VulnSea

CWE-620

CVEs classified under CWE-620, newest first.

16 CVEsRSS

CVE-2026-92467High· 8.3PoC
6d ago

zlt2000 microservices-platform through 6.0.0 contains an unverified password change vulnerability in the PUT /users/password endpoint that allows authenticated users to change any account password by omitting the current password check

zlt2000 microservices-platform through 6.0.0 contains an unverified password change vulnerability in the PUT /users/password endpoint that allows authenticated users to change any account password by omitting the current password check. …

Midnightzlt2000 · microservices-platformEPSS 0.43%via NVD
CVE-2026-91995Critical· 9.1
1w ago

pig before 4.1.0 contains an authentication bypass vulnerability in the /register/password endpoint where password verification results are discarded, allowing any value as the current password

pig before 4.1.0 contains an authentication bypass vulnerability in the /register/password endpoint where password verification results are discarded, allowing any value as the current password. Remote attackers can submit a username wit…

Midnightpig-mesh · pigEPSS 0.61%via NVD
CVE-2026-46623High· 7.4
1w ago

Open Access Management (OpenAM) is an access management solution

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the OAuth2 authentication module updates an existing local account with profile attributes that can include userPassword and inetUserStatus, rewriting the…

TwilightOpenIdentityPlatform · OpenAMEPSS 0.49%via NVD
CVE-2026-54175High· 7.6
1w ago

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. Prior to 6.8.11 and 7.0.34, MyAccountController::postAccountInfoForm…

TwilightLaravel-Backpack · CRUDEPSS 0.38%via NVD
CVE-2026-54176Medium· 6.5
1w ago

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. From 6.0.0 until 6.8.14 and 7.0.38, MyAccountController::postAccount…

SunlitLaravel-Backpack · CRUDEPSS 0.46%via NVD
CVE-2026-86260Medium· 6.5PoC
2w ago

A security flaw has been discovered in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8

A security flaw has been discovered in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. The affected element is the function modifyPassWord of the file ssm_pro/src/main/java/cn/sfturing/web/CommonUserController.java of…

Twilightsfturing · hosp_orderEPSS 0.43%via NVD
CVE-2026-85591High· 7.1
2w ago

phpMyFAQ versions before 4.1.8 contain an authentication bypass vulnerability in the user control panel API endpoint that allows authenticated attackers to change account passwords without verifying the current password

phpMyFAQ versions before 4.1.8 contain an authentication bypass vulnerability in the user control panel API endpoint that allows authenticated attackers to change account passwords without verifying the current password. Attackers with s…

Twilightthorsten · phpMyFAQEPSS 0.30%via NVD
CVE-2026-76633High· 8.1
1mo ago

WeGIA before 3.9.2 contains an authorization bypass vulnerability in the password change flow that allows any authenticated user to change their account password without providing existing credentials by exploiting the unconditional excl…

WeGIA before 3.9.2 contains an authorization bypass vulnerability in the password change flow that allows any authenticated user to change their account password without providing existing credentials by exploiting the unconditional excl…

TwilightEPSS 0.24%via NVD
CVE-2026-77644None
1mo ago

A critical bypass access control vulnerability has been reported in PTC Windchill Risk and Reliability (WRR) Enterprise Edition.

A critical bypass access control vulnerability has been reported in PTC Windchill Risk and Reliability (WRR) Enterprise Edition.

SunlitEPSS 0.31%via NVD
CVE-2026-73292High· 8.3PoC
1mo ago

Semaphore UI is a web interface for managing DevOps tools

Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.21, the /api/users/{id}/password endpoint accepts a cross-site request using the authenticated user's semaphore session cookie without CSRF protection or current-pa…

Midnightsemaphoreui · github.com/semaphoreui/semaphoreEPSS 0.23%via NVD
CVE-2026-15964Critical· 9.8PoC
1mo ago

The Single Sign On For TNG plugin for WordPress is vulnerable to Authentication Bypass via unauthenticated password reset in all versions up to, and including, 2.0.0

The Single Sign On For TNG plugin for WordPress is vulnerable to Authentication Bypass via unauthenticated password reset in all versions up to, and including, 2.0.0. This is due to the `ssoprocess_ajax()` function — registered on `wp_aj…

AbyssalEPSS 0.63%via NVD
GHSA-h4hf-v6w5-897xHigh· 8.8
2mo ago

Poweradmin: API user-update endpoint leads to a non-admin reset any user's password and take over the superuser account

Poweradmin: API user-update endpoint leads to a non-admin reset any user's password and take over the superuser account

Twilightpoweradmin · poweradmin/poweradminvia GHSA
CVE-2026-44733Medium· 5.9
2mo ago

OpenProject is open-source, web-based project management software

OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, Business Logic Error on OpenProject through PATCH request to /api/v3/users/me permits to bypass password requirements. A password validation f…

SunlitEPSS 0.28%via NVD
CVE-2026-5386Critical· 9.1
3mo ago

The affected KMW CCTV Security Cameras are vulnerable to a critical unauthenticated password reset

The affected KMW CCTV Security Cameras are vulnerable to a critical unauthenticated password reset. This flaw allows an attacker to remotely reset the administrator password to a known value without authentication, granting full access t…

MidnightEPSS 0.62%via NVD
CVE-2025-70082Critical· 9.8
6mo ago

An issue in Lantronix EDS3000PS v.3.1.0.0R2 allows an attacker to execute arbitrary code and obtain sensitive information via the ltrx_evo component

An issue in Lantronix EDS3000PS v.3.1.0.0R2 allows an attacker to execute arbitrary code and obtain sensitive information via the ltrx_evo component

MidnightEPSS 0.46%via NVD
CVE-2025-67041Critical· 9.8
6mo ago

An issue was discovered in Lantronix EDS3000PS 3.1.0.0R2

An issue was discovered in Lantronix EDS3000PS 3.1.0.0R2. The host parameter of the TFTP client in the Filesystem Browser page is not properly sanitized. This can be exploited to escape from the original command and execute an arbitrary …

MidnightEPSS 0.42%via NVD
CWE-620 vulnerabilities (CVEs) · VulnSea