Vulnerabilities > Weak Password Recovery Mechanism for Forgotten Password

DATE CVE VULNERABILITY TITLE RISK
2021-05-11 CVE-2021-31912 Weak Password Recovery Mechanism for Forgotten Password vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2020.2.3, account takeover was potentially possible during a password reset.
network
jetbrains CWE-640
6.8
2021-05-06 CVE-2021-28128 Weak Password Recovery Mechanism for Forgotten Password vulnerability in Strapi
In Strapi through 3.6.0, the admin panel allows the changing of one's own password without entering the current password.
network
low complexity
strapi CWE-640
5.5
2021-03-23 CVE-2021-29080 Weak Password Recovery Mechanism for Forgotten Password vulnerability in Netgear products
Certain NETGEAR devices are affected by password reset by an unauthenticated attacker.
low complexity
netgear CWE-640
4.8
2021-01-19 CVE-2021-25323 Weak Password Recovery Mechanism for Forgotten Password vulnerability in Misp 2.4.136
The default setting of MISP 2.4.136 did not enable the requirements (aka require_password_confirmation) to provide the previous password when changing a password.
network
low complexity
misp CWE-640
6.4
2021-01-04 CVE-2020-5361 Weak Password Recovery Mechanism for Forgotten Password vulnerability in Dell CPG Bios
Select Dell Client Commercial and Consumer platforms support a BIOS password reset capability that is designed to assist authorized customers who forget their passwords.
local
low complexity
dell CWE-640
7.2
2020-12-24 CVE-2020-28186 Weak Password Recovery Mechanism for Forgotten Password vulnerability in Terra-Master TOS
Email Injection in TerraMaster TOS <= 4.2.06 allows remote unauthenticated attackers to abuse the forget password functionality and achieve account takeover.
6.8
2020-11-05 CVE-2020-15949 Weak Password Recovery Mechanism for Forgotten Password vulnerability in Immuta 2.8.2
Immuta v2.8.2 is affected by one instance of insecure permissions that can lead to user account takeover.
network
low complexity
immuta CWE-640
5.0
2020-10-27 CVE-2020-27179 Weak Password Recovery Mechanism for Forgotten Password vulnerability in Konzept-Ix Publixone
konzept-ix publiXone before 2020.015 allows attackers to take over arbitrary user accounts by crafting password-reset tokens.
network
low complexity
konzept-ix CWE-640
7.5
2020-10-05 CVE-2020-26061 Weak Password Recovery Mechanism for Forgotten Password vulnerability in Clickstudios Passwordstate 8.3
ClickStudios Passwordstate Password Reset Portal prior to build 8501 is affected by an authentication bypass vulnerability.
network
low complexity
clickstudios CWE-640
5.0
2020-09-17 CVE-2020-25728 Weak Password Recovery Mechanism for Forgotten Password vulnerability in Alfresco Reset Password
The Reset Password add-on before 1.2.0 for Alfresco has a broken algorithm (involving an increment) that allows a malicious user to change any user's account password include the admin account.
network
low complexity
alfresco CWE-640
6.5