CWE-640
High likelihoodWeak Password Recovery Mechanism for Forgotten Password
Parent: CWE-1390 - Weak Authentication
The product contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak.
258 vulnerabilities with CWE-640
CVE-2023-53958
HIGH
LDAP Tool Box Self Service Password 1.5.2 - SSRF
CVSS 7.5
CVE-2023-7264
HIGH
Buildapp Build App Online < 1.0.21 - Password Reset Weakness
CVSS 8.1
CVE-2023-35717
HIGH
Tp-link Tapo C210 Firmware - Password Reset Weakness
CVSS 8.8
CVE-2023-7028
CRITICAL
KEV
GitLab Password Reset Account Takeover
CVSS 10.0
CVE-2023-50172
MEDIUM
Wwbn Avideo - Password Reset Weakness
CVSS 5.3
CVE-2023-49589
HIGH
Wwbn Avideo - Password Reset Weakness
CVSS 8.8
CVE-2023-42481
HIGH
SAP Commerce Cloud - Password Reset Weakness
CVSS 8.1
CVE-2023-49097
HIGH
ZITADEL - Open Redirect
CVSS 8.1
CVE-2023-4214
HIGH
AppPresser <4.2.5 - Info Disclosure
CVSS 8.1
CVE-2023-5959
MEDIUM
Byzoro Smart S85f Firmware - Password Reset Weakness
CVSS 4.3
CVE-2023-47107
HIGH
THM Pilos < 2.3.0 - Password Reset Weakness
CVSS 8.8
CVE-2023-46138
LOW
JumpServer <3.8.0 - Info Disclosure
CVSS 3.7
CVE-2023-5840
HIGH
Linkstack < 4.2.9 - Password Reset Weakness
CVSS 8.8
CVE-2023-44399
MEDIUM
Zitadel < 2.37.2 - Password Reset Weakness
CVSS 5.3
CVE-2023-5296
MEDIUM
Rockoa - Password Reset Weakness
CVSS 4.3
CVE-2023-43650
HIGH
JumpServer - Info Disclosure
CVSS 8.2
CVE-2023-4096
HIGH
Fujitsu Arconte Áurea 1.5.0.0 - Auth Bypass
CVSS 8.6
CVE-2023-34357
HIGH
Scshr HR Portal - Password Reset Weakness
CVSS 7.8
CVE-2023-3222
HIGH
Password Recovery - Password Reset Weakness
CVSS 7.5
CVE-2023-4448
MEDIUM
Openrapid Rapidcms - Password Reset Weakness
CVSS 6.3
CVE-2023-35134
HIGH
Weintek Weincloud - Password Reset Weakness
CVSS 7.4
CVE-2023-29145
HIGH
Malwarebytes EDR <1.0.11 - RCE
CVSS 7.8
CVE-2023-36487
CRITICAL
ILIAS <8.1 - RCE
CVSS 9.8
CVE-2023-26615
HIGH
D-Link DIR-823G <1.02B05 - Privilege Escalation
CVSS 7.5
CVE-2023-28202
MEDIUM
Apple Ipados < 16.5 - Password Reset Weakness
CVSS 5.5
Details
Vulnerabilities
258
Exploit Likelihood
High