Vulnerabilities > Weak Password Recovery Mechanism for Forgotten Password

DATE CVE VULNERABILITY TITLE RISK
2023-04-28 CVE-2023-30466 Weak Password Recovery Mechanism for Forgotten Password vulnerability in Milesight products
This vulnerability exists in Milesight 4K/H.265 Series NVR models (MS-Nxxxx-xxG, MS-Nxxxx-xxE, MS-Nxxxx-xxT, MS-Nxxxx-xxH and MS-Nxxxx-xxC), due to a weak password reset mechanism at the Milesight NVR web-based management interface.
network
low complexity
milesight CWE-640
critical
9.8
2023-04-27 CVE-2023-31287 Weak Password Recovery Mechanism for Forgotten Password vulnerability in Serenity Serene and Startsharp
An issue was discovered in Serenity Serene (and StartSharp) before 6.7.0.
local
low complexity
serenity CWE-640
7.8
2023-04-20 CVE-2021-36436 Weak Password Recovery Mechanism for Forgotten Password vulnerability in Mobicint 3.0
An issue in Mobicint Backend for Credit Unions v3 allows attackers to retrieve partial email addresses and user entered information via submission to the forgotten-password endpoint.
network
low complexity
mobicint CWE-640
5.3
2023-03-21 CVE-2022-45637 Weak Password Recovery Mechanism for Forgotten Password vulnerability in Megafeis Bofei Dbd+ 1.4.4
An insecure password reset issue discovered in MEGAFEIS, BOFEI DBD+ Application for IOS & Android v1.4.4 service via insecure expiry mechanism.
network
low complexity
megafeis CWE-640
critical
9.8
2023-01-30 CVE-2022-26872 Weak Password Recovery Mechanism for Forgotten Password vulnerability in AMI Megarac Sp-X 12/13
AMI Megarac Password reset interception via API
network
low complexity
ami CWE-640
8.8
2023-01-12 CVE-2022-25027 Weak Password Recovery Mechanism for Forgotten Password vulnerability in Rocketsoftware Trufusion Enterprise
The Forgotten Password functionality of Rocket TRUfusion Portal v7.9.2.1 allows remote attackers to bypass authentication and access restricted pages by validating the user's session token when the "Password forgotten?" button is clicked.
network
low complexity
rocketsoftware CWE-640
7.5
2022-12-26 CVE-2020-12067 Weak Password Recovery Mechanism for Forgotten Password vulnerability in Pilz PMC 3.0.0
In Pilz PMC programming tool 3.x before 3.5.17 (based on CODESYS Development System), a user's password may be changed by an attacker without knowledge of the current password.
network
low complexity
pilz CWE-640
7.5
2022-11-16 CVE-2022-44004 Weak Password Recovery Mechanism for Forgotten Password vulnerability in Backclick 5.9.63
An issue was discovered in BACKCLICK Professional 5.9.63.
network
low complexity
backclick CWE-640
critical
9.8
2022-08-01 CVE-2022-34530 Weak Password Recovery Mechanism for Forgotten Password vulnerability in Backdropcms Backdrop CMS
An issue in the login and reset password functionality of Backdrop CMS v1.22.0 allows attackers to enumerate usernames via password reset requests and distinct responses returned based on usernames.
network
low complexity
backdropcms CWE-640
5.3
2022-07-06 CVE-2022-23172 Weak Password Recovery Mechanism for Forgotten Password vulnerability in Priority-Software Priority 19.1.0.68
An attacker can access to "Forgot my password" button, as soon as he puts users is valid in the system, the system would issue a message that a password reset email had been sent to user.
network
low complexity
priority-software CWE-640
4.3