Vulnerabilities > Weak Password Recovery Mechanism for Forgotten Password
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-05-11 | CVE-2021-31912 | Weak Password Recovery Mechanism for Forgotten Password vulnerability in Jetbrains Teamcity In JetBrains TeamCity before 2020.2.3, account takeover was potentially possible during a password reset. | 6.8 |
2021-05-06 | CVE-2021-28128 | Weak Password Recovery Mechanism for Forgotten Password vulnerability in Strapi In Strapi through 3.6.0, the admin panel allows the changing of one's own password without entering the current password. | 5.5 |
2021-03-23 | CVE-2021-29080 | Weak Password Recovery Mechanism for Forgotten Password vulnerability in Netgear products Certain NETGEAR devices are affected by password reset by an unauthenticated attacker. | 4.8 |
2021-01-19 | CVE-2021-25323 | Weak Password Recovery Mechanism for Forgotten Password vulnerability in Misp 2.4.136 The default setting of MISP 2.4.136 did not enable the requirements (aka require_password_confirmation) to provide the previous password when changing a password. | 6.4 |
2021-01-04 | CVE-2020-5361 | Weak Password Recovery Mechanism for Forgotten Password vulnerability in Dell CPG Bios Select Dell Client Commercial and Consumer platforms support a BIOS password reset capability that is designed to assist authorized customers who forget their passwords. | 7.2 |
2020-12-24 | CVE-2020-28186 | Weak Password Recovery Mechanism for Forgotten Password vulnerability in Terra-Master TOS Email Injection in TerraMaster TOS <= 4.2.06 allows remote unauthenticated attackers to abuse the forget password functionality and achieve account takeover. | 6.8 |
2020-11-05 | CVE-2020-15949 | Weak Password Recovery Mechanism for Forgotten Password vulnerability in Immuta 2.8.2 Immuta v2.8.2 is affected by one instance of insecure permissions that can lead to user account takeover. | 5.0 |
2020-10-27 | CVE-2020-27179 | Weak Password Recovery Mechanism for Forgotten Password vulnerability in Konzept-Ix Publixone konzept-ix publiXone before 2020.015 allows attackers to take over arbitrary user accounts by crafting password-reset tokens. | 7.5 |
2020-10-05 | CVE-2020-26061 | Weak Password Recovery Mechanism for Forgotten Password vulnerability in Clickstudios Passwordstate 8.3 ClickStudios Passwordstate Password Reset Portal prior to build 8501 is affected by an authentication bypass vulnerability. | 5.0 |
2020-09-17 | CVE-2020-25728 | Weak Password Recovery Mechanism for Forgotten Password vulnerability in Alfresco Reset Password The Reset Password add-on before 1.2.0 for Alfresco has a broken algorithm (involving an increment) that allows a malicious user to change any user's account password include the admin account. | 6.5 |