Vulnerabilities (CVE)

Filtered by CWE-640
Total 322 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-5277 1 Lunary 1 Lunary 2026-06-17 N/A 7.5 HIGH
In lunary-ai/lunary version 1.2.4, a vulnerability exists in the password recovery mechanism where the reset password token is not invalidated after use. This allows an attacker who compromises the recovery token to repeatedly change the password of a victim's account. The issue lies in the backend's handling of the reset password process, where the token, once used, is not discarded or invalidated, enabling its reuse. This vulnerability could lead to unauthorized account access if an attacker obtains the recovery token.
CVE-2024-53552 1 Crushftp 1 Crushftp 2026-06-17 N/A 9.8 CRITICAL
CrushFTP 10 before 10.8.3 and 11 before 11.2.3 mishandles password reset, leading to account takeover.
CVE-2024-50356 2026-06-17 N/A N/A
Press, a Frappe custom app that runs Frappe Cloud, manages infrastructure, subscription, marketplace, and software-as-a-service (SaaS). The password could be reset by anyone who have access to the mail inbox circumventing the 2FA. Even though they wouldn't be able to login by bypassing the 2FA. Only users who have enabled 2FA are affected. Commit ba0007c28ac814260f836849bc07d29beea7deb6 patches this bug.
CVE-2024-48428 1 Olivegroup 1 Olivevle 2026-06-17 N/A 9.8 CRITICAL
An issue in Olive VLE allows an attacker to obtain sensitive information via the reset password function.
CVE-2024-47547 1 Ruijienetworks 1 Reyee Os 2026-06-17 N/A 9.4 CRITICAL
Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x contains a weak mechanism for its users to change their passwords which leaves authentication vulnerable to brute force attacks.
CVE-2024-45980 2026-06-17 N/A 8.8 HIGH
A host header injection vulnerability in MEANStore 1.0 allows attackers to obtain the password reset token via user interaction with a crafted password reset link. This allows attackers to arbitrarily reset other users' passwords and compromise their accounts.
CVE-2024-45670 1 Ibm 1 Soar 2026-06-17 N/A 5.6 MEDIUM
IBM Security SOAR 51.0.1.0 and earlier contains a mechanism for users to recover or change their passwords without knowing the original password, but the user account must be compromised prior to the weak recovery mechanism.
CVE-2024-43190 1 Ibm 2 Engineering Requirements Management Doors, Engineering Requirements Management Doors Web Access 2026-06-17 N/A 5.9 MEDIUM
IBM Engineering Requirements Management DOORS 9.7.2.9, under certain configurations, could allow a remote attacker to obtain password reset instructions of a legitimate user using man in the middle techniques.
CVE-2024-42915 2026-06-17 N/A 8.0 HIGH
A host header injection vulnerability in Staff Appraisal System v1.0 allows attackers to obtain the password reset token via user interaction with a crafted password reset link. This will allow attackers to arbitrarily reset other users' passwords and compromise their accounts.
CVE-2024-38468 1 Guoxinled 1 Synthesis Image System 2026-06-17 N/A 9.8 CRITICAL
Shenzhen Guoxin Synthesis image system before 8.3.0 allows unauthorized password resets via the resetPassword API.
CVE-2024-38287 1 Rhubcom 1 Turbomeeting 2026-06-17 N/A 9.8 CRITICAL
The password-reset mechanism in the Forgot Password functionality in R-HUB TurboMeeting through 8.x allows unauthenticated remote attackers to force the application into resetting the administrator's password to a random insecure 8-digit value.
CVE-2024-36407 1 Salesagility 1 Suitecrm 2026-06-17 N/A 3.7 LOW
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and 8.6.1, a user password can be reset from an unauthenticated attacker. The attacker does not get access to the new password. But this can be annoying for the user. This attack is also dependent on some password reset functionalities being enabled. It also requires the system using php 7, which is not an officially supported version. Versions 7.14.4 and 8.6.1 contain a fix for this issue.
CVE-2024-33530 2026-06-17 N/A 7.5 HIGH
In Jitsi Meet before 9391, a logic flaw in password-protected Jitsi meetings (that make use of a lobby) leads to the disclosure of the meeting password when a user is invited to a call after waiting in the lobby.
CVE-2024-32642 1 Masacms 1 Masacms 2026-06-17 N/A 8.8 HIGH
Masa CMS is an open source Enterprise Content Management platform. Prior to 7.2.8, 7.3.13, and 7.4.6, there is vulnerable to host header poisoning which allows account takeover via password reset email. This vulnerability is fixed in 7.2.8, 7.3.13, and 7.4.6.
CVE-2024-2862 1 Lg 1 Lg Led Assistant 2026-06-17 N/A 9.1 CRITICAL
This vulnerability allows remote attackers to reset the password of anonymous users without authorization on the affected LG LED Assistant.
CVE-2024-2463 1 Cdex 1 Cdex 2026-06-17 N/A 8.0 HIGH
Weak password recovery mechanism in CDeX application allows to retrieve password reset token.This issue affects CDeX application versions through 5.7.1.
CVE-2024-27899 2026-06-17 N/A 8.8 HIGH
Self-Registration and Modify your own profile in User Admin Application of NetWeaver AS Java does not enforce proper security requirements for the content of the newly defined security answer. This can be leveraged by an attacker to cause profound impact on confidentiality and low impact on both integrity and availability.
CVE-2024-24903 1 Dell 1 Policy Manager For Secure Connect Gateway 2026-06-17 N/A 8.0 HIGH
Dell Secure Connect Gateway (SCG) Policy Manager, version 5.10+, contain a weak password recovery mechanism for forgotten passwords. An adjacent network low privileged attacker could potentially exploit this vulnerability, leading to unauthorized access to the application with privileges of the compromised account. The attacker could retrieve the reset password token without authorization and then perform the password change.
CVE-2024-22454 1 Dell 1 Powerprotect Data Manager 2026-06-17 N/A 8.8 HIGH
Dell PowerProtect Data Manager, version 19.15 and prior versions, contain a weak password recovery mechanism for forgotten passwords. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to unauthorized access to the application with privileges of the compromised account. The attacker could retrieve the reset password token without authorization and then perform the password change
CVE-2024-12604 1 Tapandsign 1 Tap\&sign 2026-06-17 N/A 6.5 MEDIUM
Cleartext Storage of Sensitive Information in an Environment Variable, Weak Password Recovery Mechanism for Forgotten Password vulnerability in Tapandsign Technologies Tap&Sign App allows Password Recovery Exploitation, Functionality Misuse. This issue affects Tap&Sign App: before V.1.025.