Skip to main content

CWE archive

CWE-640 CVEs

Programmatic archive

310 CVEs tagged with CWE-64095 Critical, 124 High, 74 Medium, 15 Low, 2 Unrated.

CVE-2022-29174

Published May 17, 2022

countly-server is the server-side part of Countly, a product analytics solution. Prior to versions 22.03.7 and 21.11.4, a malicious actor who knows an account email address/userna…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2022-29933

Published May 9, 2022

Craft CMS through 3.7.36 allows a remote unauthenticated attacker, who knows at least one valid username, to reset the account's password and take over the account by providing a…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-24892

Published Apr 28, 2022

Shopware is an open source e-commerce software platform. Starting with version 5.0.4 and before version 5.7.9, multiple tokens for password reset can be requested. All tokens can…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-27157

Published Apr 15, 2022

pearweb < 1.32 is suffers from a Weak Password Recovery Mechanism via include/users/passwordmanage.php.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-43498

Published Apr 8, 2022

An Access Control vulnerability exists in ATutor 2.2.4 in password_reminder.php when the g, id, h, form_password_hidden, and form_change HTTP POST parameters are set.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-0777

Published Mar 1, 2022

Weak Password Recovery Mechanism for Forgotten Password in GitHub repository microweber/microweber prior to 1.3.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-23619

Published Feb 9, 2022

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions it's possible to guess if a user has an account on th…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-27654

Published Jan 28, 2022

Forgotten password reset functionality for local accounts can be used to bypass local authentication checks.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-23855

Published Jan 24, 2022

An issue was discovered in Saviynt Enterprise Identity Cloud (EIC) 5.5 SP2.x. An authentication bypass in ECM/maintenance/forgotpasswordstep1 allows an unauthenticated user to res…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-44839

Published Jan 18, 2022

An issue was discovered in Delta RM 1.2. It is possible to request a new password for any other account using the account ID. Using the /listes/DTsendmaildata/adm_utilisateur/send…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-22691

Published Jan 18, 2022

The password reset component deployed within Umbraco uses the hostname supplied within the request host header when building a password reset URL. It may be possible to manipulate…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-39919

Published Dec 13, 2021

In all versions of GitLab CE/EE starting version 14.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, the reset passwo…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-39899

Published Oct 4, 2021

In all versions of GitLab CE/EE, an attacker with physical access to a user’s machine may brute force the user’s password via the change password function. There is a rate limit i…

CVSS 2.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2021-25961

Published Sep 29, 2021

In “SuiteCRM” application, v7.1.7 through v7.10.31 and v7.11-beta through v7.11.20 fail to properly invalidate password reset links that is associated with a deleted user id, whic…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2021-36095

Published Sep 6, 2021

Malicious attacker is able to find out valid user logins by using the "lost password" feature. This issue affects: OTRS AG ((OTRS)) Community Edition version 6.0.1 and later versi…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-25957

Published Aug 17, 2021

In “Dolibarr” application, v2.8.1 to v13.0.2 are vulnerable to account takeover via password reset functionality. A low privileged attacker can reset the password of any user in t…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-37693

Published Aug 13, 2021

Discourse is an open-source platform for community discussion. In Discourse before versions 2.7.8 and 2.8.0.beta4, when adding additional email addresses to an existing account on…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-37541

Published Aug 6, 2021

In JetBrains Hub before 2021.1.13402, HTML injection in the password reset email was possible.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-36209

Published Aug 6, 2021

In JetBrains Hub before 2021.1.13389, account takeover was possible during password reset.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-36804

Published Aug 4, 2021

Akaunting version 2.1.12 and earlier suffers from a password reset spoofing vulnerability, wherein an attacker can proxy password reset requests through a running Akaunting instan…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-33321

Published Aug 3, 2021

Insecure default configuration in Liferay Portal 6.2.3 through 7.3.2, and Liferay DXP before 7.3, allows remote attackers to enumerate user email address via the forgot password f…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 201-225 of 310 CVEsPage 9 of 13