VulnSea

CWE-640

CVEs classified under CWE-640, newest first.

25 CVEsRSS

CVE-2026-93340Medium· 6.8
yesterday

Gladys Assistant before 5.1.0 contains a password reset link poisoning vulnerability that allows unauthenticated remote attackers to obtain valid password reset tokens for any account by exploiting the client-supplied origin parameter in…

Gladys Assistant before 5.1.0 contains a password reset link poisoning vulnerability that allows unauthenticated remote attackers to obtain valid password reset tokens for any account by exploiting the client-supplied origin parameter in…

SunlitGladys Assistant · Gladys Assistantvia NVD
CVE-2026-93453High· 8.3PoC
4d ago

SOGo before 5.12.11 constructs password-reset links using the client-supplied Origin header as the authority, allowing unauthenticated attackers to redirect recovery tokens to attacker-controlled domains

SOGo before 5.12.11 constructs password-reset links using the client-supplied Origin header as the authority, allowing unauthenticated attackers to redirect recovery tokens to attacker-controlled domains. Attackers can submit password re…

MidnightAlinto · SOGoEPSS 0.34%via NVD
CVE-2026-14850High· 8.8
5d ago

The password reset funcionality is vulnerable to unauthorized account modification due to improper validation of the user_id parameter

The password reset funcionality is vulnerable to unauthorized account modification due to improper validation of the user_id parameter. An attacker can manipulate this predictable numeric identifier to reset passwords for arbitrary users…

TwilightMobiAPParc · MobiAPParcEPSS 0.29%via NVD
CVE-2026-90522High· 7.3PoC
1w ago

A vulnerability was determined in jaychouchannel Tourism-Management-System up to d984d172dceca907f8b447efbdb06dc233f7938d

A vulnerability was determined in jaychouchannel Tourism-Management-System up to d984d172dceca907f8b447efbdb06dc233f7938d. Impacted is the function resetPass of the file UsersController.java of the component Password Recovery. This manip…

Midnightjaychouchannel · Tourism-Management-SystemEPSS 0.50%via NVD
CVE-2026-81905Medium· 6.3
1w ago

Concrete CMS below 9.5.3 stores user validation hashes for multiple purposes (email/registration validation, password reset, and persistent login) in a single table with a type column, but the redemption path resolves a hash by value alo…

Concrete CMS below 9.5.3 stores user validation hashes for multiple purposes (email/registration validation, password reset, and persistent login) in a single table with a type column, but the redemption path resolves a hash by value alo…

SunlitConcrete CMS · Concrete CMSEPSS 0.24%via NVD
CVE-2026-6285High· 7.5
1w ago

Improper Authentication in Ankaref's LIBRID/LIBREF

Weak Password Recovery Mechanism for Forgotten Password vulnerability in Ankaref Innovation and Technology Inc. LIBRID/LIBREF allows Password Recovery Exploitation. This issue affects LIBRID/LIBREF: from 2.01.0.2183 through 10092026. NO…

TwilightAnkaref Innovation and Technology Inc. · LIBRID/LIBREFEPSS 0.29%via CVEORG
CVE-2026-86260Medium· 6.5PoC
2w ago

A security flaw has been discovered in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8

A security flaw has been discovered in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. The affected element is the function modifyPassWord of the file ssm_pro/src/main/java/cn/sfturing/web/CommonUserController.java of…

Twilightsfturing · hosp_orderEPSS 0.43%via NVD
CVE-2026-71625Critical· 9.8PoC
2w ago

An issue in slimkit plus ThinkSNS+ v.2.4 allows a remote attacker to escalate privileges via the ResetPasswordController.php component

An issue in slimkit plus ThinkSNS+ v.2.4 allows a remote attacker to escalate privileges via the ResetPasswordController.php component

AbyssalEPSS 0.40%via NVD
CVE-2026-82487Medium· 6.3
3w ago

A vulnerability was determined in Beetel 450TC3 01.00.00_01

A vulnerability was determined in Beetel 450TC3 01.00.00_01. This affects an unknown part. Executing a manipulation can lead to weak password recovery. The attack can be executed remotely. The exploit has been publicly disclosed and may …

SunlitEPSS 0.21%via NVD
CVE-2026-55207High· 8.8
3w ago

Pimcore: Account Takeover via Password Reset URL Injection allows unauthenticated attacker to hijack any admin account with 2FA bypass

Pimcore: Account Takeover via Password Reset URL Injection allows unauthenticated attacker to hijack any admin account with 2FA bypass

Twilightpimcore · pimcore/studio-backend-bundleEPSS 0.67%via GHSA
CVE-2026-18963Critical· 9.1PoC
1mo ago

A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak

A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated attacker to force the passwo…

AbyssalRed Hat · rhbk/keycloak-operator-bundleEPSS 3.2%via NVD
CVE-2026-15689None
1mo ago

Dancer2::Plugin::Auth::Extensible versions through 0.713 for Perl allow password reset link poisoning via the request Host header in _default_email_password_reset and _default_welcome_send. Both default emails emit a link of the form `$…

Dancer2::Plugin::Auth::Extensible versions through 0.713 for Perl allow password reset link poisoning via the request Host header in _default_email_password_reset and _default_welcome_send. Both default emails emit a link of the form `$…

