CWE-640

High likelihood

Weak Password Recovery Mechanism for Forgotten Password

Parent: CWE-1390 - Weak Authentication

The product contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak.

258 vulnerabilities with CWE-640
CVE-2024-50356 NONE
Press - Info Disclosure
CVE-2024-48428 CRITICAL
Olivegroup Olivevle - Password Reset Weakness
CVSS 9.8
CVE-2024-9302 HIGH
Appcheap App Builder < 5.3.7 - Password Reset Weakness
CVSS 8.1
CVE-2024-9305 HIGH
Apppresser < 4.4.5 - Password Reset Weakness
CVSS 8.1
CVE-2024-9907 LOW
QileCMS <1.1.3 - Info Disclosure
CVSS 3.7
CVE-2024-45980 HIGH
MEANStore 1.0 - Host Header Injection
CVSS 8.8
CVE-2024-8878 CRITICAL
Riello-ups Netman 204 Firmware < 4.05 - Password Reset Weakness
CVSS 9.8
CVE-2024-8692 MEDIUM
TDuckCloud TDuckPro <6.3 - Weak Password Recovery
CVSS 5.3
CVE-2024-42915 HIGH
Staff Appraisal System v1.0 - Host Header Injection
CVSS 8.0
CVE-2024-6203 HIGH
HaloITSM <2.146.1 - Password Reset Poisoning
CVSS 8.3
CVE-2024-38287 CRITICAL
R-HUB TurboMeeting <8.x - Info Disclosure
CVSS 9.8
CVE-2024-6125 HIGH
WordPress Login with phone number <1.7.34 - Info Disclosure
CVSS 8.1
CVE-2024-38468 CRITICAL
Shenzhen Guoxin Synthesis <8.3.0 - Info Disclosure
CVSS 9.8
CVE-2024-36407 LOW
SuiteCRM <7.14.4-8.6.1 - Info Disclosure
CVSS 3.7
CVE-2024-5277 HIGH
Lunary < 1.4.9 - Password Reset Weakness
CVSS 7.5
CVE-2024-5404 CRITICAL
Moneo Appliance - Info Disclosure
CVSS 9.8
CVE-2024-33530 HIGH
Jitsi Meet <9391 - Info Disclosure
CVSS 7.5
CVE-2024-27899 HIGH
NetWeaver AS Java - Info Disclosure
CVSS 8.8
CVE-2024-2862 CRITICAL
LG LED Assistant - Unauthenticated Password Reset
CVSS 9.1
CVE-2024-2463 HIGH
CDeX <5.7.1 - Info Disclosure
CVSS 8.0
CVE-2024-24903 HIGH
Dell Policy Manager For Secure Connect Gateway < 5.22.00.16 - Password Reset Weakness
CVSS 8.0
CVE-2024-22454 HIGH
Dell PowerProtect Data Manager <19.15 - Privilege Escalation
CVSS 8.8
CVE-2024-0491 MEDIUM
Huaxia ERP <3.1 - Weak Password Recovery
CVSS 5.3
CVE-2024-0425 MEDIUM
Foru Cms < 2020-06-23 - Password Reset Weakness
CVSS 5.3
CVE-2024-0186 LOW
Huiran Host Reseller System < 2.0.0 - Password Reset Weakness
CVSS 3.7
Details
Vulnerabilities 258
Exploit Likelihood High