CVE-2026-107640Critical· 9.1▾ MidnightIntegrics Enswitch 3.13 through 4.4 contains an authentication bypass vulnerability in /api/json/user/password/update/ that allows unauthenticated attackers to change account passwords by omitting the reset parameter. Attackers can targe…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 50.1 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Integrics Enswitch 3.13 through 4.4 contains an authentication bypass vulnerability in /api/json/user/password/update/ that allows unauthenticated attackers to change account passwords by omitting the reset parameter. Attackers can target accounts with no pending reset, whose empty reset_key matches the defaulted empty value, to take over administrator accounts after enumerating valid usernames.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-19218Critical· 9.1Weak Password Recovery Mechanism for Forgotten Password vulnerability in AKIN Software Computer Import-Export Industry and Trade Co
CVE-2026-105785Medium· 4.8Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks
CVE-2026-53953Critical· 9.1GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS
CVE-2020-37158Medium· 5.3AVideo Platform 8.1 - Cross Site Request Forgery (Password Reset)
CVE-2020-37172Medium· 5.3AVideo Platform 8.1 - Cross Site Request Forgery (Password Reset)
CVE-2026-102115Critical· 9.8Kiteworks Core did not correctly validate a parameter submitted to the password reset workflow