi-plugin-users-permissions/controllers/Auth.js.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-15929

Published Oct 24, 2019

In Craft CMS through 3.1.7, the elevated session password prompt was not being rate limited like normal login forms, leading to the possibility of a brute force attempt on them.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-15749

Published Oct 7, 2019

SITOS six Build v6.2.1 allows a user to change their password and recovery email address without requiring them to confirm the change with their old password. This would allow an…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-14955

Published Oct 1, 2019

In JetBrains Hub versions earlier than 2018.4.11436, there was no option to force a user to change the password and no password expiration policy was implemented.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-12943

Published Sep 10, 2019

TTLock devices do not properly restrict password-reset attempts, leading to incorrect access control and disclosure of sensitive information about valid account names.

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2019-13240

Published Jul 10, 2019

An issue was discovered in GLPI before 9.4.1. After a successful password reset by a user, it is possible to change that user's password again during the next 24 hours without any…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-10270

Published Jun 21, 2019

An arbitrary password reset issue was discovered in the Ultimate Member plugin 2.39 for WordPress. It is possible (due to lack of verification and correlation between the reset pa…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-16988

Published May 2, 2019

An issue was discovered in Open XDMoD through 7.5.0. An authentication bypass (account takeover) exists due to a weak password reset mechanism. A brute-force attack against an MD5…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-11393

Published Apr 22, 2019

An issue was discovered in /admin/users/update in M/Monit before 3.7.3. It allows unprivileged users to escalate their privileges to an administrator by requesting a password chan…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-10641

Published Apr 17, 2019

Contao before 3.5.39 and 4.x before 4.7.3 has a Weak Password Recovery Mechanism for a Forgotten Password.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-16529

Published Mar 28, 2019

A password reset vulnerability has been discovered in Forcepoint Email Security 8.5.x. The password reset URL can be used after the intended expiration period or after the URL has…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-19488

Published Mar 21, 2019

The WP-jobhunt plugin before version 2.4 for WordPress does not control AJAX requests sent to the cs_reset_pass() function through the admin-ajax.php file, which allows remote una…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-0696

Published Feb 13, 2019

OpenAM (Open Source Edition) 13.0 and later does not properly manage sessions, which allows remote authenticated attackers to change the security questions and reset the login pas…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1000812

Published Dec 20, 2018

Artica Integria IMS version 5.0 MR56 Package 58, likely earlier versions contains a CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability in Password reco…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2018-7811

Published Nov 30, 2018

An Unverified Password Change vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 which could allow an unauthenticated remot…

CVSS 9.8 · Critical

CVE-2018-7809

Published Nov 30, 2018

An Unverified Password Change vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 which could allow an unauthenticated remot…

CVSS 9.8 · Critical
Showing 226-250 of 291 CVEsPage 10 of 12