SunlitEPSS 0.61%via NVD
CVE-2026-72772High· 8.8
1mo ago

n8n before 2.32.1 (and before 2.31.5) is vulnerable to account takeover via the Token Exchange Embed Login feature

n8n before 2.32.1 (and before 2.31.5) is vulnerable to account takeover via the Token Exchange Embed Login feature. When a validly-signed incoming token was matched to a local account by its email claim, the service did not verify that t…

Twilightn8n · n8nEPSS 0.26%via NVD
CVE-2026-19361Low· 3.7
1mo ago

A flaw has been found in macrozheng mall 0504e86

A flaw has been found in macrozheng mall 0504e86. This vulnerability affects unknown code of the file /sso/getAuthCode of the component mall-portal Module. Executing a manipulation can lead to weak password recovery. The attack may be la…

SunlitEPSS 0.28%via NVD
CVE-2026-61181High· 7.6
2mo ago

Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Product Quality Management)

Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Product Quality Management). The supported version that is affected is 6.2.4. Easily exploitable vulnerability allows…

Twilightoracle · agile_product_lifecycle_management_for_processEPSS 0.27%via NVD
CVE-2026-56308High· 7.3
2mo ago

Capgo before 12.128.2 allows email address changes without requiring current password re-authentication or verification of the existing email address

Capgo before 12.128.2 allows email address changes without requiring current password re-authentication or verification of the existing email address. An attacker with access to a valid session cookie or authenticated browser can change …

TwilightEPSS 0.43%via NVD
CVE-2026-15479High· 7.3
2mo ago

A vulnerability was found in H3C NX15 V100R017

A vulnerability was found in H3C NX15 V100R017. Affected by this vulnerability is the function change_passwd of the file /api/login/modify of the component Administrator Password Modification Endpoint. The manipulation of the argument ne…

TwilightEPSS 0.47%via NVD
CVE-2026-15155High· 8.8
2mo ago

The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Authenticated Account Takeover via Email Header Injection in all versions up to, and including, 6.6.10 This is due to insuff…

The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Authenticated Account Takeover via Email Header Injection in all versions up to, and including, 6.6.10 This is due to insuff…

TwilightEPSS 0.67%via NVD
CVE-2026-7655High· 8.1
2mo ago

The SureCart plugin for WordPress is vulnerable to privilege escalation via account takeover in versions up to, and including, 4.2.3

The SureCart plugin for WordPress is vulnerable to privilege escalation via account takeover in versions up to, and including, 4.2.3. This is due to the plugin not properly validating a user's identity prior to updating their details lik…

TwilightEPSS 0.47%via NVD
GHSA-m492-gv72-xvxjLow
2mo ago

Kimai Password Reset Link Remains Valid After Password Change

Kimai Password Reset Link Remains Valid After Password Change

Sunlitkimai · kimai/kimaivia GHSA
CVE-2026-37106Critical· 9.8
2mo ago

An issue in DokuWiki 2025-05-14b "Librarian" 56.2 allows a remote attacker to create an account via the register function in inc/auth.php

An issue in DokuWiki 2025-05-14b "Librarian" 56.2 allows a remote attacker to create an account via the register function in inc/auth.php. NOTE: this is disputed by the Supplier because this is the intentional behavior when the product i…

MidnightEPSS 0.74%via NVD
CVE-2025-63314Critical· 10.0PoC
8mo ago

A static password reset token in the password reset function of DDSN Interactive Acora CMS v10.7.1 allows attackers to arbitrarily reset the user password and execute a full account takeover via a replay attack.

A static password reset token in the password reset function of DDSN Interactive Acora CMS v10.7.1 allows attackers to arbitrarily reset the user password and execute a full account takeover via a replay attack.

Abyssalddsn · cm3_acora_cmsEPSS 0.29%via NVD
CVE-2025-50433Critical· 9.8PoC
10mo ago

An issue was discovered in imonnit.com (2025-04-24) allowing malicious actors to gain escalated privileges via crafted password reset to take over arbitrary user accounts.

An issue was discovered in imonnit.com (2025-04-24) allowing malicious actors to gain escalated privileges via crafted password reset to take over arbitrary user accounts.

Abyssalmonnit · imonnitEPSS 0.43%via NVD
CVE-2022-34530Medium· 5.3
4y ago

An issue in the login and reset password functionality of Backdrop CMS v1.22.0 allows attackers to enumerate usernames via password reset requests and distinct responses returned based on usernames.

An issue in the login and reset password functionality of Backdrop CMS v1.22.0 allows attackers to enumerate usernames via password reset requests and distinct responses returned based on usernames.

Sunlitbackdropcms · backdrop_cmsEPSS 0.60%via NVD
CVE-2021-25323Critical· 9.1
5y ago

The default setting of MISP 2.4.136 did not enable the requirements (aka require_password_confirmation) to provide the previous password when changing a password.

The default setting of MISP 2.4.136 did not enable the requirements (aka require_password_confirmation) to provide the previous password when changing a password.

Midnightmisp-project · mispEPSS 1.3%via NVD
CWE-640 vulnerabilities (CVEs) · VulnSea