CWE-640

High likelihood

Weak Password Recovery Mechanism for Forgotten Password

Parent: CWE-1390 - Weak Authentication

The product contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak.

258 vulnerabilities with CWE-640
CVE-2023-53958 HIGH
LDAP Tool Box Self Service Password 1.5.2 - SSRF
CVSS 7.5
CVE-2023-7264 HIGH
Buildapp Build App Online < 1.0.21 - Password Reset Weakness
CVSS 8.1
CVE-2023-35717 HIGH
Tp-link Tapo C210 Firmware - Password Reset Weakness
CVSS 8.8
CVE-2023-7028 CRITICAL KEV
GitLab Password Reset Account Takeover
CVSS 10.0
CVE-2023-50172 MEDIUM
Wwbn Avideo - Password Reset Weakness
CVSS 5.3
CVE-2023-49589 HIGH
Wwbn Avideo - Password Reset Weakness
CVSS 8.8
CVE-2023-42481 HIGH
SAP Commerce Cloud - Password Reset Weakness
CVSS 8.1
CVE-2023-49097 HIGH
ZITADEL - Open Redirect
CVSS 8.1
CVE-2023-4214 HIGH
AppPresser <4.2.5 - Info Disclosure
CVSS 8.1
CVE-2023-5959 MEDIUM
Byzoro Smart S85f Firmware - Password Reset Weakness
CVSS 4.3
CVE-2023-47107 HIGH
THM Pilos < 2.3.0 - Password Reset Weakness
CVSS 8.8
CVE-2023-46138 LOW
JumpServer <3.8.0 - Info Disclosure
CVSS 3.7
CVE-2023-5840 HIGH
Linkstack < 4.2.9 - Password Reset Weakness
CVSS 8.8
CVE-2023-44399 MEDIUM
Zitadel < 2.37.2 - Password Reset Weakness
CVSS 5.3
CVE-2023-5296 MEDIUM
Rockoa - Password Reset Weakness
CVSS 4.3
CVE-2023-43650 HIGH
JumpServer - Info Disclosure
CVSS 8.2
CVE-2023-4096 HIGH
Fujitsu Arconte Áurea 1.5.0.0 - Auth Bypass
CVSS 8.6
CVE-2023-34357 HIGH
Scshr HR Portal - Password Reset Weakness
CVSS 7.8
CVE-2023-3222 HIGH
Password Recovery - Password Reset Weakness
CVSS 7.5
CVE-2023-4448 MEDIUM
Openrapid Rapidcms - Password Reset Weakness
CVSS 6.3
CVE-2023-35134 HIGH
Weintek Weincloud - Password Reset Weakness
CVSS 7.4
CVE-2023-29145 HIGH
Malwarebytes EDR <1.0.11 - RCE
CVSS 7.8
CVE-2023-36487 CRITICAL
ILIAS <8.1 - RCE
CVSS 9.8
CVE-2023-26615 HIGH
D-Link DIR-823G <1.02B05 - Privilege Escalation
CVSS 7.5
CVE-2023-28202 MEDIUM
Apple Ipados < 16.5 - Password Reset Weakness
CVSS 5.5
Details
Vulnerabilities 258
Exploit Likelihood High