CWE-620

Unverified Password Change

Parent: CWE-1390 - Weak Authentication

When setting a new password for a user, the product does not require knowledge of the original password, or using another form of authentication.

78 vulnerabilities with CWE-620
CVE-2025-4322 CRITICAL
Motors WordPress <5.6.67 - Privilege Escalation
CVSS 9.8
CVE-2025-4903 MEDIUM
Dlink Di-7003g Firmware - Password Reset Weakness
CVSS 5.3
CVE-2025-46748 LOW
Product - Privilege Escalation
CVSS 2.7
CVE-2025-4558 CRITICAL
GPM - WormHole Tech - Auth Bypass
CVSS 9.8
CVE-2025-4552 MEDIUM
Continew Admin < 3.6.0 - Password Reset Weakness
CVSS 5.4
CVE-2025-2253 CRITICAL
IMITHEMES Listing <3.3 - Privilege Escalation
CVSS 9.8
CVE-2025-3793 MEDIUM
Buddypress Force Password Change <0.1 - Privilege Escalation
CVSS 4.2
CVE-2025-3607 HIGH
Frontend Login & Registration Blocks <1.0.7 - Privilege Escalation
CVSS 8.8
CVE-2025-3603 CRITICAL
Flynax Bridge < 2.2.0 - Privilege Escalation
CVSS 9.8
CVE-2025-3849 MEDIUM
Yxj2018 Springboot-vue-onlineexam - Password Reset Weakness
CVSS 4.3
CVE-2025-1107 CRITICAL
Janto <r12 - Info Disclosure
CVSS 9.9
CVE-2024-12827 CRITICAL
DWT - Directory & Listing WordPress Theme <3.3.6 - Privilege Escala...
CVSS 9.8
CVE-2024-47784 LOW
ANC software <1.1.4 - Auth Bypass
CVSS 2.6
CVE-2024-48887 CRITICAL
Fortinet FortiSwitch GUI - RCE
CVSS 9.8
CVE-2024-41796 MEDIUM
Siemens 7kt Pac1260 Data Manager Firmware - CSRF
CVSS 6.5
CVE-2024-9431 HIGH
transformeroptimus/superagi <0.0.14 - Privilege Escalation
CVSS 8.8
CVE-2024-13373 HIGH
Exertio Framework <1.3.1 - Privilege Escalation
CVSS 8.1
CVE-2024-12824 CRITICAL
Nokri - Job Board WordPress Theme <1.6.2 - Privilege Escalation
CVSS 9.8
CVE-2024-12860 CRITICAL
Carspot < 2.4.4 - Privilege Escalation
CVSS 9.8
CVE-2024-45647 MEDIUM
IBM Security Verify Access <10.0.9 - Privilege Escalation
CVSS 5.6
CVE-2024-13375 CRITICAL
Adifier System <3.1.7 - Privilege Escalation
CVSS 9.8
CVE-2024-28143 HIGH
- - CSRF
CVSS 8.4
CVE-2024-51493 MEDIUM
Octoprint < 1.10.3 - Missing Authentication
CVSS 5.3
CVE-2024-33699 CRITICAL
LevelOne WBR-6012 - Privilege Escalation
CVSS 9.9
CVE-2024-8794 MEDIUM
BA Book Everything <1.6.20 - Info Disclosure
CVSS 5.3
Details
Vulnerabilities 78