CWE-640
High likelihoodWeak Password Recovery Mechanism for Forgotten Password
Parent: CWE-1390 - Weak Authentication
The product contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak.
258 vulnerabilities with CWE-640
CVE-2022-22691
MEDIUM
Umbraco Cms < 9.2.0 - HTTP Request Smuggling
CVSS 6.8
CVE-2021-29038
MEDIUM
Liferay Digital Experience Platform < 7.2 - Password Reset Weakness
CVSS 6.3
CVE-2021-36436
MEDIUM
Mobicint Backend for Credit Unions <3 - Info Disclosure
CVSS 5.3
CVE-2021-43498
HIGH
ATutor 2.2.4 - Info Disclosure
CVSS 7.5
CVE-2021-27654
HIGH
Local Accounts - Auth Bypass
CVSS 7.8
CVE-2021-44839
MEDIUM
Deltarm Delta RM - Password Reset Weakness
CVSS 6.5
CVE-2021-39919
MEDIUM
Gitlab < 14.3.6 - Password Reset Weakness
CVSS 4.4
CVE-2021-44037
HIGH
Teampasswordmanager Team Password Manager - Password Reset Weakness
CVSS 7.5
CVE-2021-39899
LOW
Gitlab < 14.1.7 - Password Reset Weakness
CVSS 2.9
CVE-2021-25961
HIGH
Salesagility Suitecrm < 7.10.32 - Password Reset Weakness
CVSS 8.0
CVE-2021-36095
MEDIUM
OTRS <6.0.1, >7.0.28 - Info Disclosure
CVSS 5.3
CVE-2021-25957
HIGH
Dolibarr < 13.0.2 - Password Reset Weakness
CVSS 8.8
CVE-2021-37693
MEDIUM
Discourse < 2.7.8 - Insufficient Session Expiration
CVSS 5.3
CVE-2021-37541
MEDIUM
Jetbrains Hub < 2021.1.13402 - Injection
CVSS 6.1
CVE-2021-36708
HIGH
Prolink Prc2402m Firmware < 1.0.18 - Password Reset Weakness
CVSS 7.5
CVE-2021-36209
CRITICAL
JetBrains Hub <2021.1.13389 - Privilege Escalation
CVSS 9.8
CVE-2021-36804
MEDIUM
Akaunting < 2.1.13 - Password Reset Weakness
CVSS 5.4
CVE-2021-33321
HIGH
Liferay Portal <7.3 - Info Disclosure
CVSS 7.5
CVE-2021-22763
CRITICAL
PowerLogic - Privilege Escalation
CVSS 9.8
CVE-2021-28293
CRITICAL
Seceon aiSIEM <6.3.2 - Privilege Escalation
CVSS 9.8
CVE-2021-22731
CRITICAL
Modicon Managed Switch <V8.21 - Info Disclosure
CVSS 9.8
CVE-2021-31912
HIGH
Jetbrains Teamcity < 2020.2.3 - Password Reset Weakness
CVSS 8.8
CVE-2021-28128
HIGH
Strapi <3.6.0 - Privilege Escalation
CVSS 8.1
CVE-2021-29080
HIGH
Netgear Rbk852 Firmware < 3.2.10.11 - Password Reset Weakness
CVSS 8.1
CVE-2021-25323
CRITICAL
MISP 2.4.136 - Info Disclosure
CVSS 9.1
Details
Vulnerabilities
258
Exploit Likelihood
High