CWE-640

High likelihood

Weak Password Recovery Mechanism for Forgotten Password

Parent: CWE-1390 - Weak Authentication

The product contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak.

258 vulnerabilities with CWE-640
CVE-2022-22691 MEDIUM
Umbraco Cms < 9.2.0 - HTTP Request Smuggling
CVSS 6.8
CVE-2021-29038 MEDIUM
Liferay Digital Experience Platform < 7.2 - Password Reset Weakness
CVSS 6.3
CVE-2021-36436 MEDIUM
Mobicint Backend for Credit Unions <3 - Info Disclosure
CVSS 5.3
CVE-2021-43498 HIGH
ATutor 2.2.4 - Info Disclosure
CVSS 7.5
CVE-2021-27654 HIGH
Local Accounts - Auth Bypass
CVSS 7.8
CVE-2021-44839 MEDIUM
Deltarm Delta RM - Password Reset Weakness
CVSS 6.5
CVE-2021-39919 MEDIUM
Gitlab < 14.3.6 - Password Reset Weakness
CVSS 4.4
CVE-2021-44037 HIGH
Teampasswordmanager Team Password Manager - Password Reset Weakness
CVSS 7.5
CVE-2021-39899 LOW
Gitlab < 14.1.7 - Password Reset Weakness
CVSS 2.9
CVE-2021-25961 HIGH
Salesagility Suitecrm < 7.10.32 - Password Reset Weakness
CVSS 8.0
CVE-2021-36095 MEDIUM
OTRS <6.0.1, >7.0.28 - Info Disclosure
CVSS 5.3
CVE-2021-25957 HIGH
Dolibarr < 13.0.2 - Password Reset Weakness
CVSS 8.8
CVE-2021-37693 MEDIUM
Discourse < 2.7.8 - Insufficient Session Expiration
CVSS 5.3
CVE-2021-37541 MEDIUM
Jetbrains Hub < 2021.1.13402 - Injection
CVSS 6.1
CVE-2021-36708 HIGH
Prolink Prc2402m Firmware < 1.0.18 - Password Reset Weakness
CVSS 7.5
CVE-2021-36209 CRITICAL
JetBrains Hub <2021.1.13389 - Privilege Escalation
CVSS 9.8
CVE-2021-36804 MEDIUM
Akaunting < 2.1.13 - Password Reset Weakness
CVSS 5.4
CVE-2021-33321 HIGH
Liferay Portal <7.3 - Info Disclosure
CVSS 7.5
CVE-2021-22763 CRITICAL
PowerLogic - Privilege Escalation
CVSS 9.8
CVE-2021-28293 CRITICAL
Seceon aiSIEM <6.3.2 - Privilege Escalation
CVSS 9.8
CVE-2021-22731 CRITICAL
Modicon Managed Switch <V8.21 - Info Disclosure
CVSS 9.8
CVE-2021-31912 HIGH
Jetbrains Teamcity < 2020.2.3 - Password Reset Weakness
CVSS 8.8
CVE-2021-28128 HIGH
Strapi <3.6.0 - Privilege Escalation
CVSS 8.1
CVE-2021-29080 HIGH
Netgear Rbk852 Firmware < 3.2.10.11 - Password Reset Weakness
CVSS 8.1
CVE-2021-25323 CRITICAL
MISP 2.4.136 - Info Disclosure
CVSS 9.1
Details
Vulnerabilities 258
Exploit Likelihood High