Vulnerabilities > Weak Password Recovery Mechanism for Forgotten Password
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2020-09-17 | CVE-2020-25728 | Weak Password Recovery Mechanism for Forgotten Password vulnerability in Alfresco Reset Password The Reset Password add-on before 1.2.0 for Alfresco has a broken algorithm (involving an increment) that allows a malicious user to change any user's account password include the admin account. | 8.8 |
2020-09-03 | CVE-2020-25105 | Weak Password Recovery Mechanism for Forgotten Password vulnerability in Eramba 2.19.3/2.8.1 eramba c2.8.1 and Enterprise before e2.19.3 has a weak password recovery token (createHash has only a million possibilities). | 9.8 |
2020-06-24 | CVE-2020-14016 | Weak Password Recovery Mechanism for Forgotten Password vulnerability in Naviwebs Navigate CMS 2.9 An issue was discovered in Navigate CMS 2.9 r1433. | 5.3 |
2020-06-24 | CVE-2020-14015 | Weak Password Recovery Mechanism for Forgotten Password vulnerability in Naviwebs Navigate CMS 2.9 An issue was discovered in Navigate CMS 2.9 r1433. | 7.5 |
2020-03-23 | CVE-2019-6560 | Weak Password Recovery Mechanism for Forgotten Password vulnerability in Auto-Maskin products In Auto-Maskin RP210E Versions 3.7 and prior, DCU210E Versions 3.7 and prior and Marine Observer Pro (Android App), the software contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak. | 9.1 |
2020-02-04 | CVE-2012-5686 | Weak Password Recovery Mechanism for Forgotten Password vulnerability in Zpanelcp Zpanel 10.0.1 ZPanel 10.0.1 has insufficient entropy for its password reset process. | 9.8 |
2020-02-04 | CVE-2012-5618 | Weak Password Recovery Mechanism for Forgotten Password vulnerability in Ushahidi Ushahidi before 2.6.1 has insufficient entropy for forgot-password tokens. | 9.8 |
2020-01-23 | CVE-2020-7245 | Weak Password Recovery Mechanism for Forgotten Password vulnerability in Ctfd Incorrect username validation in the registration process of CTFd v2.0.0 - v2.2.2 allows an attacker to take over an arbitrary account if the username is known and emails are enabled on the CTFd instance. | 9.8 |
2020-01-15 | CVE-2009-5025 | Weak Password Recovery Mechanism for Forgotten Password vulnerability in Pyforum Project Pyforum 1.0.3 A backdoor (aka BMSA-2009-07) was found in PyForum v1.0.3 where an attacker who knows a valid user email could force a password reset on behalf of that user. | 7.5 |
2020-01-05 | CVE-2019-20004 | Weak Password Recovery Mechanism for Forgotten Password vulnerability in Intelbras IWR 3000N Firmware 1.8.7 An issue was discovered on Intelbras IWR 3000N 1.8.7 devices. | 8.8 |