Skip to main content

CWE archive

CWE-640 CVEs

Programmatic archive

291 CVEs tagged with CWE-64088 Critical, 116 High, 72 Medium, 14 Low, 1 Unrated.

CVE-2023-44399

Published Oct 10, 2023

ZITADEL provides identity infrastructure. In versions 2.37.2 and prior, ZITADEL administrators can enable a setting called "Ignoring unknown usernames" which helps mitigate attack…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-5296

Published Sep 29, 2023

A vulnerability was found in Xinhu RockOA 1.1/2.3.2/15.X3amdi and classified as problematic. Affected by this issue is some unknown functionality of the file api.php?m=reimplat&a=…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-43650

Published Sep 27, 2023

JumpServer is an open source bastion host. The verification code for resetting user's password is vulnerable to brute-force attacks due to the absence of rate limiting. JumpServer…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-4096

Published Sep 19, 2023

Weak password recovery mechanism vulnerability in Fujitsu Arconte Áurea version 1.5.0.0, which exploitation could allow an attacker to perform a brute force attack on the emailed…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2023-34357

Published Sep 7, 2023

Soar Cloud Ltd. HR Portal has a weak Password Recovery Mechanism for Forgotten Password. The reset password link sent out through e-mail, and the link will remain valid after the…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-4448

Published Aug 21, 2023

A vulnerability was found in OpenRapid RapidCMS 1.3.1 and classified as critical. This issue affects some unknown processing of the file admin/run-movepass.php. The manipulation o…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-35134

Published Jul 19, 2023

Weintek Weincloud v0.13.6 could allow an attacker to reset a password with the corresponding account’s JWT token only.

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2023-36487

Published Jun 29, 2023

The password reset function in ILIAS 7.0_beta1 through 7.20 and 8.0_beta1 through 8.1 allows remote attackers to take over the account.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-26615

Published Jun 28, 2023

D-Link DIR-823G firmware version 1.02B05 has a password reset vulnerability, which originates from the SetMultipleActions API, allowing unauthorized attackers to reset the WEB pag…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-42807

Published Jun 23, 2023

A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13. A user may accidentally add a participant to a Shared Album by pressing the De…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-3007

Published May 31, 2023

A vulnerability was found in ningzichun Student Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file resetPasswor…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-31459

Published May 24, 2023

A vulnerability in the Connect Mobility Router component of Mitel MiVoice Connect versions 9.6.2208.101 and earlier could allow an unauthenticated attacker with internal network a…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-31287

Published Apr 27, 2023

An issue was discovered in Serenity Serene (and StartSharp) before 6.7.0. Password reset links are sent by email. A link contains a token that is used to reset the password. This…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-36436

Published Apr 20, 2023

An issue in Mobicint Backend for Credit Unions v3 allows attackers to retrieve partial email addresses and user entered information via submission to the forgotten-password endpoi…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-45637

Published Mar 21, 2023

An insecure password reset issue discovered in MEGAFEIS, BOFEI DBD+ Application for IOS & Android v1.4.4 service via insecure expiry mechanism.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-10071

Published Jan 19, 2023

A vulnerability was found in gitter-badger ezpublish-modern-legacy. It has been rated as problematic. This issue affects some unknown processing of the file kernel/user/forgotpass…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2020-12067

Published Dec 26, 2022

In Pilz PMC programming tool 3.x before 3.5.17 (based on CODESYS Development System), a user's password may be changed by an attacker without knowledge of the current password.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 151-175 of 291 CVEsPage 7 of 12