Skip to main content

CWE archive

CWE-640 CVEs

Programmatic archive

310 CVEs tagged with CWE-64095 Critical, 124 High, 74 Medium, 15 Low, 2 Unrated.

CVE-2023-4448

Published Aug 21, 2023

A vulnerability was found in OpenRapid RapidCMS 1.3.1 and classified as critical. This issue affects some unknown processing of the file admin/run-movepass.php. The manipulation o…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-35134

Published Jul 19, 2023

Weintek Weincloud v0.13.6 could allow an attacker to reset a password with the corresponding account’s JWT token only.

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2023-36487

Published Jun 29, 2023

The password reset function in ILIAS 7.0_beta1 through 7.20 and 8.0_beta1 through 8.1 allows remote attackers to take over the account.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-26615

Published Jun 28, 2023

D-Link DIR-823G firmware version 1.02B05 has a password reset vulnerability, which originates from the SetMultipleActions API, allowing unauthorized attackers to reset the WEB pag…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-42807

Published Jun 23, 2023

A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13. A user may accidentally add a participant to a Shared Album by pressing the De…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-3007

Published May 31, 2023

A vulnerability was found in ningzichun Student Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file resetPasswor…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-31459

Published May 24, 2023

A vulnerability in the Connect Mobility Router component of Mitel MiVoice Connect versions 9.6.2208.101 and earlier could allow an unauthenticated attacker with internal network a…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-31287

Published Apr 27, 2023

An issue was discovered in Serenity Serene (and StartSharp) before 6.7.0. Password reset links are sent by email. A link contains a token that is used to reset the password. This…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-36436

Published Apr 20, 2023

An issue in Mobicint Backend for Credit Unions v3 allows attackers to retrieve partial email addresses and user entered information via submission to the forgotten-password endpoi…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-45637

Published Mar 21, 2023

An insecure password reset issue discovered in MEGAFEIS, BOFEI DBD+ Application for IOS & Android v1.4.4 service via insecure expiry mechanism.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-10071

Published Jan 19, 2023

A vulnerability was found in gitter-badger ezpublish-modern-legacy. It has been rated as problematic. This issue affects some unknown processing of the file kernel/user/forgotpass…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2020-12067

Published Dec 26, 2022

In Pilz PMC programming tool 3.x before 3.5.17 (based on CODESYS Development System), a user's password may be changed by an attacker without knowledge of the current password.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-44004

Published Nov 16, 2022

An issue was discovered in BACKCLICK Professional 5.9.63. Due to insecure design or lack of authentication, unauthenticated attackers can complete the password-reset process for a…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-37300

Published Sep 12, 2022

A CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability exists that could cause unauthorized access in read and write mode to the controller when communic…

CVSS 9.8 · Critical

CVE-2022-34530

Published Aug 1, 2022

An issue in the login and reset password functionality of Backdrop CMS v1.22.0 allows attackers to enumerate usernames via password reset requests and distinct responses returned…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-23172

Published Jul 6, 2022

An attacker can access to "Forgot my password" button, as soon as he puts users is valid in the system, the system would issue a message that a password reset email had been sent…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 176-200 of 310 CVEsPage 8 of 13